General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to get PA-200 Split Tunneling Internet traffic only logs to forward to Panorama?

I have split tunneling setup on my PA-200. I have the logs being forwarded to Panorama. I would only like the logs from the Internet traffic to be forwarded to Panorama.I don't want the VPN tunnel traffic logs to be sent to Panorama.I have three security policies.Default Outbound - Policy for split tunnel Internet traffic.VPN Outbound - Outbou...

Resolved! create a any-ipv6 address object

Hey all,Is it possible to create a any-ipv6 address object?I tried with an object "::/0" (same syntax used to configure default route) but this seems to hit any-ipv4 address as well.Tried this in PanOS6.0.10, PanOS6.1.3 and PanOS7.0.0.0b23

mr.linus by L4 Transporter
  • 6375 Views
  • 4 replies
  • 0 Likes

PA URL FILTERING UPDATES force to update the HA peer

Hi, i have 2 palo alto 2050 in HA (active/passive). The active HA has intenet acces in order to take the palo lato updates but the passive PA doesnt have access to internet. The problem is that the active PA has a URL version updated but the passive has a version very old. what should i do??? there is any way to send this URL updates from Pa act...

SOC_CSG by L4 Transporter
  • 16265 Views
  • 12 replies
  • 0 Likes

Resolved! Questions about internal gateway

Hello everyone,I have questions about global protect internal gateway.1. What difference are between tunnel mode and non tunnel mode on internal gateway?Encrypted? or Something?2.If customer does not use external gateway, Can I set external gateway instead of internal gateway purpose for accessing internal resources?Because my customer feel heav...

Webui cert for HA PA's

I am trying to assign a external cert to the webui so I don't get the warning message anymore? I imported my cert to the primary box and the setting did not fully synchronize to the passive box. I noticed there is an import and an import HA, do I have to use import HA to make it synch to both boxes?

jdprovine by L4 Transporter
  • 7164 Views
  • 12 replies
  • 0 Likes

Resolved! Recommended Hardware for BranchOffices (PA-200 vs. PA-500)

Hi all,We're evaluating new IT hardware for some small/mid-sized branch offices in Asia. If we compare the PA-200 and PA-500 (Link) we don't see a technical limitation when using PA-200s instead of PA-500s. Most branch offices don't have Internet connections with more than 50 Mbps, but sometimes 100+ users. Is there a recommendation on the amoun...

oschuler by L4 Transporter
  • 3482 Views
  • 2 replies
  • 0 Likes

Find out more information from a listed Threat Protection

Hey all,Love Palo Alto Networks!! Wooo!Anyway, just wanted to know something, when I go into ACC (Application Command Center) under Threat Protection... and I get something like this...Nice to know I was protect from a possible Virus, but what is Win32.Generic.deaep? Google doesn't show anything... all the links are pretty much useless as all th...

Zewwy by L3 Networker
  • 4273 Views
  • 4 replies
  • 0 Likes

Globabprotect on demand mode

I have configured the GP agent to be on demand mode so you have to manually have to login in and it won't automatically log you in. But the client on my machine is still trying to login in automatically, is there another setting that has to be changed?

jdprovine by L4 Transporter
  • 4431 Views
  • 5 replies
  • 0 Likes

Threat prevention subscription

Is anyone using the threat prevention subscription and how are they configuring it? I know that there are things I want to block but currently I have only set it to alert. What is the best way to configure the security profiles to get the best result?

jdprovine by L4 Transporter
  • 5139 Views
  • 7 replies
  • 0 Likes

Custom report

Is it possible to create a report that shows the threat and what specific machine is being infected or attacked? We want to be able to use the PA and the reports to track down where the machine/pc or server so that we can remove/fix it

jdprovine by L4 Transporter
  • 2180 Views
  • 2 replies
  • 0 Likes

Can Palo Alto firewall prevent/intercept this JS in Github DDoS event?

Dear Sirs,On March 26 the Github has been attacked by a five-days DDoS. Many people pointed out that an javascript infected from China was very suspicious because it would connect to Github per 2 seconds. University of Toronto’s Canada Centre and Citizen Lab call this weapon of China as “The Great Cannon”.The problem is, can Palo Alto firewall p...

Resolved! Client Certificate Error

Hey All,Heres the Hardware and Software details:ModelPA-500Serial##############Software Version6.0.2GlobalProtect Agent1.2.3Application version452-2343 (08/26/14)Threat Version452-2343 (08/26/14)Antivirus Version1361-1833 (09/01/14)URL Filtering version4360TimeTue Sep 2 13:26:07 2014 Uptime52 days, 20:49:06User Systems:Windows 7 Enterprise 64-bi...

Zewwy by L3 Networker
  • 7290 Views
  • 2 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels