General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


User ip mapping with only Global Protect

Hi all,

i have a question regarding user ip mapping when only using Global Protect to authenticate users.

Without enabling any user-id agent. Neither external on a server, neither on the firewall.

It works as Global Protect identifies the logged-on user


Resolved! Let me know how to block virus in SFTP


As title see

I would like to block virus in SFTP

as far as I know SSH Proxy is same as SSL Proxy

so I installed Bitvise SSH Server(Personal Version) recently

I have confirmed be server normally

and than I configured similar as SSL way in Policy



User Activity Reports

I really need some help in the correct process of running a user activity report. I have a request to pull the last 30 days of internet activity on a particular user. Every time I attempt this, I get strange results. Either the info only goes back 3


brb by Not applicable
  • 4 replies

Pannorama and HA Cluster


i would like to know how the commit process works when i push commit on pannoaram to HA device group.

1) does Panorama send the configuration to both of the device and then commit it?

2) does Panorama send it only to one device and it commits it to


minow by L4 Transporter
  • 5 replies

Destination NAT to address not in same subnet


I had a quick question about destination NATing to an address not in the same subnet as an interface on the Palo Alto. For example, let's say I have a site-to-site VPN and I am using destination NAT on one side of the tunnel. When traffic comes


Resolved! Forefront UAG Direct Access

I was wondering if anyone has deployed Microsoft Direct Access or Forefront UAG behind a Palo Alto firewall, and could share their experiences.  Direct Access requires 2 consecutive public IPv4 addresses (no NAT), and we are trying to figure out the


abelgard by L1 Bithead
  • 3 replies

Problem with IPSec tunnel monitor


We have an issue with one IPSec site-to-site tunnel. The PAN usually doesn't recognize when a tunnel is down. We can correct this by setting up monitors on all tunnels with a "wait-recover" action after 3 subsequent failures. This works for all


oschuler by L4 Transporter
  • 2 replies

Resolved! Viewing all URLs visited by a user

Hi there

I'm trying to track down an incident here and I'd like to get a report on a particular user for all URL activity. I've set up a custom report using the URL Log, with a time frame of the last 12 hours and added the username in via the query bu


Panorama commit devices with different results


We have a device group in Panorama with 4 devices members. When we've committed changes sometimes devices had the result "Commit succeeded with warnings", because we have some dependence warnings, but one of them has the result Commit Succeeded".


  • 23698 Posts
  • 105 Subscriptions
Top Solution Authors
Top Liked Authors