General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Windows Server 2012 ms-update

We are using WSUS to manage our Windows updates. It's hosted on Windows Server 2012 and runs smoothly.We recently added a Windows Server 2012 in DMZ and pointed it to our WSUS server:server --- DMZ --- PA2020 --- LAN --- WSUS serverThe PA2020 does not recognize specific WSUS traffic to the WSUS server.That is: most detecting/reporting passes fin...

dieter_b by L4 Transporter
  • 5216 Views
  • 5 replies
  • 0 Likes

Resolved! Agentless User-ID

Hi,I am having issues with getting the user-mappings after configuring the PAN as an agentless user-id with an AD. I have followed all the steps in this document-> https://live.paloaltonetworks.com/docs/DOC-4332.All are good except that when I run the CLI command > show user ip-user-mapping all

Suhaimi by L1 Bithead
  • 8809 Views
  • 6 replies
  • 0 Likes

Resolved! How to process OSPF in FW?

Hello,I heard from someone in the past that control plane send ospf hello packet and data plane has routing table.Is it correct??OSPF issue occurred in my custom site. So I wonder it.And what is the different between routing table and FIB?Thanks.

Upgraded to 5.0.9 ? User Identification stops working?

Hi,I had 2 PA's running with user-identification using the user-id-agent.Both have the same config, running 5.0.7I upgraded both to 5.0.9one is working fine, the other one does not "see" the user anymore.Tried the normal stuff: reboot, reinstall, tried 5.0.8 ( same problem ), checked the user-id-agent (connected), ...When I revert to 5.0.7, ever...

paulmeys by L1 Bithead
  • 3762 Views
  • 3 replies
  • 0 Likes

problem with group membership display in PAOS 5.0

I use the command :"show user group name domain \domain users" , the response from the firewall is :"User group 'domain\domain users' does not exist or does not have members" .The domain users is the default group for the new user, I think maybe some error for the group membership display in the PA firewall. The PAOS version I used is the 5.0.8

Resolved! How can i create a "next VR" type route in panOS version 3.1.12?

Hi, guysI have two Virtual Routers in a Virtual System in a 2050 Paloalto NGF version 3.1.12I want to create a Static route in one of this Virtual Routers to send that traffic to the other Virtual Router similar like i do this in version 4.1.In version 4, when you add a static route there is a type of route "next VR" where you can define the oth...

Pepen by L1 Bithead
  • 4179 Views
  • 1 replies
  • 0 Likes

Resolved! Policy log settings

Hi Pals,I would like some second opinion on my observation reg. the option 'log at session start' and 'log at session end'. I have tried both options and at the same time monitor the generated traffic logs for each setting. This is my observation:a) For log at session end, there is only one traffic log created for a sessionb) For log at session ...

Suhaimi by L1 Bithead
  • 5056 Views
  • 4 replies
  • 0 Likes

Dynamic block list and custom blocked page

Hi,I am planning to use custom blocked page. So far I have got the logic of creating custom block page and using it in the policy. I would however like to know if I can somehow redirect user to custom blocked page and inform user that his/her access is blocked for xyz reason.Thanks in advance.

File blocking..

Hi Gents,I have a Palo Alto 5050 installed between users and my Server Farm.I configured a security policy to allow access to the File Server, and applied a File type profile to block files such as exe, avi, and FLV.but the file blocking doesn't work, while the users are still able to put these file types on the server share.how can I resolve th...

File Types and Applications regarding SSL Decryption

Hi All,I don't have content Filter License.am I required to configure ssl decryption to block internet applications or file types?shall I've a content filter license to configure ssl decryption or not?Also I'm facing other Issues,to open internet access for users, I open web-browsing application and ssl.while I'm trying to brows the internet I f...

Policies security rules - filtering issue

Hi,Do you know is there any documentation regarding policies security rules filtering? I have found some strange behavior for filtering. Examples below on the screenshots are from Palo Alto testing firewall (sv 5.0.6). As it can be seen, if I use filter (source-user eq ‘any’) not all relevant results are returned which is obviously wrong.Also, I...

Monitor traffic - filtering issue

Hi all,we have noticed inconsistency in PAN OS 5.0.8 and 5.0.9, compared to 4.1.9, related to monitor traffic filter. In older version message box pops-up in case filter is not properly defined (i.e. if there is syntax error), which is fine and helpful. In mentioned 5.0.8 and 5.0.9 nothing pops-up in case of erroneous filter, only white area is ...

Active/Active traffic log.

HelloI knew session owner generate traffic log.Does session setup device generated traffic log If a session is denied L4 processing before L7 processing???Network DiagramRouter#1(Power-OFF) ------ Router#2(Power ON) | | FW#1 FW#2 | ...

Resolved! use GlobalProtect for Network Logon

Dear,Is it possible to use GlobalProtect with pre-logon enabled as a "Network Logon" for Windows?This way I want to use the GlobalProtect to tunnel the domain-login request to our AD when the pc is on the road.Ultimately we want to use this for users with expired accounts to be able to reset their domain password remotely.If this is not possible...

mr.linus by L4 Transporter
  • 5529 Views
  • 8 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels