General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Deactivate Url-filtering

Hello all,I have problem with deactivation of URL-filtering on my PAN-500.My license had expired on 30.04 and I still receive system alert:opaque: License for feature url-filtering expired on 2016/04/30I tried to use:set deviceconfig setting url dynamic-url nobut it doesn't work.

ITBT by L1 Bithead
  • 2995 Views
  • 1 replies
  • 0 Likes

Firewall Interface Not Responding to Pings

Hello Community, My firewall won't respond to pings. My Palo Alto sits within a VM. At first I thought it was because the mac address in my ESXi didn't match the mac address on the interface, but then I noticed none of my other interfaes match with my ESXi, but they all seem to work. see image Its just ethernet interface 1/4 that doesn...

mac.png
outside.png
ethernet1-4.png
ethernet1-4mac.png

Global Protect does not Work after transfering licences from PA-500 to OSS SPARE

Hello To All, I'm facing an issue after doing a migration. We'd an issue with a FAN on PA-500, so RMA works fine We decided to transfer licences from PA-500 fan error to OSS Spare. Everything went well until we do realize that Global Protect is not working anymore. The Synch between AD/LDAP and PALO is OK When we try to log-in to Global p...

Resolved! Add Virtual Interface to Palo Alto

Hello Community, I have a Palo Alto VM. It was configured with three interfaces, see picture. I would like to add another virtual interface. Can you how many Virtual Interfaces can be configured on the Palo Alto VM? Is there a document to assist me? Cheers Carlton

interfacce.png

Captive portal deployment...advices

Hello, We have all our branches in south america going to internet through a PA located in Boston. This PA has configured captive portal for all these branches (each branch has own domain controller), This PA in Miami has a VPN to Barcelona from where takes the LDAP group for captive portal. The problem is that last week the VPN went down so n...

Ability to report on user web searches

I work in a large K-12. We had used Blue Coat for our Web Security/Proxy before moving entirely to PAN. With Blue Coat we had the ability to produce reports on users search terms. Does anyone know if this is possible within PAN-OS?Thank you,Patrick

Report about all rules from zone 1 to zone 2

Hello, After a Migration I have many rules from zone1 to zone2 set to any any. Some of them are highlighted as not used rules. I think about a report of all Rules displaying their activity without copying and pasting each rulename to a custom report. Question 1: which rule run with 0 bytes? (e.g. since last week) Question 2: Which applic...

rkra by L2 Linker
  • 2276 Views
  • 1 replies
  • 0 Likes

Resolved! Limitation IPsec VPN performance

Hello I have 2 PA-500 in active-passive mode (Pan-os 6.1.0)In the model specification PA-500 shows that "IPsec VPN performance" is 50 Mbps.I want to make an IPSec VPN tunnel with a cloud provider. The speed that gives me supplier for the tunnel is 100 Mpbs guaranteed.Does this mean that my connection with cloud provider may not exceed 50 Mbps?...

Panorama 7.0.6

Hi, We have several Palo Alto FWs in diferent PanOS. W want to update our panorama to version 7.0.6 but we dont know if this panorama in 7.0.6 could manage FWs in PanOS 5.0??? Regards, Jesus C.

Resolved! Panorama userid obfuscation

For a new panorama deployment, a customer is asking if access to panorama logging can be configured in such a way that the USERID is invisible or obfuscated with a number. View this is in light of user privacy protection in an international context and with multiple admins looking at the data.

deecee by L0 Member
  • 2702 Views
  • 1 replies
  • 0 Likes

Blocking LinkedIn-Publish A Post

Has anyone been successful in blocking the Publish A Post option on LinkedIn. I don't kknow how to do custom application blocking if it is needed and tech support just said they would submit a feature request. Thank You

ANorton by L0 Member
  • 4326 Views
  • 3 replies
  • 0 Likes

Resolved! reset-client vs. reset-server

How do you decide on the action for a particular threat? For drop, tcp will still retry. With recent what is the general practice, reset-both, reset-client or reset-server?

Active Directory Testing

Hello Community, My first posting here. I have successfully configured LDAP / Active Directory on my VM ESXi. My Palo Alto can connect to the AD, see image However, I don't know how to test to see users in the monitoring logs. I will need a VM to log on to the AD from within the virtual environment but not sure how to do that. Can some...

LDAP.png

Resolved! Configured, Enabled Nodes not showing up under Minemeld > Nodes.

After reboot, none of the configured nodes (all enabled) are showing up under "Nodes". Tried restarting services and VM. Further configuration commits without any errors, but still no nodes show up. Minemeld logs attached. (/opt/minemeld/logs/*) Any ideas where to start troubleshooting? -Nasir

nbilal by L3 Networker
  • 8200 Views
  • 5 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels