General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

GlobalProtect client doesn't inform the user that the portal/gateway connection is timing out

In my testing of the GlobalProtect client (I'm using the latest stable, 1.2.1), I noticed that if for any reason the connection to the GP portal or gateway times out (e.g. the user's laptop isn't connected to the Internet, doesn't have the correct IP address, doesn't have the cable plugged in, etc etc) the client will never actually inform the u...

SSL based custom application also seen as SSL

Hi,I set up an SSL based custom application for a specific web application in the company.I followed this document : But when I look at the traffic logs, for every connection to this application I have :- 1 log that shows traffic as "ssl" application,- 1 log that shows traffic as my custom application.07/23 18:11:18 traffic start ssl ...

mattieub by L0 Member
  • 3151 Views
  • 2 replies
  • 0 Likes

PA-2050 - what are the aho_sw_fpga_unavailable and dfa_sw_fpga_not_loaded counters all about?

HelloI'm trying to find out what the following two counters are all about and if our rate/count for these counters are anything to worry about regarding Data plane performance issues with our PA2050 Active-Active platform. NameCategorySeverityAspectValueRateaho_sw_fpga_unavailableahowarnpktproc29184581949dfa_sw_fpga_not_loadeddfawarnoffload1808...

Smi12 by L2 Linker
  • 4221 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect and HIPS

We have setup Global protect and are able to connect to our network.Once we add a HIPS profile all the traffic gets denied. The only setting in the HIPS profile is the OS is microsoft.We are currently using Software version 5.0.6 and global protect 1.2.4 and have even tried rolling it back to 1.2.3 and still no luck. Has anyone had a problem lik...

murphyj by L2 Linker
  • 8160 Views
  • 8 replies
  • 0 Likes

Resolved! Palo Alto cant filter users in a group

Hi,I have a PA2050 v(4.0.11) and PAN-Agent for ldap users and groups. I have created a a group in my Active directotory and i configure a policy for this group but i try to check this policy with one user in this group and firewall dont let me passtrough.I cant see that my user belongs to this new group but i can add this group in policies.telin...

Resolved! user-id agent commit issue

Hi team,I have got issue when trying to commit our configuration on User-id agent.User-id agent can not to connect AD without commit.Who have an experience of this, please help.BR

Ulugbekyu by Not applicable
  • 5043 Views
  • 4 replies
  • 0 Likes

Maximum latency between HA peers?

Whats the maximum latency allowed for HA peering links (e.g HA1 control and HA2 keep-alive) between devices setup in active/passive HA pair?i.e based on the latency can determine the approximate distance that HA pairs can be physically separated.. 1Km .. 100Km? etc. whilst connected via dark fibre.

CMG by L2 Linker
  • 5298 Views
  • 1 replies
  • 0 Likes

Site-to-Site vpn and NAT

Hello,I have one vpn configuration question, I hope somebody can help...I am configuring vpn site-to-site in my site PaloAlto, other site is not important in this case.I am making source and destination NAT for the traffic that is used for vpn. The purpose of this NAT is that we have lot of vpn tunnels and we have similar IP networks on local an...

aaputis by L0 Member
  • 4803 Views
  • 3 replies
  • 0 Likes

Resolved! Policy with "Log at Session Start" option - how to find it?

HelloI have about 100 polices on my device, some of them has "Log at Session Start" option enabled. Is it posisible to find it from the CLI ?I have very little skills in CLI so please give me the whole CLI command.I realised that my weekly reports are unusable because I have only data from last few days. How I can save some space on PA200 to get...

_slv_ by L4 Transporter
  • 11196 Views
  • 7 replies
  • 0 Likes

Panorama: migrating between a failed and replacement device

Hi all,I am running Panorama with two PA-5020s which belong to one device group. The policy for this group applies to both or either firewalls, depending on zones (basically, this is a non-HA pair on two Internet links). One of the 5020s has gone into castors-up mode and is being RMA'd; a replacement is due tomorrow.As Panorama seems to refer to...

notes01 by L2 Linker
  • 4354 Views
  • 3 replies
  • 0 Likes

How Long to Update Firewall from Panorama

I changed a zone in a policy from Panorama but the change doesn't show when in the context for the particular device. Did I miss something? How long for that change to show up?

Weese by Not applicable
  • 4682 Views
  • 4 replies
  • 0 Likes

partial commits causing allowed RTP flows to change to discarding?

We are seeing a strange issue with our 4020s (running 4.1.8h2 right now) where, as far as we can tell, partial commits are at times causing some kind of HA event that, at times, causes some already-established RTP streams that are allowed by the policy to change from allowed to a discarding state. This causes our Polycom videoconference systems ...

How to skip CaptivePortal for one device?

HelloAs you can see on this forum I have some configurations problems with CP.In the zone where I have CP enabled I have Minolta BizHub c220 device (with static IP 192.168.3.251). This device has scan to email features. After I enabled CP for this zone of course noone email go to user.I checked almost every thread on this forum, but I didn't get...

_slv_ by L4 Transporter
  • 5156 Views
  • 6 replies
  • 0 Likes
  • 24431 Posts
  • 125 Subscriptions
Top Solution Authors
Labels