General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

iMac updates and traffic monitoring

I have permitted apple-updates and users have confirmed that they are able to perform their updates. However, a user in is unable to perform updates as it appears that he is being blocked.All our firewall and filtering is carried out by PAN and I am usually view traffic from a user's PC computer and figure out what is being blocked by the one of...

PeterG by Not applicable
  • 2411 Views
  • 2 replies
  • 0 Likes

Resolved! Threat search by name

Hi,If i have just threat name (eg.: Suspicious Content Found in 404 Page). How i can find this threat in a threat log? Is any search by name? Or i need to look all log by my self?

Interface by L3 Networker
  • 3289 Views
  • 3 replies
  • 0 Likes

Subtype "4" in Traffic log

PAN OS 5.0.0 on VMWareI see a lot of subtype "4" in my traffic log. I also see start, end, deny, drop, so I'm sure it's not just a display error meaning one of the listed.Does anyone know what "4" means?ThanksAndre

u13550 by L3 Networker
  • 4063 Views
  • 4 replies
  • 1 Likes

telnet with EBCDIC encoding

We are having some issues with IBM telnet (tn3270) through a PA-200. The telnet sessions are very sluggish. I had to remove the firewall to restore performance. The telnet is using EBCDIC encoding. I had been specifying a security policy using the application telnet. When I get a chance I will change that to service port 23 and test again. ...

oshcomp by Not applicable
  • 5026 Views
  • 5 replies
  • 0 Likes

Resolved! Disabling warning messages during commit

Hi,I get a lot of warning messages during commit, regarding rules shadowing, application dependency, etc.I've been looking for a way to disable some or all of the warning messages, but with no luck.Anyone know if it is even possible?

JFunk by L0 Member
  • 4504 Views
  • 2 replies
  • 0 Likes

Resolved! logs on PA-2050

Hello everyone ,I have recently implement pa-2050 at a customer premises. Nine days after the implementation each time when login on the web interface a system alarm just popup saying '' Database traffic exceeds percentage limited '' . Have a question , with the default quota for the traffic log how many days pa device can keep the logs?Please ...

Resolved! Security Policy Rule matches on ALL URL categories

Hi,I'm sure this was working at some stage but now it's not working the way I need it: I have a rule from inside to outside, any user, web-browsing and a URL category of gambling, allow the traffic and use log forwarding with no profiles selected.The problem is that the URL is matched on ANY traffic. Doing a 'test url' from the command line list...

hoerzers by L1 Bithead
  • 10983 Views
  • 10 replies
  • 0 Likes

QoS (bandwidth) VPN site-to-site tunnel?

Hi all,I am trying to understand the QoS feature of the PAN-2020 and was wondering if I could get some assistance. We have a VPN site-to-site tunnel and the data center we are tunneling to is a 10 Mbps connection we can burst up to (10 Mbps being the max speed). We are using PAN-2020s on either side to manage the tunnel and I am looking into h...

cmateam by L3 Networker
  • 6654 Views
  • 3 replies
  • 0 Likes

M86 Migration Experiences

I may be starting a migration soon that includes migrating URL filtering from an M86 to PAN. I'm trying to get up to speed on the M86 (haven't used it before) and wondered if anyone had any hints, recommendations or "gotchas" to watch out for.Currently perusing the M86 web filter user guide but that never paints the whole picture. So, appreciat...

Resolved! Mismatch of static-ip source translation address range between original address and translated address

What exactly does this error mean?Error: nat rule 'ipCentrix Outbound': Mismatch of static-ip source translation address range between original address and translated addressI get this error during commit.I'm trying to:Change the Source Address to 66.111.112.5 forAny Packet to the Internet zoneThat has the destination address of 192.168.128.0/18...

JoshG by Not applicable
  • 24150 Views
  • 1 replies
  • 0 Likes

M100 - incorrect Message Authentication Code

I have the following setup: A VM100 that has multiple VLANs, for example LAN, Guest and DMZ. In the DMZ are some https websites, hosted on VM's on the same VM server as the M-100.Everything is working as expected, so internet, DHCP, DNS etc. is all working fine.However, when connected to the LAN, surfing to a https website in the DMZ results in:...

Palo Alto in Virtual Wire mode - problem with perimeter gateway (Firewall)

Hello everyone,I decided to post here a question that I hope someone would be able to answer or at least provide some guide to which direction to move.I have an opportunity to sell Palo Alto appliances to one of our clients and for that I need to show to the client that it is better that their current firewall.So configuration:Clients Perimeter ...

  • 24430 Posts
  • 125 Subscriptions
Top Solution Authors
Labels