General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to traffic-shape traffic over public wireless to app-stores like (app-id) apple-appstore?

Hi,I'd like to implement qos traffic-shaping from our public wireless network to sites like apple's appstore or google's appstore.When i look at the monitor screen of our palo, i only see ssl traffic. Do i need to decrypt the ssl traffic first so i can determine if it's app-id is android-market / apple-store ??Our goal is to limit the amount of ...

Resolved! Allow remote host to port scan

I am looking to allow a single host on the outside to run an NMAP port scan. What can I do to allow this host to get an accurate picture from the outside without giving additional access that may skew the results? In addition I would need it to bypass vulnerability protection (TCP Scan 8001). Looking at my scan attempts I see the application typ...

mcocat by Not applicable
  • 10438 Views
  • 5 replies
  • 0 Likes

SCP export log on PA-7050 and SCP import log on VM-100

Hi,Anyone know if I can run a “scp export logdb” on a PA-7050 and then restore this logdb via a “scp import logdb” on a VM-100 ?I understand that this would override all existing logs on the VM-100 but that’s fine, I just want to make sure this would work.Thanks

Resolved! LACP Link-Down critical system alert from the passive node.

Hi guys,We enabled LACP for an aggregated groups on our firewall, It seems we are receiving critical system logs from the passive node every 5 minutes that the LACP is down! All the interfaces are up and running on the active firewall, So the critical system alerts are from the passive firewall interfaces, Any idea?System log from the passive no...

Resolved! How to use multiple authentication profiles for Global Protect VPN

I have a need for our employees to use LDAP in the authentication profile for VPN connectivity, but I also have outside third parties that need remote VPN connectivity as well. I want them to use local database user accounts. How can I do this? It seems that a given portal can only use 1 authentication profile type.I only have 1 external interfa...

kkrause by L2 Linker
  • 18913 Views
  • 6 replies
  • 2 Likes

ending captive session with browser close

Hi,Captive Portal is used for all LAN (no Active directory)we want to kill captive portal session when a client closes the browser.Any idea ? (we can install scripts or etc. to computers, they are not visitor computers)

Is the behavior in my tests normal or maybe I missed something?

I have a specific question. Our firewalls are able to decompress some files like .zip or gzip and after that we are able to analyze their content and detect some malicious files with threat prevention or WildFire.For the .cab file, the cabinet file compressed by Windows, which is not cyphered, I saw some tests and I was surprised that the conten...

VM Panorama utilizes 100% CPU always

We had a panorama VM upgrade recently to 6.0.8 with 4 cores CPU and 16 G memory.The moment it boots up the management CPU is always close to 100%. Any one ran in to this problem or any suggestion would be helpful.

RajeshB by L0 Member
  • 4750 Views
  • 5 replies
  • 0 Likes

allow googlebot crawler only

I found reference to this discussion but there were no details specifying how to allow googlebot crawls only.How to Allow Googlebot Through the Firewall I would like to only allow google and bing if that's possible. I can see options for google-analytics in the definition rules. Can this be done?

bino150 by Not applicable
  • 4847 Views
  • 3 replies
  • 0 Likes

GlobalProtect issue

Hi all,We have problem connecting to a VPN using GlobalProtect. We opened a case but maybe someone has an idea what's going on..The error message on GP client isError(4960): failed to get the tag gateways(T1404) Error(5401): Failed to get gateway list for external network.Erros on Palo Alto:GlobalProtect portal user authentication succeeded. Log...

L3 gateway Interface traffic relaying

Hello All,just want to share one thought about problem which I faced with. One of L3 interface on PAN 500 was configured as default gateway (192.168.0.1/24 sec zone "trusted") for one network. On that trusted network I have two servers, one terminal 192.168.0.10/24 and VPN 192.168.0.15/24. VPN clients with IP pool 192.168.50.0/24 are making conn...

Tician by L3 Networker
  • 2722 Views
  • 2 replies
  • 0 Likes

Resolved! HP MSM765 Syslog RADIUS auth using user agent

we have been trying for some time now to get our msm765 syslog to be read by our pa500 / user agent. we want to use RADIUS authentication on our MSM765 controller and for the agent to read the user to IP mapping. however we have the following issue.our syslog filter looks like thisour raw syslog string is02/20/15 13:17:36:568[Debug 372]: Syslog...

d_ballam by Not applicable
  • 4269 Views
  • 2 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels