General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! not-resolved URL Category

We are seeing a large amount of url logs being categorized as 'not-resolved' at a rate of about 5500 per hour. After reviewing logs to compare it appears it started a few days previous. What is strange is a site will be categorized as 'not-resolved' but a second or two later it is properly categorized. For example: www.napaautopro.com category =...

lewis by L4 Transporter
  • 14300 Views
  • 13 replies
  • 1 Likes

NSS Labs Report - Mitigation for claimed vulnerabilities?

Seriously? | NSS LabsCould someone elaborate on the section which says:All PAN-OS devices require a configuration change to detect even the most basic TCP stream segmentation evasions. The “Mismatched overlapping TCP segment” protection in the Zone Protection profile is not enabled by default, which allows attackers to bypass the device complete...

Resolved! NAT Rules

Hello,I was wondering if anyone could explain the following scenario to me as I seem to have found a bug with NAT policies.On our PA-2050 v5.0.8 I have configure three zones: inside, dmz and outside, and a host in the DMZ. I created two NAT policies, one is static for the spam appliance (MX) and another is a catch-all for other servers in the DM...

MikeBull by L0 Member
  • 5013 Views
  • 4 replies
  • 1 Likes

Resolved! External Data Port Cabling

Halloi am setting up a new PA 3050 FW. I dont want to use the management port to connect to internet and download updates. So I am following the admin guide to "Set up an External Data Port" for updates. Now as per that:1. I set up a port, say e1/4 on PA 3050, as an internal port in "L3-Trust" Zone and give it a static IP address 192.168.35.100....

Resolved! Print policies/objects/rules

Hi,Is there any way to print the PA policies??? i would like to print the window with all policies NAT/security.... Its possible to do it or i would have to use "Print Screen" many times :''( thanks

SOC_CSG by L4 Transporter
  • 4957 Views
  • 5 replies
  • 0 Likes

Resolved! Unable to access PA-500 GUI "Creating Administrative Session"

Hello, Today, when i try to connect PA-500 user interface, after login, PA-500 WEB server shown (as usually) "Creating administrative session. Plase Wait..." for a while, and nothing happen. Chrome Browser shown "Page is not responding".I tried to login with other browsers, from other PCs - not result.I can access the CLI, i restarted web-server...

Resolved! url log without profile

Hi ,Why do we see url filtering logs although there is no any url profile ?logs related to denied app. like ultrasurf and hot-spot shield

Employee Privacy in the Global Enterprise - SANS Reading Room

For those of you with global Palo deployments, here's a paper to get you started on what you should know about employee privacy issues. This issue can be complex in countries outside of the U.S."Next Generation Firewalls and Employee Privacy in the Global Enterprise”http://www.sans.org/reading-room/whitepapers/legal/generation-firewalls-employe...

RyanF by L2 Linker
  • 2922 Views
  • 1 replies
  • 0 Likes

Resolved! Possible Issues with 6.0.5-h3

Has anyone discovered any issues with H3? I have an odd issue and am not sure if it has to do with the layer 4 changes in the hotfix to address the evasion issues.I have upgraded 3 client sites. No issues at 2 of the sites. On the third side, I have an issue. This client has a public web site in a DMZ. The ACL allows it to be directly accessed b...

SDorsey by L4 Transporter
  • 8804 Views
  • 7 replies
  • 0 Likes

Extended SSO Support for GlobalProtect Agents

Hi,GP 2.1.0 is now released with the extended SSO support: With Single Sign-On (SSO), the GlobalProtect agent wraps the user’s Windows login credentials to automatically authenticate and connect to the GlobalProtect portal and gateway. SSO has been enhanced in this release to so that when a third-party credential provider is being used to wrap t...

Hithead by L4 Transporter
  • 4755 Views
  • 5 replies
  • 0 Likes

Resolved! WAN interface connectivity loss logged anywhere?

Do the PaloAlto's have any functionality to monitor a wan link or tunnel and create a log entry if the link is down or there is significant packet loss? I am able to see these things through external monitoring tools but it would be nice to have a system log entry or something on the PANs as well.

bgirdner by L2 Linker
  • 8289 Views
  • 5 replies
  • 0 Likes

FTP Data - Handshake is not estabilished

Hello,we are struggling with this problem.There is a FTP Client and an FTP Server. Both on different sites. Between them is a VPN Tunnel build with PA 3020 and PA 5020.FTP is working - but sometimes not!!!!!We found the reason for this: This is what I can see at client's siteControlchannel (21) is UPClient asks "STOR myfile.txt"Datachannel Hands...

rkra by L2 Linker
  • 5964 Views
  • 4 replies
  • 0 Likes
  • 24448 Posts
  • 125 Subscriptions
Top Solution Authors
Labels