General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PA blocking returned traffic!!!

Hi,I've deployed PA-500 recently, and I'm experiencing an interesting situation.PA-500 is deployed in virtual-wire, and I'm filtering only my main ISP connection (ISP 1). The connection for ISP 2 goes directly to the router.We have a web server, which accepts requests from users through ISP2, and replies back but the router sends the replies thr...

Besfort by L2 Linker
  • 4426 Views
  • 2 replies
  • 0 Likes

HA broken after upgrading to 6.0.3

Hi,We have just upgraded our 5020s and 3020s to 6.0.3 and encountered an issue, where the secondary device became the Active one and the primary displays this error, only on the 5020:does anybody else had this issue or knows how to solve it?Thank you.

MMCiobanu by L3 Networker
  • 18640 Views
  • 28 replies
  • 0 Likes

Resolved! 'enable-user-identification' turned on!

Hi everyone,I wanted to do user based filtering on PA-500, but after I've successfully connected PA with active directory, and applied a security policy on user based I get this warning:Warning: Rulebase 'security'Rule 'LAN-r2'; Zone 'LAN' does not have 'enable-user-identification' turned on.Does anyone know how to enable user identification?

Besfort by L2 Linker
  • 3653 Views
  • 2 replies
  • 0 Likes

HA queue full

Hi, im receiving this snmp trap in my Palo Alto (PA-3020 PANOS 6.0.3). Checking the system logs i see each 15 mins this log message "HA-queue-full". Why is this happening?

SOC_CSG by L4 Transporter
  • 7675 Views
  • 13 replies
  • 0 Likes

HA queue is full

Hi there,I'm not sure if anyone else has seen this alert show up on their devices but I have Critical system messages sent to me by email and I have received this afternoon every 15 minutes a message saying "HA queue is full". I made a small tweak to a random description in a policy line so that I would be offered the oportunity to do a commit a...

UKRB by L3 Networker
  • 4668 Views
  • 4 replies
  • 1 Likes

Resolved! URL Rewrite - any update in new PanOS 4.1?

We are increasingly seeing the need for a URL rewrite feature - we had hoped to use it for one of the ways to force Google SafeSearch (vs. the existing option of blocking searches using an app signature)We now would like to use YouTube for Schools, which depends on URL modification:http://support.google.com/youtube/bin/answer.py?hl=en&answer...

keklund by L1 Bithead
  • 17658 Views
  • 25 replies
  • 1 Likes

Failed to execute op command

We frequently face an error for fetching the group-mapping in the user-id tab. The error is normally shown up as failed to execute op command. One of the reason can be invalid credentials in the ldap configurationTroubleshoot this error with Tail follow yes mp-log userid-log2014-05-04 14:31:21.052 +0400 connecting to ldap://[192.168.0.199]:389 ....

Westcon2 by L3 Networker
  • 8064 Views
  • 5 replies
  • 0 Likes

Turn off Application ID globally?

Can one turn off the application awarenes globally to set up a PAN as a L4 firewall? Trying to get some comparison stats against the old L4 only (non PAN) firewall and the new PAN.thanks.

blarney by Not applicable
  • 5155 Views
  • 6 replies
  • 0 Likes

PAN Dual ISP Failver Best Practices

I have setup dozens of PANs with multiple ISPs and failover but have some questions in regards to best practices..1. Is PBF the only way to handle failover? If not, can the same be achieved via HA Link/path monitoring or is that specifically for device/firewall failover? 2. This is mostly in regards to what is processed first in the firewall. If...

SDorsey by L4 Transporter
  • 9299 Views
  • 11 replies
  • 0 Likes

Unknown File Types

Hi all,we like to block or be alert when the file types .edrw and .easm (eDrawing) are passing the PA. Currently nothing is shown in the Monitoring Data Filtering.Any idea how to get PAN to update file types in security profiles? Can I somehow report it to PAN?

Hithead by L4 Transporter
  • 5192 Views
  • 5 replies
  • 0 Likes

NAT Performance Issue

Hi All,I recently migrated a client from a Fortinet firewall to a PANW. Most of the Virtual IPs from the Fortinet were migrated as bidirectional Source NATs.One specific server had issues where outside traffic would intermittently not be able to connect with the server. I troubleshot the issue and couldn't find anything wrong with the NAT or a...

Resolved! USER ID Issues

Hi All,My name is Paul Mathew and I am working as a Network Engineer at American School of Dubai, in UAE. Our environment is 99% MAC and IOS devices, and some of you were aware of Mobile Account concept in MAC. Let me explain briefly about it. Mobile account means when we login to a MAC machine as network user we create the mobile account so tha...

ajay by Not applicable
  • 11127 Views
  • 10 replies
  • 2 Likes

FILE BLOCKING NOT INSPECTING ZIP CONTENT

Hello everyone,I'm trying to block download of CPL files (PE) using a file blocking profile. We are trying to create it in a way which assures that even zipped CPL Files will be blocked. We created the profile but it did not work on HTTPS sites, just on HTTP sites. We were wondering if its necessary to create some kind of Decryption Policy or so...

  • 24415 Posts
  • 125 Subscriptions
Top Solution Authors
Labels