General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Custom URL category - URL filtering logs displays which category?

Hey all,Suppose I create a Custom URL category called "myCategory", including "*.microsoft.com" and "microsoft.com".Before implementing the changes, I see in the URL logs the following category:business-and-economyAfter creating the category, I still see business-and-economy even after "clear url-cache all".However, when I create a Custom URL ca...

Data plane utilization

Hi,PA 2050 pan OS 5.0.7, data plane utilization show 94- 98 % during day time, is this creates a bottleneck in our network?Thanks

mgeorge by L0 Member
  • 8430 Views
  • 10 replies
  • 0 Likes

Internet browsing is slow through PA 2050 with PAN OS 5.0.4 .

Hi All,Internet browsing is slow through PA 2050 with PAN OS 5.0.4 , below are the some outputs from CLI. Can any one analyze the outputs given below tell me the root cause for slowness?Decryption is not enabled.admin@PA-2050> show session info--------------------------------------------------------------------------------Number of sessions s...

Gururaj by L4 Transporter
  • 4088 Views
  • 3 replies
  • 0 Likes

Resolved! Unable to block port scanning even after enabling "zone protection profile".

Hi All,How to block port scanning?I tried by defining the "zone protection profile" and using it in "zone" with below settings and used "tenable Nessus" tool to perform port scanning and it was successful,. It is not getting blocked,.. please any one can guide me?No thread logs were found, Any further settings required?Regards,Gururaj

Gururaj by L4 Transporter
  • 5160 Views
  • 2 replies
  • 1 Likes

User ID mapping update

Hi,How regularly should the user-id mapping take place in the pan agent.If I log into the > Program Files> Palo Alto Networks > Panagent folder, and review the user_ip_maptext file, it shows the last dated of June, 2013.But this is the month of Sep, 2013.Why does this not show the latest, what do I do to update this so it reflects the l...

rz185016 by Not applicable
  • 4130 Views
  • 4 replies
  • 0 Likes

Resolved! Accessing all company networks with GlobalProtect client

Hi!Basic info:PA-500 (software version 5.0.7)Main location network: 10.10.1.0/24Branch location network: 192.168.1.0/24GlobalProtect client IP pool: 10.10.3.10 - 10.10.3.254We have main location network and branch location network connected thru IPSec VPN. Our PA-500 is located on main location and handles GlobalProtect clients connections. When...

kpv by L1 Bithead
  • 7803 Views
  • 9 replies
  • 0 Likes

Client VPN traffic and routing over IPsec Tunnel

Hi there,Here is our scenario that I am trying to figure out.We have two sites (main office and a rack in a data center) that are connected via PAN-2020's on both sides through a IPsec Tunnel. I am trying to route Client VPN traffic that connects at our main office to go over the site-to-site tunnel to access some web servers there. It seems the...

cmateam by L3 Networker
  • 9740 Views
  • 5 replies
  • 0 Likes

Having trouble with link aggregation using 10G ports

We have a cluster of two PA-5060 running in active-passive mode. Two 10G interfaces are configured as an aggregated interface. They are connected to two Avaya 8600 switches which are running SMLT. Whenever a failover happens, the aggregated interface fails. We have to unplug and re-plug in the cable to make the interface start working again. Sh...

Resolved! Traffic Filter by Address Groups

Is it possible to create a traffic filter using an address group as the src or dst?I have an address group with around 15 IPs in it that I would like to filter on in the traffic logs.

AmyTyler by L2 Linker
  • 3743 Views
  • 2 replies
  • 0 Likes

Resolved! URL Filter update - users not seeing changes?

1. If a URL is incorrectly categorized, I submit a change to Brightcloud.2. Brightcloud emails me the next day (or two) and says the change was accepted and is in the latest DB.3. I confirm on Brightcloud's website that the URL is newly categorized and what version of the DB it is in.4. I confirm that my PAN devices have that version of the URL...

cenders by L3 Networker
  • 5593 Views
  • 7 replies
  • 0 Likes

Resolved! Authenticating external users to firewall like Sonicwall?

Hi all,I am configuring a PA-500 for a POC exercise with a customer who is currently using a Sonicwall.While there are obviously other/better ways to accomplish this and I realize how silly this is, given the limited scope I'm presently working in, I need to find a way to replicate a feature they presently "require".In Sonicwall world, a user ou...

Resolved! Slow VPN throughput after update to 5.0.7

Hello CommunityHas anyone recognized some performance issues (extremely slow ip-sec throughput, hanging sessions) after updating to 5.0.7A Firewall reboot solves this issue, but it's coming up again after some days.Many thanksHannes

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels