General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Issues with netflow.

I have configured netflow profile and applied to an interface. I dont see anything in session browser,packet capture or traffic. I have port 9995 for netflow with ip in trust interface (172.29.5.248). setup active timeout to 1min.

ssl sever certificat can't be verified

Hi, This issue is on a Palo-Alto PA-500. I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates. It tells me that this certificate is valid. Ok. thanls. But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that ...

About Facebook File Control?

Dear Sir, In facebook, There are many way to transfer file. Like In chat windows , Or In posting windows. In Paloalto App-ID facebook-file-sharing Description: Facebook file sharing is a feature offered on Facebook Groups that lets users share presentations, schedules, documents and many other file types with a group. You can post a fi...

BGP Active/Passive vs Active/Active argument

I'm running into an argument with our carrier for our 2 ISP links that I need to clarify. We currently have two 3050's with 2 ISP links coming into both devices in an Active/Passive configuration using PBR's to route traffic. We are adding a third ISP and dropping the slowest link, followed by implementing a BGP configuration with both ISP's....

POODLE BITES (and other Informational Vulnerabilities )

Just wanted to gauge what others are doing with regards to this particular vulnerability if anything. Historically this has been set to reset-both on this vulnerability. Which, by and large doesn't seem to cause that much of a problem on most sites, but I suppose the question I was asking is, is this something I should be blocking/resetting, o...

JRussell by L3 Networker
  • 4157 Views
  • 4 replies
  • 0 Likes

Resolved! USER-ID debug logs

Hi, I saw several articles which describe agentless user-id debugging and all show different ways (commands and output files), so I'm not sure which way is right and how to debug and see user login, logout and group mapping process for agentless user-id...I'll be very appreciate if someone share this information!

Tician by L3 Networker
  • 13414 Views
  • 1 replies
  • 1 Likes

Resolved! URL Filtering and CRL Download

We have PA Zone for which we have a very restrcitive URL filter , i.e. lots of categorys are blocked. The issue is that when a user in that zone goes to the SSL encrypted site and the browser tries to download the CRL for the SSL certificate it gets blocked becsue the CRL link either falls into Computer and Internet Info or Web Hosting, both ...

RC-BHF by L2 Linker
  • 2755 Views
  • 1 replies
  • 0 Likes

ChromeBook and Filtering on External Networks

I'm asking this from a perspective a a school district. Chrome devices (specifically ChromeBooks) have skyrocketed in numbers over the past couple of years. I was hoping to see development of the GlobalProtect client to encompass the ChromeBook (ChromeOS) platform. I guess what I'm asking for is an update to the previously asked thread: http...

P429-T by L1 Bithead
  • 4397 Views
  • 4 replies
  • 0 Likes

Resolved! How the interface may answer ping in this situation?

Hello for all. I had a problem that I resolved. But, I am posting because I could have solved of the best form. I have three links of internet. I have the firewall PA-200. These links are connected on three interfaces and the fourth interface is connected on my corporate network. The schema of links of internet is simple. This is controlled by P...

Bruce2 by L0 Member
  • 3041 Views
  • 2 replies
  • 1 Likes

Can PANOS support to export logs via API XML[through scp or ftp export log traffic]

Hello. My customer desire to export logs[traffic, threat, etc] via API XML The customer want that there is server which is requested to FW via API to get CSV File,,, he has already known how to export logs via CLI[SCP, FTP, TFTP] tftp export log traffic start-time equal ... like this I haven't found it yet.. Is anybody who can help me?

John_Lee by L2 Linker
  • 2889 Views
  • 2 replies
  • 0 Likes

How to architect Virtual PANs with AWS ELBs

We're at the initial stages of architecting our AWS environment and are considering using PANs to secure North/South traffic. The problem I am running into is the network design of how to get traffic to flow through the virtual PANs from the internet on their way to the front end web servers. The difficulty we're having is ELBs (Elastic Load Bal...

jjavier by L0 Member
  • 4937 Views
  • 2 replies
  • 0 Likes

Captive portal and url filtering .

Does captive portal work with url filtering. Getting all sorts of issues with captive portal .I works intermittently. running 6.1.7 spent lot of time with palo alto tech.

Integrating Panorama with existing PAN Firewalls?

I've inherited an environment where Panorama was an afterthought for 60+ PAN firewalls. Finally convinced management to buy Panorama after we terminated the reason for this mess and had to change passwords on 60+ firewalls individually. The problem I'm running into is that almost every firewall has different polcies, objects, network profiles...

  • 24379 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels