General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

URL Filtering Log shows FORWARD

Hey All - I have several URL-Filtering logs that come through with a category of FORWARD. Everything else is blank (URL, From Zone, To Zone, etc.). Can anyone shed some light on what this means?Thanks!Matt

Decryption certificate

Hi,I have a PA500 (OS 5.0.11)I already configured it for SSL Decryption with a self signed certificate.I need to use a Digicert Certificate. I already have a wildcard certificate with Digicert.Question is: can I use my wildcard certificate for SSL Decryption?How?I try to import my certificate but I cannot use it for SSL DecryptionThanksRegards

diennea by L3 Networker
  • 6685 Views
  • 5 replies
  • 0 Likes

FTP

How can I verify whether port 21 ftp traffic is being blocked by the PA 302?

infotech by L4 Transporter
  • 10134 Views
  • 17 replies
  • 0 Likes

Resolved! PA-200 - commit change and then nothing

I have opened a critical ticket, but was looking for community feedback on this issue.Setting up my new PA-200, troubleshooting a route problem. I removed a rule to simplify troubleshooting, hit 'commit' The progress bar reached '98%' then the device was unreachable by https.I called the colocation staff, asked for a power reset. The device n...

bdunbar by L3 Networker
  • 6042 Views
  • 4 replies
  • 0 Likes

Tunnel

I have a vpn tunnel that works fine most of the time and then is just goes down for no reason any suggestion

infotech by L4 Transporter
  • 19500 Views
  • 30 replies
  • 0 Likes

Resolved! Management PORTs

Hi guys ,how can i change the management port to other port than 443 ?Best Regards.Thiago Lima.

Thiago by L3 Networker
  • 3867 Views
  • 4 replies
  • 0 Likes

Special Character in domain name

Hi,I have a domain with special character "&" in the NetBios domain name. In the FQDN name this character has been substituted by "e".By user-identification, PAN discover the users, but some have the "&" character in domain name and some have "e" character in domain name. Then the user's identification doesn't operate well. There is a wo...

lauro7 by L0 Member
  • 3894 Views
  • 4 replies
  • 0 Likes

High Availability weirdness

Hi.I have a pair of 2020's (I know, don't comment - they're getting upgraded soon, I hope!) which run in active/passive HA pairing.This morning, I noticed the following entries in the logs on my primary (normally active) device2014/06/25 08:58:37 info ras rasmgr- 0 RASMGR daemon sync all user info to HA peer exit.2014/06/25 08:58:37 info...

darren_g by L4 Transporter
  • 8497 Views
  • 6 replies
  • 0 Likes

websense webfilter as proxy

Hi All,I have websense web filter license. I want to integrate it with PAN firewall. Could you share any documents to integrate it as proxy.?Please guide. Thanks

Javith by L3 Networker
  • 4018 Views
  • 2 replies
  • 0 Likes

Feature Request

Hi all,I have a feature request (hope PA respond to it...)It would be nice if we could schedule automatic backup configuration using FTP (preferred), TFTP or SMB protocol.Regards,HA

licenselu by L4 Transporter
  • 4138 Views
  • 4 replies
  • 0 Likes

Resolved! Blocking OS specific traffic?

Does anyone know if there is a way to block traffic sourced from a specific OS in our network?We were discussing legacy Windows XP machines. Since they are no longer supported or being updated it would be nice to be able to block them from the internet but allow internal connections to them. (We have a couple of legacy programs we need to keep f...

Curious: How are people doing User-ID?

Hey All -I am just curious to find out how people are doing User-ID? We are currently using the software Agents connected to DC's, and we read syslog from our Wireless Controllers to parse user to IP mappings for wireless. Our wireless solution is only about 50% accurate due to the fact that many times logs are written to the wireless controll...

Resolved! Globalprotect "Assign private IP address failed"

Hi,I had GP working from my Mac yesterday evening but today it's failing with "Assign private IP address failed" in the logs when trying to login with the same local user as yesterday, I haven't changed anything but I am suspicious it might have something to do with me setting only one simultaneous connection?Best regardsRichard

monitor range of ip traffic

Does anyone know how to monitor a range of IP traffic on the firewall? Note: i'm trying to view the historical traffic data on the firewall as it's not pertinent to set up a new rule and monitor all traffic to/from the range requested of me.i'm currently running version 10.0.5 on a PA3020 and i've been requested to check for any traffic from a...

bdapice by Not applicable
  • 9876 Views
  • 3 replies
  • 0 Likes

Upgrading PanOS from v5 to v6

Hi,We're currently running codebase 5.0.11, and would like to go to 6.0.3.Here are a few questions I have.1) This is a fairly new install. When we migrated our config from our ASA to the PAN, the only reason I didn't go to the 6.0 codebase is because some of our objects didn't move over properly. For instance, Service Groups and Address Group...

wocomike by L1 Bithead
  • 3349 Views
  • 2 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels