General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Rule to block TOR Application blocks all traffic directed to Internet

Hello Community, we have an issue when we try to block TOR application. We do a rule like the image reported below and put it on top of the rulebase: But it seems that all Internet traffic is dropped by the rule named "Tor_Blocking". We see the Application is "Not-Applicable" on all log files. It seems PaloAlto cannot resolve properly th...

Rule_TOR.png
LOG_TOR.png

Sample configurations and logs for PAN-OS and Panorama for VM-Series Base Images

Dear PA, In order to enhance my learning effect with PA products, I installed VM workstation 12 Player and downloaded and ran the PA-VM-ESX-7.1.0 Base Images in it. The PAN-OS (Play virtual machine) runs fantastic on windows 7. I enjoyed playing around in the VM, but I missed the sample configuration and logs in order to understand the outcome...

Captive portal user-id for all services

Hi, I have set up a captive portal for services http and https. The captive portal works well and I get user-id/IP mapping in the logs. The rules are then applied based on the user group membership (AD). However, this user-id mapping does not work for all services and therefore some rules are not applied based on the user-id... The sessions ar...

Screen Shot 2016-05-21 at 6.45.36 PM.png
Screen Shot 2016-05-21 at 6.43.42 PM.png
JBOURDON by L0 Member
  • 3505 Views
  • 3 replies
  • 0 Likes

Terminal Server Agent service account issue.

Configured a new TS on palo alto and installed agent on the server. Already have 2 TS configured on the PA and running fine.This new server has 2 service accounts with both needing internet access. These are adsync and centrify service accounts. I can see mapping of the users who are logging to TS server but service accounts are having issues. c...

Resolved! NSX Tags IP information gets lost between Panorama and 5060's

Hello, We are sending NSX Tags with IP's to Panorama, in Panorama everything shows up great, then when we go to our Physical 5060's Edge Firewalls we see the Tags but the IP information is missing. This makes it hard to build North/South Rules if it dosn't know what the IP addresses are for the Tags. Anyone know what we might be missing? How ...

dschmidt by L0 Member
  • 2824 Views
  • 2 replies
  • 0 Likes

Resolved! Many-to-One Destination NAT

Hi, We currently have a problem on site where our windows domain name matches the website name so the naked domain DNS configuration contains an A record for a web server and not the domain controllers. As a short term workaround (because it could take 2-3 years to plan and change the domain name) I'm using the destination NAT feature. In my tes...

panos_screenshot_campusmsdcsuat.png

Url category unknown for dropbox and msn

Hello I'm using BrightCloud URL Filtering (at the moment I have 4792 version on my device). I'm started testing this functionality (security policy with url filtering in monitor mode). In Monitor tab in URL filtering section I see: How it's possible that DropBOX and MSN are in unknown url category? Regards SLawek

2016-05-19_095625.jpg
_slv_ by L4 Transporter
  • 2364 Views
  • 2 replies
  • 0 Likes

Resolved! Question about HA 2 link

Hi Team, Good day!My questions is in regards to the HA 2 link. It is a l2 link. However, we can have an IP address on it. However, lets say that we have no IP address on dedicated HA 2 link on both sides. Now, If I have a L2 switch in between How will one side come to know about other's MAC address? Thanks in advance. Regards.

yadsingh by L2 Linker
  • 3175 Views
  • 1 replies
  • 0 Likes

Resolved! PPS Report

Has anyone built a custom report to get packets per second for a destination? I see we can get total packets transmitted/received over a given period of time, but nothing for calculating pps right in the report. Any suggestions? Thanks!

AmyTyler by L2 Linker
  • 4840 Views
  • 4 replies
  • 0 Likes

Resolved! User-ID Agent error

Hi, I am getting the below error in domain controllers DCOM was unable to communicate with the computer 10.0.129.3 using any of the configured protocols; requested by PID aec (C:\Program Files (x86)\Palo Alto Networks\User-ID Agent\UaService.exe). Event Xml: Please help to get rid of the problem Thanks

sib2017 by L4 Transporter
  • 5230 Views
  • 1 replies
  • 0 Likes

Searching a Howto for two ISP Connection and two Lan

Hello, i seach a HowTo for configuration two different ISP connections and two different LANs. Both should nothing to do with eatch other. They should be seperate. Is there any where a HowTo for this configuration? I only found twi isp connection for use with Backup connection but nothing for user bothe with different networks.I use a PA200 for ...

Resolved! Pan agent

Hi, I was using windows 2008 Domain controller and Palo alto ldap profile configured. ,Now changing to 2012 So which version of panagent need to be installed.Where can i download the panagent ?Is there something need to be done on paloalto side after migrating dc Thanks

sib2017 by L4 Transporter
  • 3547 Views
  • 3 replies
  • 0 Likes

No traffic being logged at all

Hello, we've got a bunch of virtual palo alto firewalls running 7.0.1. One set are running fine, largely configured with no issues. The other set are in a different environment, all the infrastructure is the same (same type of hypervisor, same version, all that) The only significant difference is that in the second environment, each PA is part o...

PaulAlto by L0 Member
  • 3411 Views
  • 5 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels