General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PANOS 7 on PA-2020 ?

Will it work ? I don't mean like is it compatible.I mean: Will it be manageable at all, seeing that version 6 is already a management nightmare ?Is anyone on PA-2020/2050 on version 7 and what are the experiences ? I see some changes that may be useful for alleviating management (eg Time-Based Log andReport Deletion), but will it be enough ?

dieter_b by L4 Transporter
  • 8144 Views
  • 9 replies
  • 0 Likes

Globalprotect still cant report missing patches on MAC OS?

The last version that didn't have this "known issue" was 2.2.0, based on release notes. Even the most recent release, 2.3.1, has bug id 77018 and wont report missing patches on the mac. Any idea when Palo will resolve this? It seems to severely limit a key feature we and others use Globalprotect as a vpn solution if one can't enforce HIP checks ...

ulti by L3 Networker
  • 3548 Views
  • 2 replies
  • 0 Likes

Device Capacity Planning

I am trying to get my head around device throughput maximums. As an example the 3020 is speced as such:2 Gbps firewall throughput(App-ID enabled1)1 Gbps threat prevention throughput500 Mbps IPSec VPN throughputAre these throughputs simultaneous? In other words, can I have 2Gbps of Firewall through put and 500Mpbs of IPsec traffic, or if I have 5...

dpayne by L1 Bithead
  • 2913 Views
  • 1 replies
  • 0 Likes

Lync Federation Traffic

Hi Guys, Recently we've configured Lync 2013 on our network. What i've noticed on the PA external firewall is the Lync federation traffic from the internal lync clients to for example 'Skype clients' on the web or other organizations is classified on the PA as 'unknown-tcp'... on port 443. Currently i've got a security policy purely allowing 'un...

PAN-DB URL Category List

Hi Everyone! I'm being asked to provide a report of all of the applications, categories and URLs we are currently blocking. Does anyone know how to obtain this?

dgoins by L1 Bithead
  • 2989 Views
  • 2 replies
  • 0 Likes

Global Protect - User login from only one device at a time

Hello, I have configured global protect and was able to connect successfully. But is there a way to restirct user login from only one device at a time?. Meaning if the user has a laptop and a smart phone , the user should connect either from the laptop or from the smart phone at time. Please help me to resolve this issue ASAP. Thanks and Regards...

Resolved! UserID Built-in Syslog listener - Limitations?

We use the Syslog integration in the PAN Agents to forward User/IP-mappings from our wireless controllers to PA 5020 firewalls. We are considering to move the Syslog integration to connect directly with the PA5020 instead of the PAN Agents. But i remember having read something about limitations on the built-in Syslog reciever. That we should st...

Resolved! Outlook timeout issues

DescriptionWe are experiencing a timeout problem when using outlook/exchange across the PA firewall.When the RPC connection between Outlook and Exchange is idle, the PA apparently terminates the connection. This causes the Outlook client to hang/stall until restarted - and thereby establishing a new RPC connection. When the timeout occours, a Ba...

palo alto networks configuration

hello, I configured a PA-500 with routing mode in our company . I set the zone , the security rules , the nat rules . I allow all traffic from trust zone to untrust zone. But the problem there is no internet connection. We use a DNS server , that is in trust zone.I add a security role from untrust zone to a trust zone (with addressof DNS server)...

RCHAIBI by L2 Linker
  • 1939 Views
  • 1 replies
  • 0 Likes

SSL decryption inconsistency

Hi, I have enabled decryption on a small group for testing purposes. I have a simpel 2 rule setup, first exluding financial, health and custom white listed and then decrypt everything else. I have a hard time finding out why the same site in the same browser on different pc's behave differently. For example my colleague got ERR_SSL_PROTOCOL_ERRO...

Resolved! Processes on the Palo.

Hi,There are various processes that maybe restarted using the debug command. Most are self explanatory. But whats the difference between l3-service and routed ? and webserver and management-server ? and vardata-receiver.> device-server Device server process> l3-service L3 services server process> log-receiver Log R...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels