General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Policy report for PCI

For PCI compliance, I need to submit poof of our firewall policy (we use a PA3020). Is there a standard report that I can run that summarizes our Policies, or is there a way to export the policies to a PDF or spreadsheet? On our old ASA I could simply do an export to HTML or spreadsheet which I could attach to my report.Thanks in advance.David

breedend by L1 Bithead
  • 3579 Views
  • 4 replies
  • 0 Likes

Windows Radius Server (NPS) / User ID discovery through PA Agent

I'm trying to figure out a way for the PA to discover usernames / IPs for wireless clients (could be Iphones / Andriod) authenticating via a Windows 2008 R2 Radius server. Clients are authenticating through dot1x (wpa2 enterprise). Auth and everything works fine, but the usernames are not being discovered.Just curious if anyone else has ever run...

rbergen by L1 Bithead
  • 7927 Views
  • 8 replies
  • 1 Likes

Issues upgrading pa200 from version 4.1.6 to 5.0.10

I downloaded OS file version 5.0.10 and when I tried to install it, I get the following error message: Failed to install 5.0.0 with the following errors. SW version is 5.0.0 Error: Upgrading from 4.1.6 to 5.0.10 requires a content version of 320 or greater and found 255-1052. Failed to install version 5.0.0 type panosMy pa200 currently have 4.1....

Resolved! What type of policy\rules do you need to access an internal licenses server from the internet

I have an internal licenses server that users need to access from the internet, 10.1.3.21. The The external exposed ip is 216.55.55.10The application on the users computer needs the following TCP ports open through the firewall so that client workstations are able to obtain a license from your license server system.lmgrd.exe needs INCOMING TCP ...

Portal Page for web based email?

Is it possible to have a portal page or a content page when someone uses gmail, yahoo mail, .... that would make them have to read company policy about not to use them to upload and email company data?

markk96 by L3 Networker
  • 2747 Views
  • 2 replies
  • 0 Likes

Custom Vulnerability (.DMG)

Hi All,PanOSS 5.0.10The following site (amongst others) hosts a malicious file that I want to block: Download Genieo. The file is a .dmg and I want it blocked to my Mac user estate. Rather than block the URL I thought I would give Custom Signatures > Vulnerability a go. I am following the document Creating_Custom_Signatures-RevA (page 43).Fil...

nickcx1 by Not applicable
  • 4051 Views
  • 2 replies
  • 1 Likes

Idle timeout since 5.0.11

Hi All,We have an issue with our firewall. Ever since we did the update to 5.0.11 a few weeks back our RDP connections from WAN to LAN are timing out after 30 minutes of Idle time. I have checked the server settings And they are fine, the only thing thats changed is the firewall version. Below are the NAT and Policy rules for the RDP server. We ...

VPN is UP but no traffic flows through

HelloI have noticed the issue a few times, when the VPN was UP but no traffic was going through. I had to clear the VPN for the traffic to flow again. Has any one had this issue and is there anyway to stop this from happening again?When monitoring the policies, i could see incomplete applications which would be normal when traffic doesnt flow th...

shyams by L0 Member
  • 3925 Views
  • 4 replies
  • 0 Likes

Resolved! PA and SSTP

Hi,does anyone know about issues on using a MS SSTP VPN behind a PA. Especially when natting from a non-standard port (f.ex. 5002) to 443 port of the server.The Logs look good, but shows 'incomplete' in the 'application' columns.Kind regards.

vertical by L2 Linker
  • 5311 Views
  • 5 replies
  • 0 Likes

How do you Commit the configuration of a Panorama to an existing HA Pair of 5060s?

I followed the instructions from “Panorama-Device-Migration-Tech_Note-revB.pdf” using the CLI method to capture the configuration of an HA Pair of 5060 running PAN OS 5.0.11 and paste it to the Panorama running PAN OS 6.0. The Migration Checklist states during the cutover process to cutover 1 firewall first. The document states after deleting th...

Nonno1 by L0 Member
  • 2905 Views
  • 2 replies
  • 0 Likes

Captive Portal Timeout no new Session - Cisco VPN Client

Hi there,I'm facing the following challenge.We have various guest users being authenticted via the captive portal after that, they are using their cisco vpn client.So there is only one session.And because all traffic is routed to the vpn connection no new sessions would be established.Our idle timer was 1800 minutes and after that the connection...

Threshold block

I want to block access to the users only if they watch youtube and the bandwidth consumed is more than 500 Mb.Is this possible. Can this be done.

Westcon2 by L3 Networker
  • 5825 Views
  • 7 replies
  • 0 Likes

Need advice whitelisting external network vuln mgmt scanners

Curious what other PAN companies are doing for this? What best practices around whitelisting your own Vuln mgmt internal and external scanners? When we asked PAN support, they recommended adding a new security policy to top, but that's not scalable because it needs to be updated each time we allow a new service or security rule inbound. Looking ...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels