General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! REST API and Powershell

Has anyone used Powershell to interact with REST API on PA500?When I use the Invoke-RestMethod cmdlet to try and generate a key, I get back an empty response. If I run the keygen through a browser, it successfully returns a key. Running 6.1.1.PS C:> Invoke-RestMethod -Uri http://<ip-of-PA500>/api/?type=keygen%26ampuser=<adminuser>...

sphi by Not applicable
  • 11494 Views
  • 3 replies
  • 1 Likes

Object references - 'where used'

Hi all,I'm new to the Palo Alto's, having cut my teeth on Stonesoft, Checkpoint and Sophos.One nice feature in those solutions was the ability to select an object (of any type) and be able to list everywhere that it was being used - from policies to groups.I've not yet seen a way of mimicing this in PAN-OS 6.0. Is there a way, or a work-around, ...

User-ID for Cloudware

Hi Guys,Just finding for options and thoughts to be honest...We have a service called Cloudware which is almost like terminal servers. What we are seeing is that users using a browser from these servers are not identified on the PAN as it is not covered by AD authentication.I am aware that it is not possible to run the TS client on Cloudware an...

How to traffic-shape traffic over public wireless to app-stores like (app-id) apple-appstore?

Hi,I'd like to implement qos traffic-shaping from our public wireless network to sites like apple's appstore or google's appstore.When i look at the monitor screen of our palo, i only see ssl traffic. Do i need to decrypt the ssl traffic first so i can determine if it's app-id is android-market / apple-store ??Our goal is to limit the amount of ...

Resolved! Allow remote host to port scan

I am looking to allow a single host on the outside to run an NMAP port scan. What can I do to allow this host to get an accurate picture from the outside without giving additional access that may skew the results? In addition I would need it to bypass vulnerability protection (TCP Scan 8001). Looking at my scan attempts I see the application typ...

mcocat by Not applicable
  • 10318 Views
  • 5 replies
  • 0 Likes

SCP export log on PA-7050 and SCP import log on VM-100

Hi,Anyone know if I can run a “scp export logdb” on a PA-7050 and then restore this logdb via a “scp import logdb” on a VM-100 ?I understand that this would override all existing logs on the VM-100 but that’s fine, I just want to make sure this would work.Thanks

Resolved! LACP Link-Down critical system alert from the passive node.

Hi guys,We enabled LACP for an aggregated groups on our firewall, It seems we are receiving critical system logs from the passive node every 5 minutes that the LACP is down! All the interfaces are up and running on the active firewall, So the critical system alerts are from the passive firewall interfaces, Any idea?System log from the passive no...

Resolved! How to use multiple authentication profiles for Global Protect VPN

I have a need for our employees to use LDAP in the authentication profile for VPN connectivity, but I also have outside third parties that need remote VPN connectivity as well. I want them to use local database user accounts. How can I do this? It seems that a given portal can only use 1 authentication profile type.I only have 1 external interfa...

kkrause by L2 Linker
  • 18787 Views
  • 6 replies
  • 2 Likes

ending captive session with browser close

Hi,Captive Portal is used for all LAN (no Active directory)we want to kill captive portal session when a client closes the browser.Any idea ? (we can install scripts or etc. to computers, they are not visitor computers)

Is the behavior in my tests normal or maybe I missed something?

I have a specific question. Our firewalls are able to decompress some files like .zip or gzip and after that we are able to analyze their content and detect some malicious files with threat prevention or WildFire.For the .cab file, the cabinet file compressed by Windows, which is not cyphered, I saw some tests and I was surprised that the conten...

VM Panorama utilizes 100% CPU always

We had a panorama VM upgrade recently to 6.0.8 with 4 cores CPU and 16 G memory.The moment it boots up the management CPU is always close to 100%. Any one ran in to this problem or any suggestion would be helpful.

RajeshB by L0 Member
  • 4685 Views
  • 5 replies
  • 0 Likes

allow googlebot crawler only

I found reference to this discussion but there were no details specifying how to allow googlebot crawls only.How to Allow Googlebot Through the Firewall I would like to only allow google and bing if that's possible. I can see options for google-analytics in the definition rules. Can this be done?

bino150 by Not applicable
  • 4783 Views
  • 3 replies
  • 0 Likes

GlobalProtect issue

Hi all,We have problem connecting to a VPN using GlobalProtect. We opened a case but maybe someone has an idea what's going on..The error message on GP client isError(4960): failed to get the tag gateways(T1404) Error(5401): Failed to get gateway list for external network.Erros on Palo Alto:GlobalProtect portal user authentication succeeded. Log...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels