General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 303 Views
  • 0 replies
  • 2 Likes

Resolved! interesting PPPoE Problem

Hi guys,

i am currently tasked to replace two firewalls we have in the company. The first is a small cisco ASA 5505 for client breakout and a MS TMG(yeah i hate,too) for publishing the Servers.

For the first step I am trying to replace the ASA. WAN con

...

vertical by L2 Linker
  • 9350 Views
  • 12 replies
  • 0 Likes

Resolved! GMAIL Base and SMTP - WTF??

Folks.

The latest content update (pushed today, my time) gave me the following warning in the task when I installed it

VSYS1: Rule 'Outbound_Traffic' application dependency warning: Application 'gmail-base' requires 'smtp' to be allowed, but 'smtp' is

...

darren_g by L4 Transporter
  • 11184 Views
  • 20 replies
  • 0 Likes

Invalid threat ID number, next steps

In the threat logs, the PAN is detecting a virus for internal traffic, server to client, but the threat id doesn't match anything in the threat vault, 1 number too short, 253879. What's the best way to identify if the threat is legitimate, not a fals

...

tstores by Not applicable
  • 1948 Views
  • 1 replies
  • 0 Likes

Same traffic traverses the firewall twice.

I will try to draw this out the best I can and then ask my question.

Remote Site (zone is trust, vrouter2, tunnel.1) <<>> Core network (zone is trust, Interface 1/10, vrouter2, layer3)

Rule for this is any, any in both directions.

The above is how all

...

rbit0965 by L1 Bithead
  • 4503 Views
  • 6 replies
  • 0 Likes

Resolved! GlobalProtect Portal konfig update on Windows

Is there a way to force an update of the GlobalProtect configuration on a windows agent?

I`m testing different configurations but the client would update the config, probably because of the "Config Refresh Interval (hours)"

Regards

Kristian

kristian by L3 Networker
  • 2912 Views
  • 3 replies
  • 0 Likes

iMac updates and traffic monitoring

I have permitted apple-updates and users have confirmed that they are able to perform their updates. However, a user in is unable to perform updates as it appears that he is being blocked.

All our firewall and filtering is carried out by PAN and I am

...

PeterG by Not applicable
  • 1768 Views
  • 2 replies
  • 0 Likes

Resolved! Threat search by name

Hi,

If i have just threat name (eg.: Suspicious Content Found in 404 Page). How i can find this threat in a threat log? Is any search by name? Or i need to look all log by my self?

Interface by L3 Networker
  • 2363 Views
  • 3 replies
  • 0 Likes

Subtype "4" in Traffic log

PAN OS 5.0.0 on VMWare

I see a lot of subtype "4" in my traffic log. I also see start, end, deny, drop, so I'm sure it's not just a display error meaning one of the listed.

Does anyone know what "4" means?

Thanks

Andre

u13550 by L3 Networker
  • 3072 Views
  • 4 replies
  • 1 Likes

telnet with EBCDIC encoding

We are having some issues with IBM telnet (tn3270) through a PA-200.  The telnet sessions are very sluggish.  I had to remove the firewall to restore performance.  The telnet is using EBCDIC encoding.  I had been specifying a security policy using th

...

oshcomp by Not applicable
  • 3537 Views
  • 5 replies
  • 0 Likes

Resolved! Disabling warning messages during commit

Hi,

I get a lot of warning messages during commit, regarding rules shadowing, application dependency, etc.
I've been looking for a way to disable some or all of the warning messages, but with no luck.
Anyone know if it is even possible?

JFunk by L0 Member
  • 3434 Views
  • 2 replies
  • 0 Likes

Resolved! logs on PA-2050

Hello everyone ,

I have recently implement pa-2050 at a customer premises. Nine days after the implementation each time when login on the web interface a system alarm just popup saying '' Database traffic exceeds percentage limited ''  . Have a questi

...

Resolved! Security Policy Rule matches on ALL URL categories

Hi,

I'm sure this was working at some stage but now it's not working the way I need it: I have a rule from inside to outside, any user, web-browsing and a URL category of gambling, allow the traffic and use log forwarding with no profiles selected.

The

...

hoerzers by L1 Bithead
  • 7840 Views
  • 10 replies
  • 0 Likes

QoS (bandwidth) VPN site-to-site tunnel?

Hi all,

I am trying to understand the QoS feature of the PAN-2020 and was wondering if I could get some assistance.  We have a VPN site-to-site tunnel and the data center we are tunneling to is a 10 Mbps connection we can burst up to (10 Mbps being th

...

cmateam by L3 Networker
  • 4366 Views
  • 3 replies
  • 0 Likes
  • 23650 Posts
  • 107 Subscriptions
Top Liked Authors
Labels