General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Unable to commit config - Invalid Auth Profile After 7.0.5 update

Hi, We recently updated to 7.0.5 and I cannot commit changes anymore. Error: ______________ Invalid global authentication profile POV-Auth-Profile, only radius auth profile or auth sequence is supported. Configuration is invalid Validation Error: deviceconfig -> system -> authentication-profile 'POV-Auth-Profile' is not a valid refere...

PCoIP traffic getting dropped because it's using SSL

I have VMWare View clients and I'm trying to set up the rule with the vmware-view App-ID, but the traffic gets dropped at PCoIP. The PA logs are showing tcp/4172 as SSL, even though PCoIP has port tcp/4172 defined. Is this an issue with the App-ID not identifying secure PCoIP?

Maxstr by L3 Networker
  • 11099 Views
  • 13 replies
  • 0 Likes

Globalprotect and simple SSL VPN?

It appears that, after a user has authenticated to a Globalprotect portal for the first time, they are prompted to download and install client software. Does Globalprotect (or Palo Alto in general) provide the option of simple client SSL VPN? ie; when a user logs in, an applet is invisibly downloaded and installed in the background to provide VP...

Upgrade 6.1.x to 7.0.x

In the release notes of 7.0.5-h2 there is now this information: Before you upgrade to PAN-OS 7.0.3 or a later PAN-OS 7.0 release, you should review the information about how to upgradea firewall to PAN-OS 7.0. Additionally, if virtual system (vsys) configuration is not enabled on your firewall or appliance, youmust reboot your firewall or appl...

Anon1 by L4 Transporter
  • 9180 Views
  • 10 replies
  • 0 Likes

Bug in password-string when using GlobalProtect with LDAP?

We had some users, who were not able to use VPN. they alway got XML parse-errors in the GlobalProtect Agent log. We finaly found out, that this users had '<' or '>' in theire passwords. when thy changed theire passwords in some string without these characters, the xml-errors disappeared and thy could login. we are using GlobalProtect Age...

inheco by L0 Member
  • 3076 Views
  • 2 replies
  • 2 Likes

PA-VM Update Check Fails

We have recently deployed PA-VM to ESXi for testing and we have found that any attempt to upgrade the unit fails with a very vague message. cfg.platform.serial': NO_MATCHES 'cfg.general.vm-mode-type': NO_MATCHES 2016-03-10 09:14:42.447 -0800 updater error code:-1 2016-03-10 09:14:48.140 -0800 Error: refresh_uploaded_image_info(pan_ops_common.c:...

xandout by L1 Bithead
  • 12614 Views
  • 10 replies
  • 0 Likes

IP SLA - but not dual ISP. Receiving and Forwarding from the same Interface.

hi, I know PA doesn't have IP SLA and i've read documents that talks about using VR and PBF to handle dual ISPs.this works with an ASA but not sure how to do it with PA. But there's a slight difference on my implementation and it seems to fail with a lot of SSL sites: I have two links at each site.First Link, ISP <----> Palo alto (10.1.1.1...

7.0.3 upgrade

I am planning on upgrading the PA 5050 os from 6.1.7 to 7.0.3. I have been reading over the changes and I think it would be beneficial to see examples instead of description of what changes are , anyone have any recommendations

jdprovine by L4 Transporter
  • 16737 Views
  • 27 replies
  • 0 Likes

Global Protect w/ OTP RE: disconnect/recovery timer tolerance?

We have implimented Global Protect with radius authentication, username/password and a second prompt for OTP, this works great most of the time. We have noticed that when our users connect from poor WiFi, or internet connections, there are times where connections drops out momentairly. This results in Global Protect disconnecting. The user the...

pwebber by L2 Linker
  • 3470 Views
  • 3 replies
  • 0 Likes

Resolved! Block Vpn

Hi, How to block ssl vpn and ipsec vpn going from trust to untrust . I suspect few users are using like free vpn services like tunnel beer and hola vpn . How can i search those users from palo alto log. Some users are connected from inside to outside world (for official purpose ) using cisco anyconnect (ssl ) and ipsec .And i don't wa...

sib2017 by L4 Transporter
  • 5733 Views
  • 2 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels