General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! What Event ID is the PAN-OS User Mapping Looking For?

In the PA 5.0 Admin guide the following is stated:"In Windows 2008 or later domains, you can add an account to the “EventLog Readers” group to access event logs to obtain user to IP mapping informationfrom event logs."What AD event ID is it looking for? I do not have a deep knowledge of AD and asking as I am being asked.

Viewing Drop Packets/Log on FW.

Is there another method to view logs/packets that are drop on the firewall without having to do a packet capture. Is there a command that could be used in the CLI to view all drops data. If anyone know if this is possible please comment.

How to do URL Whitelists?

I am trying to figure out how to do Whitelists for a list of URLs and I am not having much luck. By default all outgoing is allowed on everything internal. I have a group of addresses that should only be allowed to view certain websites with wildcards. I created a profile that is set to that address group for source, ANY for everything else, and...

jeffm by L0 Member
  • 25382 Views
  • 4 replies
  • 0 Likes

Allowing "Save" function in a limited Admin Role

I have created an Admin Role for helpdesk users, limited to URL log, URL Objects and Custom URL Category.However, the users do not get the "Save" Option in their login.Anyone know which part of the tree I need to allow access to in order to get the Save option back?(PANOS 3.1.2)

DNS in IPv6 RA

I think it is time to start the first IPv6 only setups. What I missed in my testing setups was the DNS option in the RA (RFC 6106).Has anybody IPv6 only setups routed via PA?

Unibw by L2 Linker
  • 3051 Views
  • 3 replies
  • 0 Likes

Resolved! How do I check Products release?

Hello everyone;;I want to know release;;as far as we know, PA Devices are 200, 500, 2050, 3020, 3050, 4020, 4050, 4060, 5020, 5050, 5060When did them release,,?I am not sure that OS Version releaseIt seems that There is PA Site somewheregood bye;Have a nice day

One-to-One NAT - DMZ to inside - how do I make it work?

Folks.I'm apparently having a particularly stupid day, because I can;t make something as simple as one-to-one NAT work.Scenario is this.I have an IP in my DMZ. I have assigned this IP to a particular server which is hosted on my INSIDE (secure) network.All I want to do is take this IP address and NAT it to the inside address. Something like this...

darren_g by L4 Transporter
  • 10648 Views
  • 18 replies
  • 1 Likes

How do I setup dual ISPs on pa500 with ver 5.0.3 firmware

I need some clear documentation for how to setup a secondary internet connection to take over if primary fails. I know this is done with Policy Based Routing but that is about all I know. I found documentation on this but it was for firmware version 3 and it is different than what I am used to seeing.

Resolved! What happens if threat and antivirus licenses expire?

Hi All,.What happens if threat and antivirus licenses expire? is the vulnerability,anti-spyware and antivirus will works fine with the existing database? or the feature itself will get disabled (we cant use the filters in policy)?Kindly provide information.Regards,Gururaj

Gururaj by L4 Transporter
  • 4424 Views
  • 4 replies
  • 0 Likes

L2 subinterface + L3 subinterface on the same interface

Hello all,Is it possible to create an L2 tagged sub-interface and an L3 tagged sub-interface on the same physical interface.For example.Ethernet 1/6 Ethernet 1/6.100 --- L2 Interface. Security Zone "IPS only". /* this sub-interface will be used to Content-ID scan servers sitting on the same subnet as this interface but connected to an...

Resolved! Can't block Gmail file upload

Hello,i can't block upload files to gmail. Can anyone say what i'm doing wrong?My decryption policy:File Blocking profile:With yahoo mail no problem, but with gmail.. When i connecting to gmail, i get a message:So decryption works, but not completely.. I can upload any file i want. What else do I need to do to block upload?

Interface by L3 Networker
  • 7331 Views
  • 5 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels