General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

UniDirectional Link Failure Detection without UDLD

Hi,

Does anyone know the network appliance could detect uni-directional link failure of SFP+ without UDLD?

I tried the test with PA-5060 and Juniper-EX,

but SFP+s kept link-up cause TX might continue to shot laser when RX came not to receive laser from

...

komure by Not applicable
  • 2934 Views
  • 1 replies
  • 0 Likes

Blocking Facebook apps without ssl policy

We are trying to let users to have read-only access to Facebook' but not allow them do posting or download anything from it.   We don't have SSL policy.  Can you block Facebook posting with you SSL policy decrypt traffic?

Thank you

awarsame by L1 Bithead
  • 2438 Views
  • 2 replies
  • 0 Likes

URL filtering Profile - URL in allow list does not work.

Hello,

PAN-OS 5.08

I have a security police to which applied a URL filtering Profile.

I have blocked the category "social-networking" and I need to allow "twitter.com"

I tried putting the URL in allow List:

*.twitter.com

*.twitter.com/*

www.twitter.com

But

...

SOC_CSG by L4 Transporter
  • 3134 Views
  • 3 replies
  • 0 Likes

Install GlobalProtect

Hi!

I have problem with installing GlobalProtect in our environment. We are using System Center
2012 to to install the GlobalProtect64.msi  with installation behavior “Install for user” but
the problem is that it only creates StartMenu ico for that us

...

unygren by Not applicable
  • 4416 Views
  • 4 replies
  • 0 Likes

Active/Active performance benefit/impact

Hi,

Anybody currently using or having had tested HA in an active/active mode with any insights into the the performance benefit or impact of such a setup?

Is the additional complexity worth the effort and is the throughput effectively increased compare

...

Resolved! TFTP file transfer on New Palo Alto PA500 Firewall

Hi Guys,


I have already my files on working tftp server and already connected via serial cable to the firewall. As i know i should also connect one end of patch cord to my PCs ethernet intrface and the other end to the firewall interface, but to with

...

Resolved! How to monitor pending commits

I'm looking for a way to externally check that there are no policy commits pending.

Is there an SNMP OID signalling a commit is pending?

Or, is there a SSH CLI command that shows a commit is pending?

I'm running a PA-3020 with PANOS 5.0.15.

Resolved! User-Id Agent log file behavior

Hello,

I have been running user-id agent in an environment and the log file size is increasing rapidly.

Is there a limit for the file size? and what will happen when the file reaches the limit?

In general, what is the best way to control its size?

File Blocking Block ZIP and Allow DOCX Extension

Hello,

I need to block files with zip extension. (action Block)

Also allow files with extension: doc, docx, xls, xlsx and pdf. (action ¿? ¿?)

What "action" can I use? or How can I create an exception?

The other extensions should ask me confirmation. (act

...

SOC_CSG by L4 Transporter
  • 2511 Views
  • 1 replies
  • 0 Likes

AEP[TRAPS]: ninja mode

Hello! Advanced Endpoint Protection Administrator's Guide [3.1] (https://live.paloaltonetworks.com/docs/DOC-8084) is mentioning that "Additional advanced EPMs are hidden and are only accessible in ninja mode". Could you, please, describe additional f

...

andreip by L2 Linker
  • 1949 Views
  • 0 replies
  • 0 Likes

CVE-2015-0235 Ghost

Just starting a thread for  CVE-2015-0235. Ghost

Anybody see any news from PA on this? I have not.

Cheers

choff123 by L3 Networker
  • 9229 Views
  • 11 replies
  • 0 Likes

tcpdump like packet capture on PA

how can check  dhcp packet on PA , for example using tcpdump -i Internal port 67 we see on unix/linux boxes.

how can we check same dhcp request and response packet on PA .

  • 24196 Posts
  • 100 Subscriptions
Top Liked Authors
Labels