General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! autocommit fail

Hi,upgrading from 4.1.13 to 5.0.0 using upload option;device boots and at %10 for autocommit it fails and again and again trying to autocommit and fails at %10any idea ?

Resolved! log export

Hi,When exporting logs from Monitor / Traffic tab to excel file is there a way not to export all columns(fields) ?

Resolved! dhcp server stops

Hi,Panos ver 4.1.13 Dhcp server on layer3 interface suddenly stops.Restarting device fixes that.error comes as Failure: dhcp server is not enabled on interface 'ethernet1/3'.Anyone see that error ? Any idea ?

Resolved! Global Protect password expire

Hi,When clients connect to Global Protect they got a warning password will expire and it says 1 day.I looked to LDAP profile it is as default 7What could this warning be ? How can we disable this ?We also checked Active Directory for password expire but it is not 1 day.

Resolved! Guest Network Setup

Hi - What is the best method to setup a guest L3 network in PanOS?UntrustA = CorporateUntrustB= Guest InternetwDMZ = Wireless DMZ for Guest Internettrust = CorporateRequirements =1. wDMZ needs to get to a few specific IP's on UntrustA.2. wDMZ needs to get to the Internet via UntrustB.Initially I was thinking of a second vRouter? OR is policy bas...

PA-500 and Jumbo Frames

Background: I've been doing some testing with a pair of A/A PA-500's and decided to enable jumbo frames on a file server. I understand that the PA-500 does not support jumbo frames but when I begin a file transfer, it works, running at about 5,017 Kbps. After a little while the frame size reaches 4464-bytes and my speed increases to 392,644 Kbps...

GtY007 by L0 Member
  • 4245 Views
  • 3 replies
  • 0 Likes

Qualys Scan alert on OpenSSH J-Pake

We run Qualys scans on the internal network, and it's picking up that the PA's are running OpenSSH ver 5.2. I receive the following warning:OpenSSH, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol. This allows remote attackers to bypass the need for knowledge of the shared secret, and successfully ...

dru by L0 Member
  • 5528 Views
  • 6 replies
  • 0 Likes

Having to reset the dataplane frequently

Hello,We've been having an issue in our environment where we need to reset the dataplane because randomly packets will traverse our rules and start getting denied. We aren't sure why this is happening or what's causing it. What I'd like to know is if anyone could shed some light on how we can go about troubleshooting.Let me know what info you ma...

grkchr by Not applicable
  • 6048 Views
  • 5 replies
  • 0 Likes

GlobalProtect client doesn't inform the user that the portal/gateway connection is timing out

In my testing of the GlobalProtect client (I'm using the latest stable, 1.2.1), I noticed that if for any reason the connection to the GP portal or gateway times out (e.g. the user's laptop isn't connected to the Internet, doesn't have the correct IP address, doesn't have the cable plugged in, etc etc) the client will never actually inform the u...

SSL based custom application also seen as SSL

Hi,I set up an SSL based custom application for a specific web application in the company.I followed this document : But when I look at the traffic logs, for every connection to this application I have :- 1 log that shows traffic as "ssl" application,- 1 log that shows traffic as my custom application.07/23 18:11:18 traffic start ssl ...

mattieub by L0 Member
  • 3080 Views
  • 2 replies
  • 0 Likes

PA-2050 - what are the aho_sw_fpga_unavailable and dfa_sw_fpga_not_loaded counters all about?

HelloI'm trying to find out what the following two counters are all about and if our rate/count for these counters are anything to worry about regarding Data plane performance issues with our PA2050 Active-Active platform. NameCategorySeverityAspectValueRateaho_sw_fpga_unavailableahowarnpktproc29184581949dfa_sw_fpga_not_loadeddfawarnoffload1808...

Smi12 by L2 Linker
  • 4165 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect and HIPS

We have setup Global protect and are able to connect to our network.Once we add a HIPS profile all the traffic gets denied. The only setting in the HIPS profile is the OS is microsoft.We are currently using Software version 5.0.6 and global protect 1.2.4 and have even tried rolling it back to 1.2.3 and still no luck. Has anyone had a problem lik...

murphyj by L2 Linker
  • 7995 Views
  • 8 replies
  • 0 Likes

Resolved! Palo Alto cant filter users in a group

Hi,I have a PA2050 v(4.0.11) and PAN-Agent for ldap users and groups. I have created a a group in my Active directotory and i configure a policy for this group but i try to check this policy with one user in this group and firewall dont let me passtrough.I cant see that my user belongs to this new group but i can add this group in policies.telin...

Resolved! user-id agent commit issue

Hi team,I have got issue when trying to commit our configuration on User-id agent.User-id agent can not to connect AD without commit.Who have an experience of this, please help.BR

Ulugbekyu by Not applicable
  • 4903 Views
  • 4 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels