General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Log Type Unknown

How do I figure out what the log type I have is when its showing me "unknown" for the current type?*edit* Sorry they are assumed for the IDS/IPS

Global Protect Welcome Page with ActiveX

Hi Guys,is it possible to customize the welcome page of Global Protect with ActiveX scripts? I need this to run Active Directory login scripts automtically after a connect with Global Protect.CheersDirk

DirkSch by L0 Member
  • 3156 Views
  • 3 replies
  • 0 Likes

Global Protect too many outstanding keep alive

Hello guy'sdid Someone see this kind off message in global protect agent log on windows device.message :too many outstanding keep aliveand just after this message a logout is innitiated the VPN session is mount conntected and after less than 2 min a lougout occured.very strange situation with the 12.4 global protect agent and 5.0.5 PANOS on PA500.

Gregoux by L4 Transporter
  • 4243 Views
  • 1 replies
  • 0 Likes

Resolved! PAN as an explicit proxy?

Hi all,I have a simple question, is it possible to make my PA-3020 work like an explicit proxy ?I configured URL Filtering and I would like to adress web requests to the PA-3020 just like if it was a real explicit proxy...Many thanks in advance.Rudy

Is there a possibility of Palo Alto releasing rule content, similar to the way Sourcefire/Snort handle IDS rules?

We have Palo Alto appliances and we have Sourcefire IDS appliances running side by side in various configurations at work. I can't emphasize enough how convenient it is to be able to have an IDS event fire off from our Sourcefire boxes, and when I drill into the event I can actually see the rule that was written that matched on the event.In my e...

Alarm on device

Hi, We've did a little bit of testing on Palo Alto device and kind of want to know something about Alarm that we still can't produce the issues such as - At what temperature or percent that device will generate an Alarm - At what percent of CPU usage that device will generate an Alarm (both management plane and ...

Resolved! virtual-wire ARP issue

hi!i have a topology of 2 cisco routers connected to e1/1 and e1/2 in a virtual-wire deployment. there is only 1 policy on the PA, permitting all traffic, and all VLANs are permitted through the v-wire.the problem is that when i try to ping from R1 to R2 through the PA, the ping fails, and i do not get the MAC address of the destination interfac...

Resolved! empty user list

Hi,Device stopped to take user information from agent.Show user ip-user mapping all comes with 0 user.Passive device works fine.it shows all users.Agent connection is fine for both device.Any idea ?restarted user-id with debug command but did not solve.

Resolved! MS-RDP and t.120 -> application: not-applicable

Hi,I have a few rules that only permit ms-rdp and t.120. A new rule was implemented last week that permits ms-rdp and t.120, just different source addresses. The other rule can see the ms-rdp application but for the new rule, it shows up as application not-applicable and the traffic is being blocked.I looked around here for some answers and have...

Resolved! Bind multiple VPNs to a single tunnel interface?

greetings all,I come from a ScreenOS background, and in their world, you can terminate multiple route-based VPNs onto a single logical tunnel interface.We have 30-40 remote sites with VPN tunnels back to HQ, which will soon be a new PAN firewall. In our lab I have tried to configure multiple IPSec VPNs terminating onto the same tunnel interface...

Resolved! Best practice: external interface with DHCP?

Hi,As I understand it I need to use an address object to create inbound NAT polices for the external interface. What is best practice to use a PAN firewall with a ISP with DHCP? I know this is not the most common setup for this high-end device but for in some cases it's needed.Right now I'm planning to use a dynamic dns service and use a FQDN ty...

Experience in 5.0 code train

Hello,How many people are running 5.0 in their production environment? How are your overall experience so far?Code stability?Any Outstanding issues?Thanks for your feedback in advanced..

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels