General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

URL filtering Profile - URL in allow list does not work.

Hello,PAN-OS 5.08I have a security police to which applied a URL filtering Profile.I have blocked the category "social-networking" and I need to allow "twitter.com"I tried putting the URL in allow List: *.twitter.com *.twitter.com/*www.twitter.comBut it does not work.I have also tried creating a Custom URL Category but neither works.How can I do...

SOC_CSG by L4 Transporter
  • 4454 Views
  • 3 replies
  • 0 Likes

Install GlobalProtect

Hi! I have problem with installing GlobalProtect in our environment. We are using System Center2012 to to install the GlobalProtect64.msi with installation behavior “Install for user” butthe problem is that it only creates StartMenu ico for that user. The next userthat logs in can’t find GlobalProtect in the start menu. The next user can’t see...

unygren by Not applicable
  • 5724 Views
  • 4 replies
  • 0 Likes

Active/Active performance benefit/impact

Hi,Anybody currently using or having had tested HA in an active/active mode with any insights into the the performance benefit or impact of such a setup?Is the additional complexity worth the effort and is the throughput effectively increased compared to active/passive?Any info or advice would be appreciated!

Resolved! TFTP file transfer on New Palo Alto PA500 Firewall

Hi Guys,I have already my files on working tftp server and already connected via serial cable to the firewall. As i know i should also connect one end of patch cord to my PCs ethernet intrface and the other end to the firewall interface, but to with one mgt? or the basic ones?how can i set up the ip address and the gateway from the CLI? and also...

Resolved! How to monitor pending commits

I'm looking for a way to externally check that there are no policy commits pending.Is there an SNMP OID signalling a commit is pending?Or, is there a SSH CLI command that shows a commit is pending?I'm running a PA-3020 with PANOS 5.0.15.

Resolved! User-Id Agent log file behavior

Hello,I have been running user-id agent in an environment and the log file size is increasing rapidly.Is there a limit for the file size? and what will happen when the file reaches the limit?In general, what is the best way to control its size?

File Blocking Block ZIP and Allow DOCX Extension

Hello,I need to block files with zip extension. (action Block)Also allow files with extension: doc, docx, xls, xlsx and pdf. (action ¿? ¿?)What "action" can I use? or How can I create an exception?The other extensions should ask me confirmation. (action Continue)Is there any way to do this?Regards,DiegoMensaje editado por: Cos seg

SOC_CSG by L4 Transporter
  • 3617 Views
  • 1 replies
  • 0 Likes

CVE-2015-0235 Ghost

Just starting a thread for CVE-2015-0235. GhostAnybody see any news from PA on this? I have not.Cheers

choff123 by L3 Networker
  • 12566 Views
  • 11 replies
  • 0 Likes

tcpdump like packet capture on PA

how can check dhcp packet on PA , for example using tcpdump -i Internal port 67 we see on unix/linux boxes.how can we check same dhcp request and response packet on PA .

Blocking Teamviewer.

I am testing the ability to block teamviewer on my network. I have a rule that should block the application. In the traffic monitor, I can see the denies for "Teamviewer-base", but it does not prevent the application for being "ready to connect", nor does it prevent me from connecting to this PC remotely. Any ideas or thoughts?

No URL-Log of HTTP/1.1 204 No Content

Hi,The PA seems not to output a URL log when HTTP response code "HTTP/1.1 204 No Content".On the traffic logs, the PA could classified the category of HTTP.But there is no log related with the same Session ID.According to the pcaps on the client PC,the browser requested HTTP GET, but the server replied "HTTP/1.1 204".You can see the same issue o...

komure by Not applicable
  • 3420 Views
  • 2 replies
  • 0 Likes

Issues with Content Update 483-2549

FYI - Having major issues with last night's content update. Inspection of traffic from our client environment to our domain controllers is causing significant logon/logoff delays. I changed from an app rule to a traditional port/service rule (as app updates have broken things in my environment often) and that made no difference. I reverted to...

  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels