General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 590 Views
  • 0 replies
  • 0 Likes

Resolved! Cannot log in after 5.0.5 upgrade

After upgrading from PAN-OS 5.0.4 to 5.0.5 and rebooting the primary 3020 of an HA pair, the logins we normally use tied to our Active Directory accounts are not working; they are giving us Invalid Logon messages.  These Invalid Logon messages occur

...

Resolved! Virtual IP

Hi

We have a scenario wherein we should create a virtual private IP in Palo Alto and that virtual IP will connect to a public IP. For example:

PA LAN IP: 192.168.1.1

PA PUBLIC IP: 9.9.9.9

Firewall Virtual IP: 192.168.1.254

Public IP: 1.2.3.4

Users will con

...

Resolved! Skype-probe rule catching other traffic

I have implemented the suggested Skype-Probe allow rule in order to block Skype.  I have noticed that this rule will also catch traffic that is of the Application type Incomple and Insufficient-data.  Just currious as to why it is ending up in this r

...

merrydc by L1 Bithead
  • 4887 Views
  • 2 replies
  • 0 Likes

Resolved! iPad App fails to connect

I have the global protect license and an active global protect subscription.  Windows Laptops, Mac Laptops, and Android devices (using the app) can connect and access network resources.  However I try with the iPad and it fails immediately.  I get "C

...

nthen by L3 Networker
  • 6966 Views
  • 6 replies
  • 0 Likes

Unable to get exchange logs

Hi,

I have a PA500 on PANOS 4.1.9

I'm doing some testing with Exchange, managing to get logs to identify iphones, ipads and android devices without a Captive Portal.

Installed USER-ID agent version 5.0.2-2 on a DC, done auto discovery, removed all DCs a

...

Resolved! Captive Portal Behavior

We have configured the captive portal for category 'Adult and Pornography' . Our question is, will the captive portal start every time or only when you are an unknown user? If the user is known (using Active Directory), is the user still being prompt

...

bbsoc by L2 Linker
  • 4520 Views
  • 4 replies
  • 0 Likes

What do 'SML VM Checks' and 'Detector Threats' do?

Hello

What do  'SML VM Checks' and 'Detector Threats' do in software pool?

These value was 1 when delayed to connect Web-Server.

Connection is normal when these value was high.

What do theses do? and what something do these influence FW?


Thanks

Resolved! Unblock an ip after the block-ip action

Is there a way other than waiting for the timeout to expire to remove an ip from the list of blocked ip's once it is blocked by a rule with an action of block-ip? I hope that makes sense .

Thanks,

Jim

jmayne by Not applicable
  • 5881 Views
  • 4 replies
  • 0 Likes

Report for CPU, Throughput, or Session

Hi,

PA can create report for Traffic, Threats, URL... very well.

However, I don't see any way to create report for CPU, Throughput, or Session in long time (about one week, or one month, whatever time),

Please let me know, can PA do that?

Note: Do not us

...

ThongPD by L1 Bithead
  • 3343 Views
  • 3 replies
  • 0 Likes

Active FTP Timeout Issue

Working with Active FTP, we are having problems with transferring files larger than 1.5GB because the control channel hits the idle session timeout for FTP (set at 1800 seconds).  Temporarily we have increased the timeout to 5400 seconds as a workaro

...

"Could not set the session location" messages in Panorama

Hello,

When I working over Panorama, I have a continuos messages,  If I try to see security rules or traffic logs or change with and other device, It presents this message  "Could no set the session location" any idea?

Note

Panorama version: 4.1.6 over

...

mchavez by L0 Member
  • 2894 Views
  • 3 replies
  • 0 Likes

Resolved! Question on Admin roles and what they see

We have an intern who we have given admin rights to our Palo Alto boxes and Panorama. I created a custom Intern role for him that just gave him access to the logs and reports and things but then read only to everything else. What is happening is when

...

JeffTQT by L2 Linker
  • 3403 Views
  • 3 replies
  • 0 Likes

Resolved! Configuring s to s VPN between three devices.

Hi All,..

We have two clients who have same ip subnets for VPN users ( ex. 192.168.29.0/24). Is it possible to configure PaloAlto to support both VPNs for different source users. 

                            VPN1:      Source- 10.66.249.0/24          

...

Gururaj by L4 Transporter
  • 2634 Views
  • 4 replies
  • 0 Likes
  • 24104 Posts
  • 117 Subscriptions
Top Liked Authors
Labels