General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1186 Views
  • 0 replies
  • 0 Likes

Global Protect Failed to open sub key

Hello All,

i have problem with my GP. I configured it and for 99% users work fine. But a few has communicate "resend credential" and stuck. 

In log file PanGPA.log i have:

(T6992) 12/01/15 11:24:08:539 Error( 129): Failed to open sub key 'Software\Pa...

ITBT by L1 Bithead
  • 3726 Views
  • 1 replies
  • 0 Likes

McAfee Evader - did You use it?

Hello

I'm courius that someone is using it for testing PA device? What was the resoults?

You can download this tool from http://evader.mcafee.com/

Do You know other tools like this?

With regards

Slawek

_slv_ by L4 Transporter
  • 5379 Views
  • 3 replies
  • 0 Likes

Global Protect DHCP Options

I have a PA-500. I have a basic configuration for Global Protect up and working - certificates, agent settings, etc. All is well. The client can route to internal resources as expected.

 

Now, the next step I need to take for these VPN clients in trans

...

mkeller by L1 Bithead
  • 4964 Views
  • 4 replies
  • 0 Likes

OpenVPN behind PaloAlto

Hi!

 

We can't get OpenVPN to work. Our Juniper-SA works well.

 

The setup is only working without Firewall:

Laptop (static IP 80.0.0.4) attachted to an switch and the OpenVPN server attached to the same switch (eth1, dmz)

 

 

Our Policies:

 

Monito

...

palo-config-policy3.png
palo-config-monitor.png
Morneweg by L1 Bithead
  • 8231 Views
  • 7 replies
  • 0 Likes

Block the remote desktop acces with Palo Alto Network

Hello,

 

In or company i need to block the remote desktp access of a specific address to the critical server like database server.

I add a security rule in the PA-500 by block (ms-rdp and t.120) applictions to a specific address by without any result

...

RCHAIBI by L2 Linker
  • 10554 Views
  • 8 replies
  • 0 Likes

NAT and site to site VPN

Hello,

 

We're trying to build a Site to Site VPN connection with an other company. They are installing software on two of our servers (10.130.0.100 and 10.202.20.20) and they need the VPN to automatically transfer configuration and other files.

The

...

VPNPrblm.PNG

Resolved! Panorama Dynamic Updates

I see three locations for Dynamic Updates while logged into the Panorama device.

 

  1. Panorama Tab >> Dynamic Updates
  2. Panorama Tab >> Device Deployment >> Dynamic Updates
  3. Device Tab >> Dynamic Updates (for each Template)

I think I know what 2&3 are for.  

...

Blocking Malware Callbacks

Malware Callbacks for command&control and also for data exfiltration are often transported in

HTTP POSTs.

 

The URL blocking of category malware URLs seems only to block the HTTP response. The GET or POST request seems to pass untouched to the server

...

Unibw by L2 Linker
  • 3507 Views
  • 2 replies
  • 0 Likes

Interface question

Hi!

 

This is our network:

 

My question is about interface 1/6:

I can ping the juniper from outside the network. But I can only ping the OpenVPN Server if I configure the IP-Address 80.0.0.5/32 explicit in this interface. Without this entry (80.0.0

...

netz-skizze.jpg
interface-aktiv.png
Morneweg by L1 Bithead
  • 2435 Views
  • 3 replies
  • 0 Likes
  • 24171 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels