General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 

 

In the past six

...

survey-livecommunity.png
jforsythe by Community Team Member
  • 14527 Views
  • 1 replies
  • 4 Likes

Resolved! Problem with Panorama

Hi all,

I am using Panorama 5.0.4. I have two device groups and let's say two administrators.

Is it possible to grant Admin A RW permissions to Device Group A and RO to device Group B, using the same login?

How can this be achieved?

Any help would be app

...

polbank by Not applicable
  • 692 Views
  • 1 replies
  • 0 Likes

Special characters in "common-name" of a certificate

I have configured a VPN portal and a gateway, both of them with an authentication profile that it's based on just an allow list (no authentication by RADIUS or anything else). The user is obtained from the common-name field of the user certificate th

...

jalvarez by L0 Member
  • 988 Views
  • 0 replies
  • 0 Likes

Resolved! PA-2050 and Juniper SRX reth config

There some problems with connection user to Juniper SRX through PA-2050.

The exercise is to make L2 connection between Wifi user to Juniper SRX through Palo Alto.

Please give some advice to make this configuration in Palo Alto.

I have no many experience

...

Ulugbekyu by Not applicable
  • 1244 Views
  • 2 replies
  • 0 Likes

Resolved! Could IPsecVPN use PBF instead of routing?

Hello guys.

I have a question about IPSEC VPN tunnel and is IPSEC VPN can use PBF instead of routing or not.

I think that tunnel interface could have ip-address (for tunnel monitoring) so I guess IPSEC VPN tunnel could use PBF instead of routing?!

So I

...

ttongfly by L3 Networker
  • 1919 Views
  • 4 replies
  • 0 Likes

Layer 7 protection with custom service (port)?

I'm having a discussion with my firewall engineer about rules in the PA5020.  If I define an application to be used, say SSL, and I want to run that on a random port, say 8443.  When I define that port (service) 8443 and choose the Application 'ssl',

...

Resolved! Migrating OSPF to the Palo Alto

Hello. I am working on the initial configuration of our new palo alto's. These are not in production yet. These new firewalls will be taking over our vlan's (will be the gateway) and will be running OSPF. I will stop the ospf instance on the local ro

...

ldavie by L2 Linker
  • 2136 Views
  • 3 replies
  • 0 Likes

Resolved! Adding domain to username for user identification

Hello

We are using RSA for user authentication with Global Protect.

We need to identify the LDAP group (Windows Active Directory) the user belongs to, but It doesn't work.

The reason is that the user we use for authentication doesn't include the domain

...

GlobalProtect auth with certificate, Safenet eToken

Hi,

For a PCI client, we are looking to get a (very) strong auth for a VPN connection with GlobalProtect, using certificate.

We use Safenet eToken for the repository of the cert (which is CAPI compliant on windows).

We want to use only cert generated by

...

rmenegon by Not applicable
  • 1138 Views
  • 0 replies
  • 0 Likes

iOS device "network errors" when SSL Decryption is turned on

Regarding SSL Decryption:

I originally put the whole category of "social-networking" under a Decrypt rule (mainly to decrypt Facebook to block Facebook games).  However, when I tested on my iPhone after that, LinkedIn, Twitter and Facebook all had "ne

...

uscit by Not applicable
  • 1179 Views
  • 2 replies
  • 0 Likes

GlobalProtect VPN with Windows-PKI (W2K8R2)

Hi

Currently we have a beta-environment for GlobalProtect-VPN on Windows7 (64bit).

Authentication with LDAP works fine.

But we want to use a client-certificate (user) from our internal Windows-PKI which is already rolled out to the endpoints.

Where can i

...

Resolved! OpenVPN

Hi,

Since application version 370 released, I have some trouble with openvpn :

Openvpn udp on port 443 didn't work anymore

Openvpn udp on port 1194 works

Maybe there is a bug on the new application version. Openvpn not on the default port didn't be recon

...

Policy Based Forwarding

We have a branch in a different state to which we have a DS3 MPLS circuit. We and our  branch office have there own ISP connections for Internet access. I would like to have redundancy build between both of our companies through IPSec VPN tunnel in t

...

Top Liked Authors