General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! GlobalProtect and OS X 10.10 (Yosemite)

Hello,some of my colleagues are testing OS X 10.10 and the global protect client does not work. I read that Apple changed something with their signatures and when I take a look into the info.plist of the GlobalProtect Client it looks like this software is build with 10.6# less /Applications/GlobalProtect.app/Contents/Info.plist....<key>DTS...

Same QoS Profile Applied to Multiple Interfaces?

I have a single QoS profile applied to a pair of internal interfaces as seen in the screenshot below:In this case, will the two internal interfaces have a single shared maximum egress number or will the full maximum egress apply to each interface separately? In other words, are the QoS limits per interface or per profile?Thanks!

Resolved! Some advise

Hi there,I am trying to deploy a network that is connected directly to my PA box over a wifi connector and I am hitting some stumbling blocks. I wondered if someone might be able to offer any advise.The scenoria is this.I have an office that is connected to my office via a wifi transmitter. These wifi use the 172.16.5.x range. There is to be a f...

JRussell by L3 Networker
  • 4464 Views
  • 5 replies
  • 0 Likes

PAN-OS 5.0.6 SNMP

server:~ leo$ snmpget -M /usr/share/snmp/mibs -m ALL -Pu -v3 -a SHA -A xxxxxxx -l authPriv -u nagios -x AES -X xxxxxxx 10.48.1.10 `snmptranslate -On PAN-COMMON-MIB::panSessionMax`PAN-COMMON-MIB::panSessionMax = No Such Instance currently exists at this OIDserver:~ leo$ snmptranslate -On PAN-COMMON-MIB::panSessionMax.1.3.6.1.4.1.25461.2.1.2.3.2Do...

Teamviewer application not allowed by policy

I'm encountering a strange situation where teamviewer is not allowed by the policy in which it is defined but is instead blocked by my clean up rule.I have all the dependencies matched but for some reason the firewall does not match on the rule where teamviewer is configured but only matches on the deny all clean up rule. There are no other logs...

tajman by L1 Bithead
  • 7543 Views
  • 4 replies
  • 0 Likes

VPN - PA to PA - need internet traffic to go through additional device one hop inside PA

Remote site has a PA-200HQ has a PA-2020.I have the VPN setup between the two so that they are connected to each other. I need the internet traffic from the remote site to pass through our content filter that is connected to the PA-2020 at the HQ. the content filter is not seen by any devices, it is transparent to all devicesTraffic...

Resolved! 6.0.4 group mapping issue?

I started running into this group mapping issue after update a client to 6.0.4. We have a policy which matches on an Active Directory group for SSLVPN and what they can access. The same A.D. group is used in the Kerberos authentication profile to auth to VPN. After the update, these users are no longer matching on this policy. There is a policy ...

SDorsey by L4 Transporter
  • 2685 Views
  • 1 replies
  • 1 Likes

Policy schedule end notification

I have a policy scheduled to run for 50 days, is there a way to get a notification at the end of the schedule time period when the policy goes inactive/disabled?

jlg by L0 Member
  • 3075 Views
  • 4 replies
  • 0 Likes

Agentless User ID problems with IPv6

We are using an agentless user id system with four domain controllers. IPv4 and IPv6 is used inside and outside our organization. The PA box fails to identify users that run IPv6. Turning off IPv6 on the Windows clients fixes the problem. The problem is intermittent so it is hard to track down. Running 6.0.3 software.

rlawsha by L1 Bithead
  • 3213 Views
  • 4 replies
  • 0 Likes

Dropbox Uploaders

I've noticed that when using the dropbox basic uploader the filenames are logged under data filtering correctly however when you drag and drop files into dropbox the filename is recorded as "chunked_upload".Is there a way to figure out the actual file name or enforce the basic uploader? It's nice to be able to see the actual file names of upload...

depps by L1 Bithead
  • 3586 Views
  • 2 replies
  • 0 Likes

Palo Alto support Windows Server 2012 R2?

Hi,At this moment we user Userd-ID agents on our WIndows Server 2008 R2 AD servers. But we want to upgrade all the servers to Windows Server 2012 R2. Does Palo Alto already support userd-ID agents on Windows Server 2012 R2 and what firmware needs to be installed on the firewall?

ZEBIT by L3 Networker
  • 3788 Views
  • 4 replies
  • 0 Likes

HA Split Brain After Upgrade from 5.0.8 to 6.0.3

We have a pair of 5050s that we recently tried to upgrade, however we ran into an issue where once both of the PANs were upgraded they went into split brain. Its currently setup with some basic HA active/standby settings for 5.0. so I'm not sure why this would change in 6.0.3. We had to roll back to stay within our maintance window. Has anyone e...

Palo GUI: Selecting lines (Multiselect)

Hello,I would like to put 20 FQDN Names in a Group ir directly in a policy.AAAA1AAAA2AAAA3AAAA4....AAA20You know what I mean, it takes a long time :=(( ... or there is a way how to select more names I do not know.Roman

rkra by L2 Linker
  • 3839 Views
  • 5 replies
  • 0 Likes
  • 24415 Posts
  • 125 Subscriptions
Top Solution Authors
Labels