General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1294 Views
  • 0 replies
  • 0 Likes

PAN-OS Bi-Directional NAT and Nintendo Online Gaming

I have a couple of Nintendo consoles on the network which would like to connect for online gaming.

 

I am on a cable connection so am using Dyndns lookup for my external-IP.

 

I have the following Bi-Directional NAT policies configured.  

 

Applicati

...

screenshot_25.png
screenshot_26.png
screenshot_27.png

Resolved! Decrypting Dropbox

Hi,

I want to decrypt Dropbox but it doesn't work. I have a catch-all decrypt policy that decrypts any-any SSL. It works fine except for Dropbox. My understanding is that Dropbox is on the PanOS internal exception list so decryption is supposed to be

...

Global Protect Routing Table

Currently for Global Protect we route all traffic through the firewall.  Is there a way we can add IP’s to the routing table for GP clients only?  For instance, add GoToMeeting IPs and have all that traffic go out the Internet.  Is this possible?

rrau by L3 Networker
  • 6024 Views
  • 1 replies
  • 0 Likes

K-12 - QOS with PARCC Testing

Has anyone looked into doing any QOS for the PARCC assesment testing? Right now I'm not doing any QOS on our 5050, but think it would be a good idea to do something so the testing gets priority over some staff member watching Netflix during their bre

...

bbilut by L3 Networker
  • 1857 Views
  • 2 replies
  • 0 Likes

user to ip mapping with LDAP

I have a pa 3020 running 6.0.8 doing LDAP lookups to multiple edir servers,

 

I have many users that PA shows as unknown but when I look on the server I see they are logged in x.x.x.x

Why does this work for some but not all?

 

I have done the followi

...

ccboe by L0 Member
  • 1947 Views
  • 2 replies
  • 0 Likes

Resolved! Dedicated log collector licensing

How are dedicated M series log collectors licensed. We are planning a deployment with two M-100 appliances in an HA configuration. If we add a third M-100 as a dedicated log collector, do we need a third license for Panorama? 

Lepton by L0 Member
  • 4323 Views
  • 1 replies
  • 0 Likes

Resolved! User-ID redistribution SSL error

Hello,

 

I am trying to configure to 2 PA to share their user-id data.

I used the following guide: https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/user-id/configure-a-firewall-to-share-user-mapping-data-with-other-firewalls.html#61291

...

Marck.To by L1 Bithead
  • 4197 Views
  • 2 replies
  • 0 Likes

User Activity Reports on Panorama

 

When we generate a UAR (Using Monitor/PDF Reports/User Activity Report) on Panorama for a particular managed firewall, we do not get any broswing summary sections in the report. If the same report is run on the firewall itself, we do get that infor

...

Nig by L1 Bithead
  • 2283 Views
  • 2 replies
  • 0 Likes

ISP failover in PanOS 7.0.4

Hi, 

 

We are moving from Juniper ScreenOS SSG firewalls to PanOS 7.0.4, 3020 clustered firewalls. 

 

On our Junipers we make use of a feature called track-ip for Interface failover between ISP's...This basically works by pinging a far device on the

...

Resolved! Dynamic Block List Question.

 

Hello Community,

 

Blacklist (such as IP Void or SpamHaus) with a suggestion that we should block that IP.  

I'm hoping there's a way that we can leverage such a blacklist - for example, to have a rule in the FW that references an existing Blacklis

...

Apadilla by L3 Networker
  • 7118 Views
  • 8 replies
  • 0 Likes

Resolved! Agentless USER-ID - no matched record

Good Day

 

I have a PAN-5050 configure for agentless USER-ID to a W2K8 AD. We were getting user ids/ips in the logs but now we're not. The server-monitor is connect and now errors or failures to connect. When I do the cli commands (show user userids,

...

burtond by L2 Linker
  • 3487 Views
  • 4 replies
  • 0 Likes

Resolved! Botnet report full of cloud.typography.com entries

My weekly botnet report is full of entries like: 

"Repeatedly visited (32) the same malicious URL cloud.typography.com/"

 

I've checked this URL in the database and using the CLI, and it shows as computer-and-internet-info

Several tools I've used to

...

holtcg by L1 Bithead
  • 4988 Views
  • 2 replies
  • 0 Likes

Resolved! Deny & Allow

I have a rule that allows the administrators remote desktop access to our physical domain controller. While reviewing the traffic logs I can see that the PA is show allows and denies for the exact same traffic from my PC to the domain controller usin

...

jdprovine by L4 Transporter
  • 2211 Views
  • 2 replies
  • 0 Likes
  • 24179 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels