General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1988 Views
  • 0 replies
  • 0 Likes

Does PA firewall really support 6in4 tunnel?


I have a free 6in4 tunnel from Hurricane Electric. The tunnel profile inucludes IPv6 Tunnel Endpoints, Routed IPv6 Prefixes and Anycasted IPv6 Caching Nameserver. I used these information to configure a Juniper SSG firewall and it works. I was told b

...

yq by L0 Member
  • 4846 Views
  • 3 replies
  • 0 Likes

Resolved! Unable to Perform Debug Flow

Hello, have a PAN-5050 running 4.1.13, where I am trying to debug flow on.  Followed the steps necessary to turn on flow debugging but I am not seeing anything log to either of the dataplane pan_packet logs files. I've confirmed the settings are in p

...

Resolved! Forward Trust Certificate

Hi,

In my office environment, we have an internal certificate that we have been using prior to installing PAN device. Lately after installing PAN, our office staff are always getting certificate warnings whenever they visit a SSL enabled website.

I re

...

Suhaimi by L1 Bithead
  • 2871 Views
  • 1 replies
  • 0 Likes

Maximum PAN-OS in Signature Update

Hi All,

I see in Release Note application update in Dynamic Updates or email like this :

There is a maximum PAN-OS version in Conficker.

Why some threat have limitation in PAN-OS ?

Please advice.

Thanks.

Regards,

MG

mg_imid by Not applicable
  • 2917 Views
  • 3 replies
  • 0 Likes

Is config saved at a flash memory?

Hi.

I saw PAN-OS 5.0 Administorator Guide.

P37 bellow

------

Revert to last saved config Restores the last saved candidate configuration from flash memory. The current

candidate configuration is overwritten. An error occurs if the candidate

configuration h

...

Resolved! Ignoring control flags

Is it possible to ignore tcp control flags in the Palo Alto?

I have a client where several nodes talk back to a server through the PAN. The nodes will send a FIN packet so the PAN will drop the session.. however, the vendor requires the session to sta

...

SDorsey by L4 Transporter
  • 3103 Views
  • 3 replies
  • 0 Likes

gotoassist application recognition

Is anyone else having issues with PA not recognizing gotoassist very well ?

Citrix documentation expects you to open tons of DNS addresses and/or IP ranges, but I'm a bit wary of opening ALL traffic on ports 80 and 443 to these (most IP ranges are on

...

dieter_b by L4 Transporter
  • 4046 Views
  • 4 replies
  • 0 Likes

Response Page using HTTP

Hi,

We are working on custom response pages for all our devices but wanted to know if it was possible to deliver then using HTTP instead of HTTPS as the default ones currelty come via HTTPS and users have to accept the invalid certificate. We have val

...

bcsgroup by L2 Linker
  • 2912 Views
  • 3 replies
  • 0 Likes

Resolved! Can the GlobalProtect Portal be disabled?


I would like to disable the GlobalProtect portal. We would like to control the deployment and installation of the GP client with other tools, and not have this outside logon page availabe to the world, but I still want to be able use the GP Client. C

...

ldavie by L2 Linker
  • 2780 Views
  • 1 replies
  • 0 Likes

vWire Fails in BGP

Hi,

We have a deployment of Palo Alto in vWire mode. But after it was setup, bgp is no longer functioning. I already created an allow all policy but it didn't work as well. Any advise that can help me to make this work?

Thanks,

Rex

Resolved! The java.tomdep worm ?

Hi,

symantec announce a worm named java.tomdep,

Ref link :

http://www.symantec.com/security_response/writeup.jsp?docid=2013-111815-1359-99

Can Paloalto with Threat Prevention can stop this threat ?

Regards

Hey guys have any of you ever come across this issue:

I was looking at some logs and noticed data displayed in the screenshot below.  There are several things highly questionable about the data displayed here:

  • - The Start Time is in 2031, and the receive time is 2013.
  • - Bytes Received is about 2 exabytes
...

lhylton by Not applicable
  • 2851 Views
  • 3 replies
  • 0 Likes

Resolved! Populating Panorama from an existing firewall.

We have a lab PA2050 that I have tweaked to exactly where I want it to be. We are now trying to add it to a lab Panorama and I would like to populate Panorama with all of the policies and objects from the lab 2050. I exported the running config to an

...

Failed to get CRL http:// ...

Im getting tons of failed to get CRL errors in my logs all of the sudden. Im not sure what I did (if anything) to cause this.

Ive tried to fix it,

  • I tried to enable  "Server CRL"
  • I did a nslookup on crl.verisign.com and I cant see any connections outbou
...

choff123 by L3 Networker
  • 4899 Views
  • 4 replies
  • 0 Likes
  • 24215 Posts
  • 117 Subscriptions
Top Liked Authors
Labels