General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 709 Views
  • 0 replies
  • 0 Likes

Resolved! Using a large destination-domain blacklist

Hello,

I am considering the use of a domain name blacklist published by the DNS-BH project in a custom URL category that will block access to any of the included domains.  However, the list is over 12K entries long, which obviously doubles when I add

...

schaleg by Not applicable
  • 2605 Views
  • 2 replies
  • 1 Likes

Resolved! Globalprotect Mobile - no cert found

I've seen post like Re: IOS Global Protect APP - Required Client Certificate is not found but the fix was to manually import certificate to phone..How do I make my GP on droid to auto-download cert and connect ? I have same problem on Windows PC , ma

...

niuk by L3 Networker
  • 4852 Views
  • 3 replies
  • 0 Likes

Radius timeout greater than 30 seconds

I am working with Microsoft MFA for some RADIUS based "cloud" dual factor authentication.

MFA recommends a RADIUS timeout of 60 seconds due to the nature of their solution but PAN restricts RADIUS to 30 seconds as a maximum.

Is there anyway to bypass t

...

kk555 by L0 Member
  • 3042 Views
  • 2 replies
  • 0 Likes

URL filtering issue.

Hi Friends,

i am facing one issue with url Filtering my site category is showing malware- sites but when ever i am trying to check with ( https://urlfiltering.paloaltonetworks.com/testasite.aspx ) its showing travel category. please suggest.





Satish by L4 Transporter
  • 4206 Views
  • 8 replies
  • 0 Likes

Resolved! Match UserId problem

Hi, we have 2 PA in cluster Active/passive. We have done the fail-over and when the secondary PA is working i can see userid is not maching. I have checked all the Userid agent config and state and everything is ok. I have restart all the userids age

...

SOC_CSG by L4 Transporter
  • 3650 Views
  • 5 replies
  • 0 Likes

Dynamic Updates Problemes

From this night with last dynamic update of Applications and Threats the detection of private IP's in Geo IP location changed from origin private IP to unknown. Does anyone have the same issue? Since this morning with last dynamic update of Applicati

...

Resolved! Two Global protect Portals on one gateway - possible?

Folks.

I have a need to implement certificate based login for most of our corporate PC's to Global protect - so they pre-login and get domain scripts etc when the remote users logon.

However, I also have a number of PC's which aren;t corporate owned (a

...

darren_g by L4 Transporter
  • 6910 Views
  • 7 replies
  • 0 Likes

Resolved! IP Mappings Disappear Too Soon in log

Hi,

We have two PA-3020 in HA state, PAN-OS is 5.0.4 and we have configured 4 User-ID Agents (for now, in this troubleshoot stage, we are focused on only one agent).

Problem is in IP – user mapping. Sometimes in logs we see user and in very next momen

...

Resolved! What happens when a User-ID agent restarts?

I have been using the agentless user-id but it seems to be overloading my firewalls so I am moving to a separate agent.  I am trying to decide whether I need one or two though and need to understand what happens when an agent restarts.

When it loses t

...

djr by L4 Transporter
  • 5522 Views
  • 6 replies
  • 0 Likes

Web Interface access from Internet

I have PA-200 connected to Internet , but mgmt interface disconnected right now. Do I have to piggyback mgmt to one of remaining Ethernet interfaces in order to get access to web interface from Internet ? Plus port forward rule ?Let me know

niuk by L3 Networker
  • 7275 Views
  • 17 replies
  • 0 Likes

Question On NAT Configuration

Hello All,

I have a PA-200 at home, sitting behind a Comcast modem, that hands out  a single DHCP address.

I also have a Meraki Z1 VPN device associated with work, that I have behind the PA-200.

The Meraki requires that the source port not be translate

...

No GUI Access: FW-6.1.0: Session Time Out

I have a PA-200 with 6.1.0.  I can SSH in fine to mgmt.  When I try GUI, I get to the login page.  When I login with correct credentials it says Session Timed Out.  I think it's a disk space issue. When I show system disk-space SDA2 is at 100%.  Ever

...

Access only to Office 365

Hi,

We have many client computers with no internet access (only intranet and email).

Since we are migrating our email to Office 365, client computers need access to Office 365 (via Outlook and Web browser). Not only mail services, but also licensing, o

...

spopovic by Not applicable
  • 7807 Views
  • 8 replies
  • 0 Likes
  • 23972 Posts
  • 114 Subscriptions
Top Liked Authors
Labels