General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 291 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3624 Views
  • 2 replies
  • 14 Likes

Captive Portal Customization and Device Detection

I have been tasked with modifying our Captive Portal, from Palo Alto, that current users see when they connect to our guest Wi-Fi here at the Upper Canada District School Board. I have read most of the documentation related to the captive portal and

...

dcletech by Not applicable
  • 1983 Views
  • 1 replies
  • 0 Likes

SSL / Outlook Web Access not identified by App-ID

I have a customer that is using a PA-5020, and when users try to go to certain Outlook Web Access sites, it won't work for them.  Checking the logs, I can see where the user initiates a connection over port 443 to the destination OWA server, but App-

...

OSPF through Vwire

I attempted to install a PA5060 between a Cisco ASA and Cisco Nexus switch in vwire mode. the ASA has an OSPF neighbor with the nexus 7k to distribute the defualt route learned via BGP from the ISP.

 

Once the 5060 was installed, the OSPF neigbor cam

...

Global Protect Speeds?

Hi, realtively new to PAN, and have some questions related to Global Protect speeds.

I have a win 7 x64 client connected to a gateway on my 3020. 

From the client to the internet over 30mbs of bw

From the PA3020 VPN interface to the itnernet 20mbs of

...

NeilR by L2 Linker
  • 4079 Views
  • 3 replies
  • 0 Likes

Panorama Access Domain Admins - Not functioning 7.0.3

Currently we have been working with setting up Access Domain accounts for our server admins to have restricted RO access to traffic logs and policy rules. The configuration appears sound but all testing using either local or radius/ldap auth accounts

...

login-error.jpg

Resolved! Upgrading Panorama and Firewalls to 7.0.3

Hey All,

I have some questions regarding the upgrade of Panorama and firewalls to version 7.0.3. I am looking to upgrade both fairly soon, and want to avoid any gotchas. My environment currently has Panorama at 6.1.4 and all firewalls at 6.1.4 or 6.1

...

Resolved! VPN IPSec / SSL

Hello,

i have the problem with understanding How my VPN works.

 

I have created one portal and gateway for all users profile and I generate for all of them unique certifcate.

 

When i look in to Remote Users table I see that some of users uses SSL an

...

ITBT by L1 Bithead
  • 2768 Views
  • 1 replies
  • 0 Likes

Does Palo Alto support Reverse Route injection?

As title, does Palo Alto support something like CISCO "Reverse Route injection" which can inject a /32 route to the campus network for a dial-in user? Or can I create a /24 loopback interface for VPN users and redistribute the /24 to campus network?

...

Slow Network Traffic Using Global Protect

Hi,

 

We are experiencing high latency when using Global Protect. It peaks to 1000ms. We tried to use Cisco VPN to isolate the problem and latency peaks at 90ms. We removed security profiles that may cause latency but it did not work. We also noticed

...

Exclude Traffic from the VPN Tunnel with scripts (GP 2.3)

Dear community,

 

have you ever tried to exclude IPs from the VPN tunnel using the GP 2.3 feature:

https://www.paloaltonetworks.com/documentation/70/globalprotect/globalprotect-admin-guide/set-up-the-globalprotect-infrastructure/deploy-agent-settings

...

Hithead by L4 Transporter
  • 2365 Views
  • 0 replies
  • 0 Likes

Automation of a vsys configuration

We would like to automate the configuration of a new vsys, uisng inputs from a file or script with the required information, using either the set commands or the API.

Has anyone attempted to do this, and what is the best way and how to gather the req

...

dwmaas by L2 Linker
  • 2319 Views
  • 1 replies
  • 0 Likes
  • 24180 Posts
  • 100 Subscriptions
Top Liked Authors
Labels