General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to test your firewall

We have a Palo Alto PA500 with several security rules. It seems okay, but the CEO asked that I'm sure the company is secure.So the question is, how can I test we are safe from the outside world?

ZEBIT by L3 Networker
  • 6802 Views
  • 6 replies
  • 0 Likes

PA-3050 stops processing traffic

Has anyone had a PA-3050 stop processing traffic? Our PA-3050 started dropping all traffic today (internet access, DMZ, etc.), we failed over to the standby unit and were able to restore service. Currently we have a support ticket opened but wanted to know if anyone here has had a similar experience. Thanks!

PANOS 6.0.2 release date

hello,is there a confirmed release date of PANOS 6.0.2? A month ago I had a case open, where the support guy has told me that the expected release date is arount the 21th of April. Today is the 24th and still nothingthanksRudolf

Silent deployment of Global Protect Agent

Hi,We use MDT to deploy new computers in our company and I have found that if I run the Global Protect agent using the silent switch the install finishes but no virtual adapter is created and the VPN does not work. If I remove the silent switch so the install pops up then click next all the way through it install correctly and creates the virtua...

bcsgroup by L2 Linker
  • 3190 Views
  • 1 replies
  • 0 Likes

Captive portal bypass

Anyone familiar with a way to bypass captive portal for non-browser-based applications? Doing some testing with an eval unit from Palo alto and have configured agentless DC monitoring and using captive portal auth for a fallback. If a user hasn't already authenticated to captive portal it is blocking apps that go over port 80/443 such as ms-upda...

ccscott by L2 Linker
  • 10606 Views
  • 7 replies
  • 0 Likes

PAN-DB URL Filtering Updates

Hi,We have a couple of PA devices configured in HA mode. I just want to ask if it is normal that only the active firewall gets the URL filtering incremental updates. eg. FW-01 (active firewall) gets updated to version 2005.12.811 and FW-02 gets stuck to version 2005.12.000? Thanks,Nelson

NelsonA by L0 Member
  • 5736 Views
  • 4 replies
  • 0 Likes

Problem with NAT rules

HelloTask is simple, give access to 3 IP from Internet to camera on non-standart ports. Ports and local IP are: 192.168.220.251:554 -> x.x.x.x:554 192.168.220.251:80 -> x.x.x.x:8881 192.168.220.251:8554-8557 -> x.x.x.x:8554-8557where x.x.x.x is one of IP belongings for my PA and is used for NAT from this zone to untrust.I created secur...

_slv_ by L4 Transporter
  • 6258 Views
  • 1 replies
  • 0 Likes

UIA - Not domain user Identification Problem

Hello,I have a problem/doubt with the user-id and in particular with the identification of the local machine users.Internet access is only allowed for domain users and if the users enter in their computer with the domain account They don't have problems, but some times when the users enter with a local machine account the UIA installed in a ser...

Resolved! FW can not update anti-virus signature.

HiFW can no update anti-virus signature.Please look at the following logs.admin@PA-3050> request anti-virus upgrade install file panup-all-antivirus-1278-1748.tgz Content install job enqueued with jobid 44admin@PA-3050> show jobs processed Enqueued ID Type Status Result Completed -------------------------...

Resolved! For OSPF or EIGRP App-id in vwire deployment between L3 devices with dynamic routing.

Hello,There is a device with vwire between L3 devices using dynamic routing protocol(ospf or eigrp).I checked ospf or eigrp app-id in traffic log but there are only two ~ three logs for 2 hours.I think they are few logs.The communication between L3 devices has no problem.I just wonder it.In addition, I can not connect a device right now. I can d...

HA binding "both option" not working in NAT policy

Dear all,I've configured my Palo Alto Cluster in a L3 Active / Active cluster setup.While I was trying to implement a NAT policy (Source Address Translation), it turns out that the only options that are working are: "0" and "1", as a reference to the member of the active/active cluster which should take care of the Address Translation.It turns o...

wimjuste by L1 Bithead
  • 8569 Views
  • 3 replies
  • 1 Likes

PANDB is not categorising correctly

HiHas anyone experienced this problem and found a solution for it ?Some examples www.testbase.co.uk -- Pandb - religion -- clearly wrong Brightcloud - Reference and Research Training and Tools -- correct www. michaelwoodside.co.uk pandb -unknown clearly wrong Brightcloud -- Personal sites and Blog ...

Network Monitor does not show specific data.

Hi.allI Have a question about Network Monitor of App Scope.filter "Source / Top 10 User / Last 30 Days"When filtering application is normal.When I select source of data is not seen among the eight days. (Capture Attached)Also I was check the Network Monitor last night then April 24 ~ May 1 of data not visible. Today check the Network Monitor Ap...

wooki by L1 Bithead
  • 10344 Views
  • 7 replies
  • 0 Likes

Entries in My System Logs

I am getting this a lot. Anyone know what it means:EBL(Dyn Block Test) Refresh Aborted. Entry not refrenced by a ruleAnd the word is misspelled in the logs as well.

User/Group mapping OpenLDAP

Hello. My situation is: - GlobalProtect VPN configurated -> user identification via GP then. - LDAP profile configurated -> authentication works well - Authentication profile configurated. - User Identification, Group Mapping configuration: - Group Objects: - Object Class: posixGroup - Group Name: cn - Group Mem...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels