General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4224 Views
  • 0 replies
  • 0 Likes

Captive Portal and RADIUS Authentication

Hello, Is it possible for Captive Portal to work with RADIUS or AD authentication in a way that if the user logs into their PC and authenticates via AD that they will not have to authenticate a second time via captive portal? Or, does captive portal have to be opened via a web browser to authenticate?Thanks,Mark

MarkTan by L2 Linker
  • 2317 Views
  • 1 replies
  • 0 Likes

Resolved! PAN OS 5.1.x branches - for whom they are?

HelloLast time when I reported issue I see on selection list that branches 5.1.x of PAN OS's I can download 6.0.0 and every from 5.0 but I can't see 5.1.x on Device > Software of my PA200 device.Could someone tell me something more about 5.1.x PAN OS?RegardsSlawek

_slv_ by L4 Transporter
  • 2061 Views
  • 1 replies
  • 0 Likes

Open a port

I am installing a caching server inside of my network. This caching server (PARCC Assessment) requires send and receive communication on ports 4480 and 4481. How do I open these ports for the particular private IP address of my server??

Resolved! PA User identification

How PA decide on user IDs, for example if i have an IP that the user was mapped from UIA, and then a security log in AD map this IP to another user?or a user that loging with global protect through local DB, and then authenticate to AD, and the PA gets a new mapping from the agent ?thanks

minow by L4 Transporter
  • 3692 Views
  • 4 replies
  • 0 Likes

unknown-tcp going out to yahoo servers - pls update applipedia

part of my routine is looking for unknown-tcp and udp connections out. Love the feature.For a while ive seen a good amount of unknown-tcp connections out to yahoo.com domains.Anyone else seeing this?PA: Are you guys looking into this so I dont ahve to screen these IPs out when I do my checks.heres the ranges, they are all yahoo206.190.37.0/24206...

choff123 by L3 Networker
  • 3122 Views
  • 2 replies
  • 0 Likes

Searching Policy for different security profiles

Hi All, Is there a way to search on differentially assigned ( or null ) different security profiles ( AntiSpam / URL / Vulnerability etc ) within a policy ? We use a couple of different vulnerability profiles/URL Filtering profiles within the same policy and its painful not being able to find where they are assigned. Am I missing som...

dpenhall by L2 Linker
  • 3890 Views
  • 4 replies
  • 0 Likes

Resolved! Maximum number of custom app-id's

Hello,Does anyone know what the maximum number of different custom app-id's, that is supported on the different devices?Especially interested in the maximum on the PA-5060Jo Christian

User-ID Agent identifies local PC users so captive portal never kicks in?

I upgraded our PAN from 4.1.x to 5.0.10 and also upgraded the User-ID agent from 3.x to the latest 5.x.We have some rules configured with groups specified and we have captive portal in place and what used to happen was if you came along on a domain joined laptop but were logged on as a local account (so LAPTOPNAME\LocalAccount) you'd get the por...

Dynamic updates ERROR after updated 6.0.0. Why? HELP

HI ALLI updated yesterday software from 5.0.10 to 6.0.0 But after such an error occurredBefore that everything was normalBut after such an error occurredmany reboots, many check updates but the error is stillWHY HOW TO FIX HELP

MRPAM by L1 Bithead
  • 1988 Views
  • 1 replies
  • 0 Likes

Resolved! X FORWARD FOR with USER ID

Hellois it possible to use ip retrieved from the x forwarded header and combined with the user-id.my aim is to filter access per active directorie usergroup, but I have a proxy implemented between the palo and the user device.thank

Gregoux by L4 Transporter
  • 4802 Views
  • 3 replies
  • 0 Likes

Functioning DLP Policies

Has anyone implemented DLP on the Palo Alto firewalls that actually provides consistent results? I am struggling to get even something as simple as a regular SSN# to log and alert every time. I am using the built in regex for SSN and SSN without dashes and have SSL decryption running on the traffic. I will upload 8 or 9 files each with a separat...

tim123 by Not applicable
  • 3034 Views
  • 1 replies
  • 0 Likes

Resolved! Registry entry for Connect Method?

Does anyone know what the registry entry is for changing the "Connect Method" to on-demand? I am trying to push out the GlobalProtect client via WSUS Package Publisher. I am able to do the install and push the "Portal" key in the registry, but don't know what the reg entry is for the Connect Method is. The client keeps popping up until the user ...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels