General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

No User ID in traffic logs (unless I filter soruce user afterwards) and User activity report blank

Has any one expereinced any issue to where the ACC shows source user-id but when ser report is ran its blank? Equallu I do not se user name in Traffic logs but when I filter by source user the name shows up. I tried restarting agent and everything still no luck. I also can see user name in User ID agent on windows machine

Dangers of creating a permiscuous IPSec VPN ( responder only) VPN

We have a business partner that wants to create an IPSec VPN tunnel with our PA-5050 using pre-shared keys, but they don't want to provide a Public IP address for us to peer with. Their other clients configure the remote peer address of 0.0.0.0 basically allowing any remote IP as a peer. My spidey sense is telling me this is a bad idea. The...

fmurray by L1 Bithead
  • 4386 Views
  • 2 replies
  • 0 Likes

What Firewall Change Management software is working with a PAN ?

Hi,Is there anyone that can tell me which Firewall Change Management ( Skybox, Tufin, Algosec,.... ) is REALLY working with a PAN ?Most of them claim they can do it, until you test it... nothing works...Some of them announce PAN support for next year.I would like to get in touch with someone who has really done this kind of integration and who i...

Resolved! DAGPusher and DAG

Luigi, Can you confirm DAGPusher name should match tag for DAG in PAN-OS? I can't have the DAG updated with Minemeld indicators Thanks Bertrand

Resolved! Site-To-Site VPN to VMWare VShield Edge?

Greetings all. We're in pre-deployment for our firewall and I'm attempting to get an Site-To-Site VPN tunnel set up to our VShield Edge setup in the cloud. I have a tunnel established but we can't seem to get anything across it. Troubleshooting so far: Verified on the Traffic Monitor I can see my pings going from my inside trusted zone to ...

jsalmans by L4 Transporter
  • 4907 Views
  • 2 replies
  • 0 Likes

Resolved! Per port session TTL

Hi, Am I correct when I state that a PAN firewall cannot set different timeouts per used port?Fortigates and Junipers seem to have this option, where they can set their defaults and specify -if required, for certain ports.On a PAN device, I don't think I'll have this option to do so, without prolonging them for all services and impacting more th...

Arne-VDH by L3 Networker
  • 3475 Views
  • 2 replies
  • 0 Likes

PAN OS 7.1.2

Just updated the FW to PAN OS 7.1.2. The UI looks very mordern ! The ACC page has been re-designed , looks better, is there any way to customise the panes ?

RC-BHF by L2 Linker
  • 3576 Views
  • 4 replies
  • 0 Likes

Single AD Forest Multiple Domains with Group Mapping & Global Protect

Does anyone have any best practives on how to configure Multi-Domain authentication with Global Protect? I see how to map/sync groups in multiple domains in my forest, but not entirely sure the process for the Global Protect end. Right now I am using Kerberos and the realm in one domain. Obviously this won't work in the other. Do I do someth...

NickThen by L2 Linker
  • 2933 Views
  • 1 replies
  • 0 Likes

PAN as VPN Client ipsec psk+xauth

I am a bit new at VPN stuff - I have a PAN-500, i configured VPN for users just fine (IPSec+xauth "cisco compatible" so it works with pretty much anything), as well as static site to site IPSec tunnels. What I cannot figure out how to do is make my box be a client, in this case I want to connect to Cisco Devnet Labs, which works fine with a ci...

Resolved! "LAN" Interface Failover configuration - Primary: dedicated Line, Secondary: VPN

Hi there, maybe it's not that complicated but I didn't find a post for this scenario: The LAN of our Clients are in Location1 (~ 200 km) The LAN of our Servers are in Location2 Location1 and 2 are using the same firewall which is stored in Location 2 because Location 1 has a dedicated line to Location 2. The Primary connection between Loca...

Resolved! global protect client

Connect option grayed out under status tab on global protect client? Anyone know what the cause is and the fix?

jdprovine by L4 Transporter
  • 4771 Views
  • 6 replies
  • 0 Likes

Cannot Change Application Risk Category Customization

I'm running 7.1.2, but the problem started after 7.1 beta update, I believe. Setting an applicaiton risk category manually results in it showing up correctly in the application's open window details; however, the firewall will only recognize the default risk category. This has effectively rendered my applcation filter rule useless. I have trie...

rrubino by L0 Member
  • 3392 Views
  • 3 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels