General Topics
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics

Discussions

Join Us for a Tech Deep Dive Miniseries!

 

Stop Zero-Day Threats in Zero Time with Nebula PAN-OS 10.2.

 

Join us live for an in-depth look at the latest advancements in cybersecurity, best practices, tips and tricks, demos and
more to protect your business and defend against threats in real

...

nebula-on-demand-tech-deep-dive-miniseries-live-community-banner-2600x600.jpg
jforsythe by Community Team Member
  • 465 Views
  • 3 replies
  • 1 Likes

Resolved! OCSP on SSL decrypt with self signed certificate

When enabling OCSP and having a self signed certificate for SSL decryption

(we push the certificate to all our domain clients)

will OCSP check my self signed certificate against the OCSP responder (and fail because it is unknown)?

Or will it only check

...

mr.linus by L4 Transporter
  • 2956 Views
  • 10 replies
  • 0 Likes

Resolved! Problem VPN Split-Tunneling

Hi everybody.

I've got a strange problem related to split tunneling in PAN configuration. The situation is:

- Portal and Gateway configuration in PAN-2050 with PANOS 4.1.7 (same results with 4.1.6 and 4.1.5).

- VPN client Cisco compatible (Windows and L

...

Resolved! Global Protect for Linux

Is there support for the Global Protect client for Linux? It's not a download option when logging into the portal via https. If not, is there a way to connect using Java? Would NetConnect work?_

Packet capture of specific Security Rule?

I need to confirm what traffic data (specific DNS Request strings inside the packet) is hitting two specific Security rules, so would like to capture just the traffic that is hitting these rules. Is there any way to do this?

I have run the Packet Capt

...

Netconnect File Extension

When I try to download the latest netconnect install file from the Software Updates web page it downloads without a valid file extension. When I download the file PanVPN-1.3.4 shouldnt it be PanVPN-1.3.4.msi ? I've tried renaming the file...

awdinfra by L0 Member
  • 1771 Views
  • 3 replies
  • 0 Likes

Resolved! Antivirus Compatibility Mismatch

Hi, i just realised that my two PA (active/passive) have an alert of HA Antivirus Compatibility. I have checked the version in Dynamic Updates and its the same in bot devices. CAn you tell me why this mismatch happens???

I attached an screenshot with

...

Nested Active Directory Groups

Can it handle nested Active Directory groups?

Security policy with a group which a user is not direct member of. When user tries connection through firewall then it checks the groups within the group (an so on).

Can it be configured how deep the nestin

...

Anon1 by L4 Transporter
  • 1792 Views
  • 5 replies
  • 0 Likes

Resolved! Mac OSx & UserID

I have a question. Maybe someone has run across this.

I am using the server monitoring function of Palo

I realize that I can use the user-ID agent and set it to never forget the user mapping, but I am looking for a more accurate way of keeping this map

...

JoeU by L1 Bithead
  • 2652 Views
  • 5 replies
  • 0 Likes

Security Policy's and NAT

Hi,

I Have configured a BYOD wireless ssid that is being forced to the internet via a port on our 2050. I am trying to get the network to be able to contact our mail server for exchange on mobile devices and also to have access to our content server r

...

mavant by Not applicable
  • 2434 Views
  • 11 replies
  • 0 Likes

Resolved! 2 isp 2vr asymmetric

Hi,

2VR 2isp,2 seperate default GW (2 ppoe modems)

PC A ---- internet through ISP 1

we want to RDP TO ISP2's public ip and make destination NAT to PC A

How can we make this work ?

New enforce symmetric return did not work .commit fails with ppoe is not su

...

panos by L6 Presenter
  • 1590 Views
  • 5 replies
  • 0 Likes

Destination NAT/PAT clarification

Prior to shooting myself in the foot I want to make sure I'm on the right track.

I have an application where I'd like to take inbound connections directed at a particular port on my untrusted "outside" FW interface and redirect them to the same port o

...

MCmgt by L2 Linker
  • 2810 Views
  • 8 replies
  • 1 Likes

Resolved! Google Mail for Business

Hi all,

Anyone has experience in using SSL decryption with Google Mail for Business? My concerns are the incoming emails will no longer go thru our mail content filtering engine and we don't have adequate tools to prevent data loss in outgoing mails (

...

Resolved! Question regarding ARP timeout

Hi,

I have a question regarding ARP caching and timeout on the Palo Alto platform.

Based on the output of the "show arp all" command, it looks as if the "default timeout" is 1800 seconds.  I am doing some work with failover for a cluster inside my fire

...

dsulli99 by Not applicable
  • 1214 Views
  • 1 replies
  • 0 Likes

Tool to generate 'phash' style hashed passwords?

We have a need to create password hashes offline, is there a tool or script available to take a cleartext password and generate a phash?

For example, the audit team wants to be able to select a password and generate the hash, so we can later paste int

...

snocc by L0 Member
  • 4995 Views
  • 2 replies
  • 0 Likes
Top Liked Authors