General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

VM-100 download link

Hello,We would like to download the VM-100 serie Firewall to test it on a POC.We cannot find it on PAlo Alto website.We have Vmware Workstation 10.Thank you in advance for your help,Kader.

internet access outage on pc's

just introduced PA on our network. Now random computers loosing internet access but network connectivity to LAN resources is still there..only after restarting the pc or disabling/enabling lan card does internet access get restored..anyone experiencing such an issue??

akuhn by Not applicable
  • 1961 Views
  • 1 replies
  • 0 Likes

Resolved! Force HA failover - how?

This is probably simple, but the documentation I can find is unclear, so I'm going to ask anyway. Better to ask and seem a fool than to act and remove all doubt!I have a pair of PA's in HA configuration. Owing to an issue on the inside with internal switching, I need to be able to kick from the current "active" to the current "passive" to test s...

darren_g by L4 Transporter
  • 120905 Views
  • 8 replies
  • 0 Likes

Resolved! Global Protect Client User Guide

Hello everyone. Sorry for this if it should be obvious, but I was thinking the community had a Global Protect Client document that was intended to be distributed to users on how the GP client worked. I was sure I've seen something like this before, but have had no luck finding it this morning. Does anyone have knowledge or a link to this doc?...

dan731028 by L3 Networker
  • 3477 Views
  • 2 replies
  • 0 Likes

GlobalConnect is slow to connect

We are having a hard time initiating the connection between the GlobalProtect client and the PAN. It seems every time a user reboots their laptop that the GP loses its configuration. Once it makes the first connection, which takes about 2-4 minutes to connect and pull policy, it's fine. A user and connect again and it will only take a few second...

jbo by L0 Member
  • 3689 Views
  • 1 replies
  • 0 Likes

Resolved! Certificate-based Authentication for the WebUI

Hi, I read about "Certificate-based Authentication for the WebUI" article. I am not sure if we can use it in our enviroment: - We have our enterprise CA and each admin has a CA Certificate. We are using those certificates for other purposes like admin authentication in security devices, Wifi and so on. - We want use those certificates for admin ...

ENAGAS by L0 Member
  • 2525 Views
  • 1 replies
  • 0 Likes

Resolved! Help with traffic reports... How can I do a report based on an ip range.

I am pulling my hair out here.I am needing to generate a report for certain traffic based on specific ranges of IP's.These ranges are client addresses in relation to the respective building they are from.I need to know if it is possible to do any range commands as part of the report filtering.Even a wildcard search, for say 10.50.x.x So far I ca...

Email Notification when a user logs into the PA Box.

Hi team,I am working on case: 00188973 where the customer want to get a real time email notification when a any user logs in to the firewall via GUI or CLI.Do we have any such feature available now on PA Box.If not, DO we need to raise a feature request for this.Regards,Sabyasachi Chatterjee | Technical Support Engineer

Resolved! acc risk factor

Hello Support Team,I'd like to know a mathematical formula of acc risk factor.It doesn't seem a session-based average value.Regards,Tomoyuki Komure

Tomoyuki by Not applicable
  • 16879 Views
  • 7 replies
  • 1 Likes

Application block page - not enabled by default

I've noticed in PAN OS 5.x that the application block page is not enabled by default. Obviously it can be manually enabled.. but was this done for a specific reason to address some common problems experienced by customers?I could surmise that perhaps displaying the application block page might chew up limited sessions/resources on the PAN firewa...

CMG by L2 Linker
  • 4245 Views
  • 3 replies
  • 0 Likes

Convert from vwire to layer 3 for globalprotect.

I'm trying to put together a plan of action to get globalprotect to work for us. I have a work ticket open with PA. Our PA firewall is currently deployed in a VWire setup, on the lan side of our router. Here are my big questions for getting this accomplished. 1) If I switch the vwire to layer 3 can I migrate the security profile name so I don't ...

Netwerx by L2 Linker
  • 5342 Views
  • 3 replies
  • 0 Likes

Resolved! SYN-Flood packets dropped by unknown rule

Hi everybody,we got a lot of syn-packets which were dropped by the rule any-allow. But we haven't this rule, so is it a inbuilt rule andwhy do i need a DoS-Rule to be protected against Syn-Floods if there is a builtin rule.Cheers klaus

kdd by L4 Transporter
  • 8539 Views
  • 14 replies
  • 0 Likes

Resolved! Decryption policy Issue

Hi All,I'm just trying to configure decryption. because I'm facing Issue while blocking applications(not all the applications got blocked as the policy supposed to do).First of all, I'm using Trusted CA, and here you are the steps I followed To generate MY certificate.1.2. then I uploaded that Certificate to the Trusted CA, and then I got a sign...

Resolved! GlobalProtect with NATet interface

I have a PA200, and is using eth1 for outside (internet) and eth2 for inside. I'm NATing from eth2 to eth1, as normal.Now i want to have the management https address on the eth1 for several reasons.At home its just for testing, but at my office i have PA200 between subnets that is duplicate, and not nessesary to route to.When i use a management ...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels