General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Captive Portal

has anyone got configuration for captive portal on and incoming untrusted public ip nat to private internal address.i need to authenticate incoming connections before they reach the internal server address.under captive portal I have the source as the public nat address and the destination as the internal server address and it does seem to work...

djrodb by L3 Networker
  • 14769 Views
  • 10 replies
  • 0 Likes

Resolved! problem with groups in user-id mapping

hi,i have a problem with using groups (from windows active directory) in security rules.on our windows active directory i have created a new group fw_finance. we use the PAN user-id agent to get the mapping from ip to user. i mapped this group on our PA-500 (user identification - group mapping settings). than i created a new security rule, that ...

assona by L0 Member
  • 12469 Views
  • 6 replies
  • 1 Likes

DNS Proxy

Can i use the DNS proxy feature for all external queries for our public sites?external user queries for www.mydomain.com - instead of our DNS servers replying, could we have the PA do it instead?So we can list out all our public domains and only those will respond?

rskler by Not applicable
  • 2518 Views
  • 2 replies
  • 0 Likes

Active/Passive - Failed to check Antivirus content upgrade info due to generic communication error

I am getting a daily notification that states that Failed to check Antivirus content upgrade info due to generic communication error . I have a HA Active/Passive set up on my network. The Active is connecting to updates.paloaltonetworks.com fine and is getting the most recent verison, and there is a Green Dot that connection is okay from the Ma...

Tunnel between PaloAlto and PaloAlto

Hello,i'm trying to get this constellation running:Two PA 200 behind a DSL-Home-Router and a firewall with a fixed public IP at the passive site.This image is just an example how it looks like....First i want to get the active site ("PA-Active"; PA 200; Version 5.0.6) running...I configured the IKE Gateway, Tunnel interface and also the IPSec Tu...

Hithead by L4 Transporter
  • 9305 Views
  • 16 replies
  • 0 Likes

Site to Site VPN from PA 200 to Juniper 5GT

Hi all,Anyone have a guide on how to set site to site vpn between PA200 and Juniper 5GT?. I tried a luck but now enable to establish a connection. In Juniper the tunnel i created the status is ready.A little help please.thanks,Jun

JunNOC by Not applicable
  • 3500 Views
  • 3 replies
  • 0 Likes

Scheduled Log Export : Path

Hello Guys,Just a quick question, I tried to dig in the forums but i can't find the right answer. the guide isn't helping too.I would just like to know the configuration in adding the Path in the Schedule Log Export.What I understand in the Path is I will just have to add the path on where the file will be saved. (am i right?)so for example the ...

DHCP server and descriptions for reserved addresses

HelloI'm using dhcp server on PAN for few small LAN. I'd would like to have ability to put label for reserved addresses. I beleave that it's usable for most of us but impossible in 5.0.5 PAN.Did someone asked for such FR?With regardsSlawek

_slv_ by L4 Transporter
  • 7595 Views
  • 6 replies
  • 0 Likes

Resolved! Can you set policy based forwarding in a virtual wire deployment?

I have our PA firewall set in virtual wire deployment. Can i set PBF's so I can do things like route things like audio-streaming to a cable modem that we have attached to the firewall? I've tried and when trying to set the zone/interface it doesn't list the vwire interfaces as options.

Netwerx by L2 Linker
  • 5129 Views
  • 4 replies
  • 0 Likes

Resolved! Unable to ping the ip address assigned to untrust interface.

Anyone can help on this issue? I just set up a new PA 200 device. My problem is i am not able to reach the ip address from outside which i assigned to my Untrust interface. Outbound traffic is ok. I have full access to the internet from internal LAN.

JunNOC by Not applicable
  • 3781 Views
  • 3 replies
  • 0 Likes

vpn between nortel and PA-500

Hi All,I have nortel vpn router 1750 in our main site and PA-500 in the branch, I need ipsec tunnel between devices. Nortel has static IP, but PA dynamic. I found that Nortel has site-to-site, initiator and responder options. which option I have to use site-to site or responder? can PA become Initiator in this case?Thank you.

Aslidin by Not applicable
  • 2942 Views
  • 2 replies
  • 0 Likes

Anyone Blocked a specific file from being downloaded?

Hello All, I am wondering if there is a way to block a specific file from any internet source. We would like to block users from grabbing a specific unsupported browser. (when you have 85k+ workstations - you need to keep them uniform for supportability ) I am looking at the File Blocking option and it doesn't seem to allow for specificatio...

Art by L3 Networker
  • 8145 Views
  • 7 replies
  • 0 Likes

Resolved! page cannot be viewed properly

Hi,There is a web page that cannot be viewed properly because of ssl decryption.Decryption is made for gmail applications by using custom urlIs there a way to fix that without disabling ssl decryption ?

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels