General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! QOS on Interface with 20 Mb

Hello,

I want to restrict bandwidth on interface e1/2 with 20 Mb

I have created QOS Profile with wireless and applied that on interface e1/2.

Enclosed are the snapshots for your reference. Please advise that it who to test this profile.

Thank you.

Suspicious DNS Query Action

Hello PAN Community,

I would just like to know if its possible to edit or change the default action for a specific suspicious DNS query?

We have a situation here where what we wanted to happen is to drop all the packets for suspicious DNS query instead

...

SSL VPN - Basic Questions

What basic steps have to be complete to allow a remote user to enter an ip address in their browser and get the ssl vpn authentication screen? We currently get an eventual timeout when we try to connect from a browser.  We followed the basic GlobalPr

...

shank by Not applicable
  • 5760 Views
  • 11 replies
  • 0 Likes

Resolved! Making server available with NAT doesn't work

Today I tried to configure our PA500 firewall to make a server from our DMZ zone available for Office 365. But first I will explain our network topology.
In our company we have 2 internet lines, one for internet and the other one as backup. After this

...

ZEBIT by L3 Networker
  • 2199 Views
  • 2 replies
  • 0 Likes

User-ID sometimes missing ntlmdomain\ on the firewall

Hi,

I've recently seen this a couple of times on completely separate firewalls / AD infrastructures (a 2050 cluster and a 3020 cluster, both running 5.0.8). User ID is setup and working fine along with LDAP group mapping

However on the odd occasion use

...

Dpeters1 by L2 Linker
  • 5425 Views
  • 6 replies
  • 0 Likes

Wildfire - is the full subscription worth it?

Apologies for the somewhat blunt title but it really is as simple as that

I've been using the bundled WildFire service for some time and did begin to wonder if it was working until it pinged on a couple of zero day Zeus trojans - seems our folks are

...

How to setup a redundant IP?

I'm trying to setup DSL as a redundant internet provider, incase the Cable goes down.  I saw a 3.1.1 document on Dual ISP Branch Office Configuration and got confused.  Our PA-500 is using 4.1.6 Wondering if anyone could help me on this?

ethernet1/1  

...

ssoiret by L0 Member
  • 2876 Views
  • 1 replies
  • 0 Likes

How to test your firewall

We have a Palo Alto PA500 with several security rules. It seems okay, but the CEO asked that I'm sure the company is secure.

So the question is, how can I test we are safe from the outside world?

ZEBIT by L3 Networker
  • 4721 Views
  • 6 replies
  • 0 Likes

PA-3050 stops processing traffic

Has anyone had a PA-3050 stop processing traffic? Our PA-3050 started dropping all traffic today (internet access, DMZ, etc.), we failed over to the standby unit and were able to restore service.

Currently we have a support ticket opened but wanted t

...

PANOS 6.0.2 release date

hello,

is there a confirmed release date of PANOS 6.0.2? A month ago I had a case open, where the support guy has told me that the expected release date is arount the 21th of April. Today is the 24th and still nothing

thanks

Rudolf

Silent deployment of Global Protect Agent

Hi,

We use MDT to deploy new computers in our company and I have found that if I run the Global Protect agent using the silent switch the install finishes but no virtual adapter is created and the VPN does not work. If I remove the silent switch so th

...

bcsgroup by L2 Linker
  • 2413 Views
  • 1 replies
  • 0 Likes

Captive portal bypass

Anyone familiar with a way to bypass captive portal for non-browser-based applications? Doing some testing with an eval unit from Palo alto and have configured agentless DC monitoring and using captive portal auth for a fallback. If a user hasn't alr

...

ccscott by L2 Linker
  • 5665 Views
  • 7 replies
  • 0 Likes

PAN-DB URL Filtering Updates

Hi,

We have a couple of PA devices configured in HA mode. I just want  to ask if it is normal that only the active firewall gets the URL filtering incremental updates. eg. FW-01 (active firewall) gets updated to version 2005.12.811 and FW-02 gets stuc

...

NelsonA by L0 Member
  • 3860 Views
  • 4 replies
  • 0 Likes

Problem with NAT rules

Hello

Task is simple, give access to 3 IP from Internet to camera on non-standart ports. Ports and  local IP are:

192.168.220.251:554 -> x.x.x.x:554

192.168.220.251:80 -> x.x.x.x:8881

192.168.220.251:8554-8557 -> x.x.x.x:8554-8557

where x.x.x.x is one

...

_slv_ by L4 Transporter
  • 5476 Views
  • 1 replies
  • 0 Likes

UIA - Not domain user Identification Problem

Hello,

I have a problem/doubt with the user-id and in particular with the identification of the local machine users.

Internet access is only allowed for domain users and if the users enter in their computer with the domain account They don't have probl

...

  • 23579 Posts
  • 103 Subscriptions
Top Liked Authors
Labels