General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PAN OS and TACACS+

Hi There,Is it possible to tie together a PANOS and TACACS+ for authorization of commands? If not, how it possible to restrict access for some cisco network equipment? Any ideas?

Oleksandr by L3 Networker
  • 4251 Views
  • 6 replies
  • 0 Likes

QoS based on DSCP marking

We have Mitel IP phone systems deployed across multiple IPsec VPN sitesThe voice packets are marked EF (DSCP 46) and signalling packets are marked AF31 (DSCP 26) automatically by the IP phones and PBX.Under QoS policies, there doesn't seem to be a way to classify traffic into PAN QoS based on DSCP marking.Assuming that QoS classification using s...

yikching by L0 Member
  • 3596 Views
  • 2 replies
  • 0 Likes

Resolved! Alerts

I have my Palo Alto setup to send emails out on critical alerts. If someone tries attacking an outside IP I will get 60 alerts sometimes all in a row. Is there anyway to get the email alert just once that the outside IP was hit 60 times as opposed to getting 60 email alerts?Thanks

aguley by Not applicable
  • 3745 Views
  • 3 replies
  • 0 Likes

Resolved! Backup Configuration of a PA-200

We had a near miss on our PA-200. Got it recovered (thanks, support team!) by reseting to factory default and restoring the configuration, but it would have been a lot quicker if we'd had a current configuration to restore from, instead of having to first save, then reset, then restore.But I want to automate the process of saving a configuratio...

bdunbar by L3 Networker
  • 9721 Views
  • 7 replies
  • 1 Likes

Resolved! can we block sending web based email

Hi all,Is there a way to block only sending an email from web-based email portals(all or common of them, hotmail,gmail etc)so that users can read their email but cannot send any ?

PanIst by L3 Networker
  • 4071 Views
  • 3 replies
  • 0 Likes

Java version detection and blocking old version

Hi,With more and more vulnerabilities in Java, I would like to know if there is any way in PAN firewall to identify and blocked non latest Java traffic? The goal is to identify machines and inform owners to update their Java version. If not then block the Java traffic from that host.Thanks in advance.

Global Protect and split-tunnel, strange behavior from Facetime

We have set up Global Protect with split-tunnel for mobile clients (iPhone, Android). The goal is that ActiveSync is using the tunnel to reach internal servers, and all other traffic can go directly to the internet. GP is set up to distribute routes to two internal networks to the clients through the Access Route parameter in Gateway configura...

arnljot by L1 Bithead
  • 4546 Views
  • 5 replies
  • 0 Likes

Resolved! PANOS 6.1 Related Log Detail View Enhancements

Greetings all!I have updated several PAN firewalls to 6.1. Today, I noticed this entry on page 5 of the guide:Related Log Detail View Enhancements To make it easier to correlate log information from a session, you can now click through the related logs in the Detailed Log View without closing the window and switching views. You can switch betw...

SDorsey by L4 Transporter
  • 5346 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama for logging/reporting ONLY

If I want to use panorama for extended logging and reporting functionality only, are there any settings or configuration needs that I should be aware of? Should I disable the panorama objects and templates?

jclingan by L0 Member
  • 5782 Views
  • 4 replies
  • 0 Likes

Resolved! About Captive Certificate

Hi all,To make visitors not having ssl warning for Captive portal page;is there a way to do that without purchase a certificate ?(no way for importing cert to the clients)

PanIst by L3 Networker
  • 4073 Views
  • 4 replies
  • 0 Likes

configuration basique Accès Externe

Bonjour,Je suis tout nouveau avec palo alto.j'ai installer une machine virtuelle VM-100 avec le model OVF, sans licence car je souhaite tester celle-ci en LAB.Une fois celle-ci installée, je configure l'ip de management 10.0.0.252/24ensuite arrivée sur l'interface Web, comment et que faire exactement pour configuré ma carte WAN?les informations ...

Resolved! Captive portal and SSL inbound inspection

Hi Guys, We have some questions regarding to captive portal and SSL inbound inspection:Can captive portal be used with SSL inbound inspection to filter users based on their client certificate while still maintaining a mutually authenticated TLS session between client and the end server.Can the client certificate used in the mutually authenticate...

MelLi by L2 Linker
  • 4512 Views
  • 2 replies
  • 0 Likes

Remote access to serial console - how to do it?

HelloI know that we live in modern world, with smartphones dual ISP and HA and etc. but in some countries we have different reality I'm looking for solution how to connect to serial console of PA firewalls remotelly using PSTN line.The idea is to use phone line not any kind of internet access bacause internet access is broken or PA device is in...

_slv_ by L4 Transporter
  • 8047 Views
  • 5 replies
  • 0 Likes

Resolved! PBF and failover

Hello all,I had a question regarding PBF and how the failover works.I have Internet circuit A and Internet circuit B, each through a different ISP. All traffic and VPN tunnels go through circuit A. I create a PBF rule to route web-browsing and ssl traffic only (using application-default) through circuit B. It is my understanding that failover...

ClintL by L2 Linker
  • 5061 Views
  • 3 replies
  • 0 Likes

YIK YAK

Due to Cyber-bullying issues we have blocked access to Yik-Yak over our Campus Wi-Fi network. The application filter worked for a few weeks but after a recent update to the yik yak app the filter is no longer functioning. I have had to resort to blocking IP's which is becoming a hassle since they have spread their service all over AWS.Any idea w...

wmumper by Not applicable
  • 7295 Views
  • 7 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels