General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

About HA1 connection down in system critical log.

Hi. allI have a question about high availability with A-P mode.We found out critical system log in active device for HA1 connection down but not occurred split-brain. (system log : type ha / severity critical / event connect-change / description HA Group 1: HA1 Connection down.)Just HA 1 link is to go down and up within a few second.Configured H...

URL Blocking

How can I add some sites to the list of blocked URLs that PA downloads into my PA-500? I know I can block them manually in my PA, but I feel that the PA tech support staff should know about these sites. I will give you and example that my students found: Shyla Stylez - Official WebSite - FREE Pictures and Trailer Videos is NOT blocked by the...

Resolved! Active/Active Floating IP/Traffic Forwarding Problem

Hello All,I have a support case open with PAN but I thought I would query others smarter than I.2 x PAN-2020Recently enabled HA Active/ActiveBGP on External/Currently ONLY Static Inside to Active-Primary device (0.0.0.0/0 -> Active Primary)Session Owner = First Packet (only going to be Active-Primary right now do you static route)Session Setu...

dshue by L2 Linker
  • 5713 Views
  • 1 replies
  • 0 Likes

Internet logs, backup and review

Pardon if this is a repost but I am new and could not find anything similar.Right now our 3020 unit seems to only be getting 4 or 5 days worth of log information before it fills up. We would like to have access for the last 30 days if possible. Is there a way to backup the monitor logs and then be able to search them later if called upon? Oh,...

Whitelist rule - confusion on URL filtering...

We have a whitelist rule that allows out http/https as a service and "any" as the application.All the URL categories in the profile applied to that rule are set to "Block" and there are some URLs in the whitelist.The destination address is set to "any".Today we noticed someone hit that rule using SSH on port 443 and it was allowed out.I'm guessi...

Panorama 6.0

we recently integrated a PA-500 (4.1.10) into PANO 6.0 and we've started seeing OSPF flapping. Has anyone else experienced this issue? It looks like the Management cpu will spike up to 100% when communicating to the PANO and then we lose OSPF. This PA-500 has been in production for over a year with no issues. Is there a good way to look a CPU hi...

mjames by L0 Member
  • 2187 Views
  • 1 replies
  • 0 Likes

Global Protect Portal

Is there anyone out there running client VPN and managing it through the portal on PAN-OS 6.0.1? I keep getting the error stating that I need a portal license. I have the same setup on another Palo on version 5.0.8 and it is running without a license just fine. Tom

tsapp by Not applicable
  • 1943 Views
  • 1 replies
  • 0 Likes

Can Global Protect use multiple methods of Authentication?

Is it possible to setup Global Protect to use Windows AD authentication for a subset of our VPN users, and Radius for the rest? I'm assuming this is not possible since you can only set one Authentication Profile under the GlobalProtectPortal, but if there's a way to accomplish this I would love some input.Thank you.David

breedend by L1 Bithead
  • 2590 Views
  • 1 replies
  • 0 Likes

Resolved! Error: Profile compiler : can not set time attribute on tid 40026 interval 60 threshold 20

When I'm committing changes to my PA-4020 I'm seeing this error message:Error: Profile compiler : can not set time attribute on tid 40026 interval 60 threshold 20(Module: device)Configuration committed successfullyThis started happening a few days ago. I'm running 5.0.11. Any ideas how I can troubleshoot this?Thanks,Dan

dbaumann by L1 Bithead
  • 7490 Views
  • 4 replies
  • 0 Likes

Mcafee Application Object

Has anyone noticed the Mcafee Application Object is using the wrong ports, or do I have something wrong?McAfee update protocol for distribution of signature/pattern updates. tcp/3025Mcafee-update tcp/8801These are all the ports Mcafee leverages (outside of backup updates)https://kc.mcafee.com/corporate/index?page=content&id=KB66797

CLI Scripting to implement missing commands

Hi,in my opinion some commands are still missing in the PanOS CLI. I miss some features implemented in my conventional firewall to handle the policy rule set efficiently. Some other vendor has the possibility to use so called op-scripts in the CLI. This scripts allow to implement own CLI commands using the built in API. Is there already the pos...

Unibw by L2 Linker
  • 3702 Views
  • 3 replies
  • 0 Likes

Best Way to use User-ID Agent.

Hey everyone,I have been bashing my head onug how I can cleaninly use the USer-ID agent.. I wanted to stop WMI or event exclude internal vlans as I thoht it was used just for VPN. But its not its used to map source user info in the log files of the firewalls...Thing is when I have it enabled it probes everything! Gateways, iPhones, S4's ipads, e...

Zewwy by L3 Networker
  • 7475 Views
  • 8 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels