General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! The User-ID active user limit for VM-Series

Hi,I've been trying to find out the user limit for the VM series, but without success so far. I'm assuming it's 64,000, as it is for the "low-end" physical models [1], but I'd like to see that confirmed somewhere. Can someone point me to the right document?Thank you,Moritz[1] https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/as...

Bit Torrent deny rule

Hello i want to block all bit torrent traffic between all zones on my PA devices. I have Panorama in place and wondering what is the best way to prevent bit torrent traffic?What settings should i use for application (bittorrent and/or bittorrent-sync) and for service (any or application-default)?Can i setup source, destination and zones to be an...

Dragan by Not applicable
  • 5509 Views
  • 4 replies
  • 0 Likes

GlobalProtect, multiple user-selectable endpoints?

I'm trying to setup two different versions of GlobalProtect SSLVPN endpoints. I already have a single portal + gateway configuration that only routes specific /24s through the VPN. I want to add a second setup that doesn't split-tunnel and instead passes all traffic through the VPN (for use on untrusted networks like public wifi).Do I need to ...

bradenmcg by L3 Networker
  • 3379 Views
  • 2 replies
  • 0 Likes

Resolved! Global protect license error

Receiving following error while commit.No Global Protect Portal licenseVsys1 portal "GP-Portal-Essilor" config "GP-Client-Config" modify gateways cutoff time will not take effect.Configuring committed successfully.Customer does not have GP license as Single portal and gateway access GlobalProtect does not require GP license.Please inform what co...

tac.in by L3 Networker
  • 4408 Views
  • 4 replies
  • 0 Likes

L3 forwarding

Hi Friendsl3 forwarding is not showing in pan os 6.0.3.RegardsSatish

Satish by L4 Transporter
  • 2811 Views
  • 3 replies
  • 0 Likes

Suppressing Global Protect balloon messages

I am trying to identify a way to either customize or disable some of the Global Protect client messages that are displayed. For example, if client on-demand mode is defined, every time the client initializes it will by default display a pop-up balloon message stating that it is in on-demand mode . Is there an option to turn that off or to cus...

Custom Redirecting

I understand how to create/edit a redirect page for blocked URLs globally. How do I set up a redirect page for a group of URLs created in Objects>Custom Objects>URL Category only?Thanks//moe

Pan(w)achrome - interface speed differences

Hello,I just started using Pan(w)achrome, version 0.7.1.5.So far, it has some useful information.I am trying to figure out why I have such a difference between my external interface receive rate (1.3+ Gbps) and my internal interface transmit rate (~300 Mbps).The internal receive and external transmit have the same bitrate (packet rate is off by ...

Cannot Ping SubInterface

Hi All,I recently added a sub-interface on a trunk to a Cisco switch. This trunk has several other VLAN's going to it, and all seem to respond fine on their IP's. This one I cannot ping from the Cisco switch on the same VLAN.Ethernet1/1.273 has an IP of 10.200.73.2/24 on it, with a management profile to allow ping from 0.0.0.0/0On the Cisco sw...

wocomike by L1 Bithead
  • 11809 Views
  • 7 replies
  • 0 Likes

Resolved! Alert: high : mdb: Exited 4 times, waiting x seconds to retry

Has anyone encountered the following alert message from your Panorama? Or do you know what it means? We have tried to restart the management plain through ssh but now since the restart we can not connect through the web interface. We have logged a ticket to support but was checking here to see if anyone has experienced this alert? Our panorama i...

lewis by L4 Transporter
  • 6937 Views
  • 4 replies
  • 0 Likes

Resolved! setup pan200

i am in the process of setting up a pan 200. i have configured the mgnt interface, 2 interfaces (1 internal, 1 external) each in there own zone and both in the same virtual router. the problem i am having is i cannot get to the internet or should i say have it pass traffic. i can ping all local devices LAN, i can ping this as the gateway on m...

How to use "Retrieve User Group" feature in RADIUS profile?

I would like to use my AD groups in Security rules (along with RADIUS and HTML Captive Portal). So far I managed to use "known users" only, seems due to a lack of Group attribute exchange between PAN and RADIUS (MS IAS 2003).I found the promising "Retrieve User Group" chekbox in RADIUS authentication profile settings but so far didn't find any r...

u3374 by Not applicable
  • 22819 Views
  • 10 replies
  • 0 Likes

Frequent Running Of AddrObjRefresh Blocking Commits?

Hi!I'm new here, so will probably be asking lots of dumb questions ... but hopefully relatively interesting dumb questions. Currently running PANOS 6.0.7 on a pair of PA-5060s (active-passive). Not currently live (switchover day is 17th January), and we're considering upgrading to 6.1.1 next week. Recently (last few days) ran into an issue where...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels