General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

2 Factor with Palo Alto, best solution?

What does everyone have setup as far as 2 factor goes?I have a consultant here and we're thinking about going to the Microsoft MFA server route. Seems ok but not very flexible for things other than VPN.Any feedback on other solutions would be appreciated. I was hoping to get all external client VPN using 2 factor, next I would like to have 2 fac...

choff123 by L3 Networker
  • 4318 Views
  • 3 replies
  • 0 Likes

How can I configure Global Protect for on-demand as well as pre-logon

Hello,I have a scenario whereby I need to offer an on-demand VPN solution to untrusted endpoints as well as an always-on solution for my trusted endpoints. Running through guides I have been able to run a pre-logon VPN that has successfully allowed me to authenticate the workstation then make use of User-ID to identify and allow users into the n...

mwhite by Not applicable
  • 10654 Views
  • 8 replies
  • 0 Likes

PA error '"useridd - virtual memory limit exceeded, restarting"'

Hi,I have a cluster A/P of PA3020, PanOS 6.0.5. Im having this error in Monitor-Log-System: '"useridd - virtual memory limit exceeded, restarting"Im not feeling any strange behaviour in Palo Alto, i dont know if this error should produce any impact.........what this critical error does???? how to solve it???thanks

SOC_CSG by L4 Transporter
  • 3442 Views
  • 1 replies
  • 0 Likes

About Minimum Password Complexity

Hello,I have questions about Minimum Password Complexity.If "minimum length" is set to some value, all accounts of administrator and local-DB are limited by this value of minimum length.But if "Require Password Change on First Login" is set to enable, only accounts of administrator are limited by it not local-DB. Is it right?If yes,Does "Passwor...

Wildfire question

Hello, I have a general question about wildfire. We would like to have wildfire inspect email attachments and send suspect files to WF for scan and remediation. My question is....how does this work? Does the firewall hold the email and wait for a fix from wildfire before forwarding the email? If it does hold the email, what sort of delay does th...

PA-500 isn't allowing some Google services (Play store, calendar sync, etc.)

Pardon the noob query or lack of actual technical knowledge in our PA-500 but I've been asked by my supervisor to see what might be blocking some Google services/apps on our new PA-500. I've tried to monitor the IP address (my personal cell phone) and gain some insight via the monitor tab and the traffic and url filtering components of this moni...

kirkc by Not applicable
  • 5667 Views
  • 5 replies
  • 1 Likes

Migration Tool 3: Missing Checkpoint NAT Rules

Hi All,I found an interesting problem while migrating a firewall policy from a Checkpoint system. Has anyone seen this problem before? Checkpoint NAT:Checkpoint has a special kind of NAT that you can configure on an object I'm going to call the "Automatic Hide NAT Gateway". You configure a private address object and then bind the NAT to that ...

New Project - PAN-OS 7

Hello Everyone,I'm starting a new project where I will be migrating Juniper Firewalls to PAN-OS.I would like to hear an opinion if there is a point to migrate to 7.0 instead of latest 6.1.x.I would appreciate complete and well explained suggestions.Thanks,Val

Replace Panorama Virtual Disk

Hi All,we are running a fresh installation of Panorama VM and need to allocate more space for logging & reporting.This scenario is well explained in the Panorama Admin Guide on Page 163 ff. but we are wondering if it is neccessary to export and import the System Logdb or could we just skip this Step? What will be the possible consequences be...

Management profile setup on the outside interface for remote management, Panorama not communicating.

I have a management profile setup on my outside interface at a VPN site for remote management. I have my in-band management port settings set to blank fields. Panorama doesn't establish communication with this firewall.I am wondering if it is because the management ip information is blank, or do I need to configure something else to allow Panor...

Layer 3 Stops Passing - All PanOS versions incl. 6.1.3

I have opened this with TAC a while ago but I continue having issues with Layer 3 not passing through the untrust/internet interface at random times. I have had this happen 5 to 10 times on different PA-200's. Some have repeated. I was hoping a firmware upgrade to 6.1.3 would finally fix this but yesterday one of my first 6.1.3 units locked u...

dusk2dusk by L1 Bithead
  • 12082 Views
  • 13 replies
  • 1 Likes

how to Evaluate PA 7.0.0 on v sphere VM100

Hi All,Can some help me how to Evaluate PA 7.0.0.1. I have installed VM 100 series with PA 7.0.0 on vshere environment.2. I have PA 5050 with PA 6.0.10 in production network.3. How to check ACC on my VM 100 series with PA 7.0.0.4. How traffic traps can be processed through VM.

KMallela by L2 Linker
  • 2849 Views
  • 1 replies
  • 0 Likes

How to convince PAN to know UID mapping for all vsys

Hi,We use multi-vsys and XMP API for UID. It works fine for vsys1. We use this sintax for login:<uid-message> <version>1.0</version> <type>update</type> <payload> <login> <entry name="user1" ip="10.1.1.1" timeout="20"> </entry> </login&gt...

segap by L1 Bithead
  • 3466 Views
  • 2 replies
  • 0 Likes

Resolved! New Logjam Attack

Hi,a new leak was found in diffie hellmann...http://arstechnica.com/security/2015/05/https-crippling-attack-threatens-tens-of-thousands-of-web-and-mail-servers/https://threatpost.com/new-logjam-attack-on-diffie-hellman-threatens-security-of-browsers-vpns/112916(german) http://www.heise.de/newsticker/meldung/Logjam-Attacke-Verschluesselung-von-ze...

Hithead by L4 Transporter
  • 7686 Views
  • 4 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels