General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4108 Views
  • 0 replies
  • 0 Likes

PA blocks spyware - identify compromised computer

Hi there,we're running the following setup:trusted zone | DC zone | InternetClient/Proxy/some old DNS Server| DNS Server| InternetI see that the PA is blocking malware traffic (app DNS). But the attacker is either the proxy, asking the DNS in the DC zone, or the old DNS server, asking DNS servers in the Internet.Unforunately that way I don't get...

Resolved! is it support ECMP protocol ??

Hi all.Is it support ECMP protocol from PAN??I can’t find whether ecmp protocol support from datasheet and knowledge base. does PA has any other similar protocol if not support ecmp?? Please refer to below URL for ECMP.http://en.wikipedia.org/wiki/Equal-cost_multi-path_routingRegards,Eugene

willstech by L3 Networker
  • 3714 Views
  • 4 replies
  • 0 Likes

802.1q tagged sub-interfaces on PA-500 v6.1 not working

I'm trying to consolidate multiple Layer3 interfaces into a single Layer3 interface using subinterfaces and VLAN tagging, but it's not working.I'm hoping someone can point out the error in my configuration.The current working configuration:FIREWALLethernet1/2 - 192.168.102.254, untagged, zone 102ethernet1/3 - 192.168.103.254, untagged, zone 103e...

Gp Configuration

Hello Friends,We want to configure our Remote VPN (Global Protect ) on two ISP and we should be able to manually switch the gateway at client end and no Lic is required for that?. Please suggest.RegardsSatish

Satish by L4 Transporter
  • 4975 Views
  • 5 replies
  • 0 Likes

HTTP Header - Logging NTLM Username

My PA firewall inspects traffic between my users and proxy server. The proxy server provides NTLM authentication. Is there a way of logging the NTLM authenticated username within the http headers?

ASCIT by L2 Linker
  • 5435 Views
  • 6 replies
  • 0 Likes

Replace a device (s/n) in Panorama Policy with an RMA s/n

Hello - Wondering if anyone has come across this issue. We recently had to RMA one of our firewalls and we have a fairly extensive / complicated policy set in Panorama which consists of the following:Shared Pre Rules targeted to specific firewalls Device Group Pre rules targeted to specific firewalls Device Group Post rules targeted to ...

Resolved! GlobalProtect Agent Question

I am configuring GlobalProtect and have a question concerning the Agent software. For security reasons, I configured GlobalProtect in "On Demand" mode for Remote Customers and do not allow the customers to view the Advanced View or save their logon credentials. We do not have the extended GlobalProtect licenses so currently we are not running ...

Palo sending email issue

Is anyone else having the "failed to forward log to mail server: aspmx.l.google.com" causing a "mailclient: error reply: 421 4.7.0 Email Senders Guidelines. l.12 - gsmtp" for google's mail?Possibly started with 6.14 and maybe 6.13. I had my email settings working up until I upgraded to 6.1.3 when it all stopped. I didnt change a thing except fo...

ulti by L3 Networker
  • 5551 Views
  • 2 replies
  • 0 Likes

Why did global protect disconnect? SSL_read() failed: 1 -1 socket error 0

I have a user that is reporting that when they use Skype video conf while connected via Global Protect the VPN connection is being dropped. Looking through the GP logs it seems to indicate there was a connection problem, but the client initiates the disconnect before the traffic logs indicates the session ended. Here are what appears to be the r...

bjdrawpv by Not applicable
  • 4539 Views
  • 1 replies
  • 0 Likes

Wildfire Email Link Test url

Hey All,Does there exist a way to test the Email Link feature of Wildfire with some sort of test url that always gets sent to Widfire and is always Malware?Like the http://wildfire.paloaltonetworks.com/publicapi/test/pe link to download a Wildfire test file?

mr.linus by L4 Transporter
  • 3538 Views
  • 2 replies
  • 0 Likes

Getting traffic from tunnel interfaces in MRTG

- I can plot data from physical interfaces (from the PA) in MRTG, such as for instancedata from Eth1/1 and Eth1/2. But MRTG's cfgmaker doesn't get any info about tunnelinterfaces. Could this be made possible, for instance by adapting some changes in the firewall. If so, which one(s) ?M.

Resolved! MIB for PanOS 7.0

Hello,where can I download the MIBs for PanOS 7.0?I guess I need to import new MIBs into my monitoring system in order to use the improved SNMP Features, right?Thanks,Detlev Weide

lavision by L2 Linker
  • 3682 Views
  • 2 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels