General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Identified User and NAT

Hi,for certain of our users is it aloud to use firefox. they are identified by their username. But if the want to go to internet they have to be "NATted" . It is possible and when how to create a NAT-Rule? What is known: username and the application.Best regardsKlaus

kdd by L4 Transporter
  • 5400 Views
  • 5 replies
  • 0 Likes

Palo Alto With TWO ISPs

Hello,We have migrated firewall from ASA firewall to Palo Alto firewall. In my case, we have below interfaces in Palo Alto firewall.1. ISP1 Interface (E1/1)2 ISP2 Interface (E1/2)3. DMZ Interface (E1/3)4. Inside Interface (E1/4)Since we are using ISP1 for accessing DMZ servers from internet and we are using ISP2 for web traffic of users from in...

Destination NAT with different subnet of Outside interface.

Hello,Outside interface of Palo Alto firewall is configured with aaa.bbb.ccc.ddd /30 subnet.I have some servers in DMZ those need to be accessed via internet with IP address(es)/subnet ZZZ.XXX.YYY.VVV/24.I have configured Destination Nat( including Security Policy) for these servers with the IP addresses as mentioned above.Please let me know how...

Resolved! address object strange behavour

Hi I create a address object base on a network address like 192.168.21.0/20 and when I used it as source address in my policy base forwarding rule this never matchbut when I create addresse object with a range like 192.168.16.1-192.168.31.254 and when I used it as source address in my policy base forwarding rule this matchwhat wrong ?is it bug?o...

Gregoux by L4 Transporter
  • 3078 Views
  • 3 replies
  • 0 Likes

Resolved! USER ID agent wmi probing

Hi something strange with old version of user-id agent version 4.1.6-5the user is connected on the network lan with wire and is authenticated on the active directory the result is the user is identicated in the traffic log If the user switch from wire connection to wifi connection the wmi probing should detect the new ip affected to user? or no...

Gregoux by L4 Transporter
  • 8040 Views
  • 5 replies
  • 1 Likes

PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site

I just stumbled on this security advisory while I was googling something totally unrelated...http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt"These issues have been fixed in PANOS 5.0.9, mentioned in the release notes like this:57343—Fixed an issue that caused improper handling of imported certificates that contained HTML."Also I thi...

Global Protect client issue - really annoying

This one has been bugging me for a long time and I've just been brushing it under the table, well new year, new resolve, so I thought I'd ask the smart people if anyone else has seen/experienced/fixed this.My organisation has the Global protect client installed on all our laptops by default, regardless of if the user is office based or remote.Al...

darren_g by L4 Transporter
  • 12292 Views
  • 12 replies
  • 1 Likes

Using application categories in security rules.

Hi all,I am in the process of configuring security rules to allow some applications for a particular user group, These applications I am taking from the app category "internet" & "Media", (131 applications in total) this I could do by adding these applications to a application group and applying it to the rule. In the same application group...

HughWalsh by Not applicable
  • 3423 Views
  • 1 replies
  • 0 Likes

Wildfire Analysis Email Alerts

Hi,Can you confirm how quickly we should be receiving the Wildfire analysis report following a malicious file detection?I have a wildfire upload that occured at about 2am GMT, I have the PAN log message reporting the upload, and in the PAN Wildfire THREAT log I can see it has been logged as malicious and links me to the online portal with the an...

apackard by L4 Transporter
  • 2597 Views
  • 2 replies
  • 0 Likes

Resolved! What is the maximum number of AD users per AD group?

Hello guys.I have a question about group membership of AD.What is exactly the maximum number of AD users per AD group on the Firewall? How much PAN recognize the maximum users per AD group from AD? There is no limit? or has limit?If it has a limit, Please let me know Thanks in advance.Regards,Roh

Resolved! Can not use captive portal

Good afternoon!I'm configuring captive portal to authenticate user through Radius. I followed steps on How to Setup Radius Authentication for Captive Portal ( enable UI on source & destination interface => create Radius Server Profile and Radius Authentication Profile => enable Captive Portal on UI with that Radius Profile & Transp...

About group-name contains special character

Hello guys.I have a question about group name could contain a special character such as & ! * from ActiveDirectory. I think it is not working properly if group name contained special character. Customer have using GlobalProtect with LDAP authentication from AD as a AD group and AD group has special character &. User could not be authenti...

Custom Vulnerability Not Showing Correctly In Reports

Hi, we're running 5.0.6 on our firewalls and 5.1.5 on Panorama.I have some custom vulnerabilities that, when triggered, do not show up correctly in reports (Monitor Tab, ACC etc).Only the reference number is show, not the name, description or assigned risk.We have had this issue since v4, and had hoped that the v5 upgrade would fix, but still ex...

apackard by L4 Transporter
  • 3974 Views
  • 5 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels