General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Required: PAN IPSEC Hub best practices for 300 route based IPSEC tunnels

Pan documentation is very weak on large scale mutli-vendor IPSEC hub terminations. Can someone help out and provide best practices, reference architecture, guides, pitfalls or experiences?My design goals: - Separate VSYS - Use dynamic routing for Tunnel Interfaces. (Either OSPF with stub areas to inject default to remote tunnels or ...

Issue with AD integration after OS upgrade.

Hi Friends.i am facing AD integration issue after PAN OS upgrade OS version 6.1.2. The firewall connection with AD server breaks at random and the AD users disappear from the firewall. After a while the firewall connection with AD server gets restored automatically.RegardsSatish

Satish by L4 Transporter
  • 2826 Views
  • 2 replies
  • 0 Likes

Resolved! How to send test email from CLI

Hi,I can send test email from GUI as belowHow can I send same test email by CLI?One of my customer does not allow me to use GUI, so I need to know this test command.I could not find command under 'test' and 'request'Cheers

emr_1 by L6 Presenter
  • 7083 Views
  • 4 replies
  • 0 Likes

WF-500 Configuration Help.

Dear Friends,I am facing some challenge during the WF-500 configuration. please find the below configurationMGT FW- IP :- 192.168.1.10/26GT- IP :- 192.168.1.2 MGT WF -IP :- 192.168.1.11/26GT :- IP :- 192.168.1.2But problem is that, when we are try to check admin@WF-500> show wildfire last-device-registration all :- status is failed.firewall ...

Satish by L4 Transporter
  • 3197 Views
  • 3 replies
  • 0 Likes

Block Activesync connections for disabled users?

Is there any way to block ActiveSync connections at the FW for disabled users? I have several users that have left the company and their accounts have been disabled, however they still have ActiveSync configured on their mobile devices trying to connect to our CAS server. While they are being denied, the login failures are filling up my logs. ...

Resolved! CNSE Exam Study Guide Rev B - Pass Mark

I am cracking on with study for the CNSE exam but on reading the latest release of the study guide have got a bit confused regarding the pass mark.In the Rev B of the study guide the pass mark is shown as 60% but in the original release it was set at 100 questions in 2.5 hours with a pass mark of 70%.Has it been reduced?The FAQs on the education...

No traffic in traffic log - VM100

Hi Guys,Following on from my last post - Site-to-Site VPN - Palo alto to Cisco Router issue i am experiencing an issue with my PA VM100, there is nothing in the traffic logs....this is running on VMWare workstation 11But there is traffic flowing through the firewall 100%, it is functioning perfectly, with the exception of the lack of traffic log...

how to handle Google SSL traffic?

Hello,I am new to PanOS devices, we recently got PA-200 router which is quite different from classic routers. Long story short - my problem is SSL traffic, I am trying to prioritize our traffic since for now we have only 10Mbit link, we have people working remotely over VPN, we have our own VoIP gateway in office, and there are people who are ac...

Nils by L0 Member
  • 4211 Views
  • 3 replies
  • 1 Likes

Captive Portal to Internal Servers

I have a client that currently uses an ISA server to restrict access to back-end web servers. The users authenticate at the ISA which then redirects to the back end web server.Palo Alto firewalls were sold as replacing this authentication mechanism using Captive Portal. Is this a possible use? I've only seen examples of Captive Portal for out...

QoS maximum number of interfaces???

I have a PA-3050 and I need to add more QoS interfaces...I receive a message that says "constraints failed: Maximum number of interfaces reached". I can't find any documentation that states there is a max. number of QoS interfaces...where is it? If this really is a maximum, is it just a licensing issue?

mike_cc by Not applicable
  • 4264 Views
  • 3 replies
  • 0 Likes

Resolved! How to setup multiple IP Public address on PA-200

Hi,We're facing an architecture where there are multiple address that needs to be used for a specific pool of IP from the LAN interface.Let's supose that we have 3 IP PUBLIC address 10.X.X.2; 10.X.X.3 and 10.X.X.4 and the gateway has the IP 10.X.X.1From the LAN interface we might expect to get a range of IP Pool addresses192.168.1.X to 192.168.1...

Resolved! No information showing up in Monitor->Logs->Traffic

Dealing with my first experience with Palo Alto Firewalls. I am working with the vmware appliance version. I have two rules/policies current configured. One allows all traffic outbound and the other allows only ms-rdp traffic inbound. This is a lab situation until I feel comfortable with deploying in a production situation. I have one host b...

RNutter by Not applicable
  • 3773 Views
  • 2 replies
  • 1 Likes

Resolved! Subinterface

Hello I have a PA500 firmware version 6.0.7. All interfaces are used, can I create a subinterface? I need to make a new segment. What is recommended to do that I need?Thank you

Antivirus Security Profile Exception

I want to create an exception action for a specific antivirus ID (which happens to be outbound traffic). The default action is “alert” and I want this one ID to be “drop”. This is possible for the spyware and vulnerability profiles, but my problem is that it looks like the antivirus security profile exceptions are ONLY “allow”. How can I configu...

JohnPa by L1 Bithead
  • 2529 Views
  • 2 replies
  • 0 Likes

Resolved! Server Certificate Verification Failed

Within the past couple of days I am starting to get reports from users that while trying to sign in with GlobalProtect they are receiving the following error:Gateway X.X.X.X: Server certificate verification failedNo changes have been made on the PA. Any suggestions for places to start looking?

mcocat by Not applicable
  • 9715 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels