General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 354 Views
  • 0 replies
  • 2 Likes

Resolved! Block users

Is there a way to block Guest users using their personal device with the virus or malicious software on it from accessing our network and notify them immediately using response or some sort of redirect page to contact support. Can PAN do this? If so

...

wesa by Not applicable
  • 2164 Views
  • 2 replies
  • 0 Likes

5.0.3 - Panorama Hanging on Commit

Has anyone else, with a 5.0.3 install, seen Panorama hang - requiring a hard (in the VM sense!) reset?

Twice within 48 hours of upgrading to this version have I had Panorama freeze totally when commiting.

First time was a local commit (saving a policy

...

apackard by L4 Transporter
  • 3007 Views
  • 5 replies
  • 0 Likes

Resolved! PanVPN agent

Hello admins.

I read in documentiotion that there is VPN client software for Palo Alto devices.

I wanted to try it out, but my licence expired and I can`t access to software page (if there is one).

I would like to know if system supports "client VPNs" (

...

Internet load balancing

Hi i have 5 internet connections (two dedicated links with different ISPs and 3 shared links with one ISP) , I need to configure the 5 untrust zones for internet and one for trust how i can configure the VR and how i can i use PBF per group of users.

...

Resolved! Deploying LSVPN ( Large Scale VPN) with NAT !!!

I'm newcomer with Palo Alto. I have project to deploy PA using LSVPN . But there is a problem because The Internet Link from ISP & MPLS must Via Router Cisco.

But I wonder , when using Router at Border , that means you must NAT Public IP to Private IP

...

MinhTuan by L0 Member
  • 4619 Views
  • 5 replies
  • 1 Likes

Resolved! GlobalProtect certificates

In my company we have AD and our internal CA. I want to use our internal CA for GlobalProtect. What I have done so far:

     I've import our root CA to PA500 (PANOS 5.0.3).

     I've generated web server certificate and imported it in PA500

     I've cr

...

marjan by Not applicable
  • 2398 Views
  • 2 replies
  • 0 Likes

Monitoring and Blocking eMail

Hello,

I want to know how I can do the following questions:

1.- How can I block in gmail application the access to all the mails like this xxxx@gmail.com, but allow the access to emalis like this xxxx@domain.ec that also are associated with Gmail.

2.- H

...

Angel by Not applicable
  • 1773 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect Usage Report

I have created a custom report to track all VPN users by subnet.. I parsed it to user and total bytes.. however, I can only get maximum 500 lines.. we have 1000 GP users, anyway around this?

rrau by L3 Networker
  • 1965 Views
  • 1 replies
  • 0 Likes

Resolved! FIPS mode IPSec cipher suite subset

When you enable FIPS mode on the firewall, what are the subsets of cipher suites available that the admin guide is referring to?

Admin guide -

"When configuring IPSec, a subset of the normally available cipher suites is available."

Mail server getting blocked when downloading files

I have an exchange server that is getting block-continues for file types that are not being explicitly blocked...pdf, jpg, etc.

It has no way to continue.....

I believe it must be some default behavior I am not aware of in the AV or AS profiles?

Where a

...

Resolved! Unable to connect Global protect portal,..

Hi All,

I am able to download GP client software, But using the same credential not able to connect to portal, giving error : portal error - unable to connect to portal. Only through one machine i am able to connect to portal using same credentials wh

...

Gururaj by L4 Transporter
  • 2044 Views
  • 1 replies
  • 0 Likes

Resolved! Tunnel Interface IP Address

Can somebody explain to me the need for the tunnel interface IP address? Apparently a VPN tunnel requires a tunnel interface configured with an IP address when using dynamic routing. Is that a dynamic gateway the PA is connecting to or the PA is usin

...

Resolved! what is standard port of ms-dtc app-id?

Hello.

I checked that ms-dtc standard port is tcp 139 on applipedia. I created couple of security rule for ms-dtc app-id and one was applied application-default at service column and other was applied specific service port tcp-49210, tcp-49217, tcp-49

...

Roh1 by Not applicable
  • 4361 Views
  • 3 replies
  • 0 Likes
  • 23674 Posts
  • 108 Subscriptions
Top Liked Authors
Labels