General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1920 Views
  • 0 replies
  • 0 Likes

Resolved! What is a "large" deployment for User-ID on the firewall?

We have a pair of 5020s and about 4000 users on 4 AD controllers. Throughout the 4.0 and 4.1 series, we have seen the Windows-based UserID Agent drop groups and users, and are interested in seeing if native event log polling from 5.0 might help. Targ

...

rgraves by Not applicable
  • 6157 Views
  • 6 replies
  • 0 Likes

Resolved! Bidirectional Forwarding Detection

Does Palo Alto Firewalls support Bidirectional Forwarding Detection (BFD). Link to RFC http://tools.ietf.org/html/rfc5880

The reason i ask is it is best practice to use this as a OSPF fault detector in lue of reducing the ospf timers.

Global Protect and Android 4.0.4 - problem

Hello

I have working VPN for Windows machines. I need to extend it for Android devices, using client from Android OS.

I'm using login and passwords (not certs) in my VPN config.

I followed by the GlobalProtect-Config-Android-RevB.pdf  - part 3



When I try

...

_slv_ by L4 Transporter
  • 6263 Views
  • 11 replies
  • 0 Likes

User-ID stopped populating mappings - OS 4.0.12

I am running OS 4.0.12 and have an issu with the user-ID / mappings not populating in the logs. 

show user pan-agent statistics:

IPs      Activity Timer(s) Domain          Index

ncmpdcden01      10.250.12.10    5009  vsys1   *connected, ok     989    9

...

Resolved! Global Protect behind a firewall

Hi,

PaloAlto firewall is behind another firewall(Firewall B).

This firewall B's port 443 busy with another app.So we have to use another port

How should we configure Paloalto portal and gateway.

we used port 18000.

Firewall B --- 2.2.2.2 port 18000 Nat to

...

Commit only a specific set of config changes?

Hi,

Is there any way to commit just a specific set commands to the Palo without committing all changes that are pending? I have an in house written piece of software that is going to make content filtering changes to my Palo's via the XML API. My conc

...

Gareth by L1 Bithead
  • 5911 Views
  • 4 replies
  • 0 Likes

Resolved! Global Protect attack

Hello

Someone could say me, what is the cause of the error?

Palo Alto: Monitor -> System

Receive Time: 08/09 9:22:58
Type: GlobalProtect
Severity: informational
Event: globalprotectportal-auth-fail
Object: Portal_Laptops
Description, GlobalProtect Portal use

...

SOC_CSG by L4 Transporter
  • 3880 Views
  • 3 replies
  • 0 Likes

Blocking an application for all websites except one

I have an Application filter for Streaming Audio and have created a policy to block it. That's going well but I need to allow http-audio which falls under Streaming Audio for one specific site only.

I have created a URL Filtering security profile with

...

eugenep by L3 Networker
  • 8836 Views
  • 10 replies
  • 0 Likes

terminal Agent - session 0 "no need to handle"

hi all,

I've encauntered the issue with terminal agent mapping.

Everything is working fine for normal users using terminals but for local console Administrator it is pain in the a...

It seems that Terminal Agent is skipping this mapping (local console

...

pkonitz by L2 Linker
  • 3145 Views
  • 2 replies
  • 0 Likes

full url address

Hi,

When looking for url reports from custom reports , some of the url addresses come only with *.domain.com

is there a way to see full address of these url's.Especially google ?

Resolved! Certificate chaining with Captive Portal

Hello,

We have a PA-3020 running PanOS 5.0.0 in L3 deployment. We have just one Private zone and one Public zone for the instance.

I have configured a Captive Portal policy on the Private zone gto ensure that all users that are not authenticated by Use

...

ldormond by L3 Networker
  • 12378 Views
  • 9 replies
  • 0 Likes
  • 24194 Posts
  • 117 Subscriptions
Top Liked Authors
Labels