General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

qos report

Hi How can i generate a throuput report on my untrust interface .And how can i genearate qos report like class 1 and class 2 usage for a period of time ) Thank you

sib2017 by L4 Transporter
  • 4320 Views
  • 4 replies
  • 0 Likes

Minemeld AWS user data error

hi all, I spun up a linux server in AES and followed the instruction to import user data from here https://minemeld-dist.s3.amazonaws.com/0_9/minemeld-cloud-init-0.9.0rc2.b64 according to the instruction, the user data was encoded in base 64, but it doesnt seem to work. see attachment.

TS agent on XenApp 7.7?

Hi! As i can see the newest TS agent(7.0.2) is only supporting XenApp 5.0/6.0/6.5. I have a customer that wants to get UserIDs from Citrix and then use AD groups to limit access to resources. BUT the customer is running on XenApp 7.7. Anyone who has tried if this is working on XenApp 7.7?

Global Protect Slowness

We recently installed a PA-3020 on a 1G circuit and are experiencing very low speeds when clients are conecting in using GlobalProtect. When connecting in from home on a 20M connection we are seeing speed drops down to a max of 5M (mostly lower). We do not have QoS set up for the tunnel so they shouldn't be limited on the PA. We are only seeing ...

drischar by L1 Bithead
  • 11182 Views
  • 10 replies
  • 0 Likes

Problems with XFF cleaning

Dear all,we are getting more and more problems with the way PA handles the X-forwarded-for header.It is very useful in getting the internal client IP in a proxy environment. OTOH, you need to clean it before it goes out so that you don't leak internal IP addresses.This cleaning creates a problem.PA only replaces the content of the header with bl...

AndreasB by L2 Linker
  • 11157 Views
  • 14 replies
  • 0 Likes

GlobalProtect: Pre-Login and user cert based auth?

Hi All, I've successfully configured pre-login and can enter my creds in to the GP client the first time I log in and it works great. Is there a way to use a user certificate for the user auth and avoid any action on the users part for auth? Desired configuration: 1. Pre-login with computer cert issued by my CA 2. When the user logs in, use ...

record reached max ression number

HiPls advise if we have CLI cmd that record the PA box reached max session number till now ...So I can assess if it will reach our session limited .ThanksJeff Jin

JeffJin by L2 Linker
  • 4499 Views
  • 5 replies
  • 0 Likes

Resolved! Hardware Upgrade

Can anyone tell me the best way to upgrade from a HA pair of PA-2020's to new PA-3050's.

rrobins by L0 Member
  • 6186 Views
  • 3 replies
  • 0 Likes

Resolved! Not working captive portal in https

Users report me problems, when they launch web-browser with a website in https, captive portal is not shown and they can not surf on internet, but if they go into http website the captive portal is working. why is not being showed the captive portal in https webs?

Resolved! VPN connection problem

Good afternoon, When we are in an external network (for example wifi ) with IP range 10.10.XXX.XXX, and our computers are trying to connect to VPN, which has the same pool address 10.10.XXX.XXX, they can not. The connection is not established . GlobalProtect Portal uses as connection method "user-logon (Always ON)" and INTERNAL HOST DETECTION i...

SOC_CSG by L4 Transporter
  • 3981 Views
  • 4 replies
  • 0 Likes

Resolved! How is to work vsys instances?

I have two 5060 in cluster. I have new request to set up a 3 new vsys. So Currently these PA have the vsys1 by default, and I monitoring this PA via Nagios. My question is, When do I configure a multiple vsys, these vsys will be sending your own logs to syslog server ?. Best regards Andres

Apadilla by L3 Networker
  • 4216 Views
  • 4 replies
  • 0 Likes

QoS on Aggregate (AE) interface

Hi, I am using PAN 7.0.3. I got two GigaE interface to form the AE Interface, however, I cannot set the Max Egress value more than 1000. And also, from the QoS Statistics and never seen the runtime bandwidth goes more than 1000. If so, it looks meaningless to us for the aggregaated interface to have 2GBps.

Koala by L2 Linker
  • 7446 Views
  • 7 replies
  • 0 Likes

Wildfire - email notification issues

Has anyone else experienced wildfire email notifications not being sent to all team members? Basically we have 3 team members who are all setup the same to recieve wildfire email notifications. One team member gets about 95% of the notficitions via email the other 2 team members only get 5% of the notifictions via email. This has been ongoing ...

lewis by L4 Transporter
  • 4139 Views
  • 4 replies
  • 0 Likes
  • 24380 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels