General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

SSL traffic mis-identified as TOR

Hi,

Seeing over the last few days traffic going from our users (various different users in different locations) to IP addresses in Google's range (74.125.0.0/16) being identified as TOR, and subsequently blocked - traffic is all dest port 443.  This i

...

Delete user out of the user agent via API

Hi.

I would like to delete a specific user out of the user agent cache via the XML API. Is it possible to do this when the ip user mapping was done by the agent itself (get the user via DC or exchange login). I enabled the user id XML API on the agent

...

Report Management via the GUI...

I sent the following in to our VAR/SE for a product Enhancement. If you feel the same, I hope you can request this also. What are your thoughts on this request?

The Reporting structure on the PA GUI is set up to MAKE lots of reports, and/or auto-gener

...

SSL Decryption with Mutual (2 Way) Authentication

Hi,

I have traffic that uses mutual (2 way) SSL Authentication that I would like to decrypt. I was able to decrypt when just using the server certificate, but when I add the client certificate it no longer decrypts (the connection still works though).

...

ckawecki by Not applicable
  • 2555 Views
  • 2 replies
  • 0 Likes

Resolved! Editing profile

Hi.

Does anyone know is it possible to change main email address on palo alto web site profile?

Thx

Global Protect bugs/enhancements

I may be doing something wrong on my end, but I have a few things that could improve the product a bit.  I am using the latest version 1.2.3-6.

1) When using On-Demand basic mode I cannot click File > Connect.  The option is grayed out.  However I can

...

nthen by L3 Networker
  • 1643 Views
  • 1 replies
  • 0 Likes

Authentication after blocked page

Dear All,

If I have two groups of users, one with more restrictive access to the internet via URL Filtering than the other.

If the more restrictive group access the internet and receive a block page as their policies do not allow access to that resourc

...

JAG by L1 Bithead
  • 2184 Views
  • 3 replies
  • 0 Likes

SSL Decryption

Hi All, I have an issue with SSL decryption and using the inbuilt CA. What appears to happen is that various parts of SSL websites don't trust the CA on the palo alto and as a consequence sites do not load fully and report various certificate issues.

...

Resolved! Ubuntu and PA-200 DHCP

I'm having a problem with mostly Ubuntu users not being able to resolve DNS. I say mostly because there is at least one Windows user having the same problem. None of the Mac workstations are having the same problem and the majority of the Windows mac

...

Global Protect - How does patch matching work?

Can someone please detail how a HIP profile for missing patches works?  I have tried every combination possible and I always get the same result.

My Criteria is as follows:

Patching is Enabled Yes is Installed Checked

Severity - Greater than 2 (Which me

...

allens by Not applicable
  • 2160 Views
  • 1 replies
  • 0 Likes

Antivirus DB not showing up on inactive HA node

Hi,

I have a pair of PA-500 in an active/passive cluster. The Dashboard says that all content is matching between the nodes. However, if I go into Device->Dynamic Update on the secondary node, there is no Antivirus in there. I can only see it on the p

...

Resolved! Policy Based Forwarding - Enforce Symmetric Return

Hi,

I am planning a firewall migration right now and trying to solve the problem that traffic comes in through two different interfaces during the migration (Internet through old firewall, Internet through new firewall). I was looking at policy based

...

Port Forwarding Without NAT

So, I have a very interesting network.  I have a media server that is on a separate VLAN.  There is no way for me to statically configure the client(s) with a static IP (they just search for the server).  It uses tcp/32400.  Basically, my host will s

...

Resolved! NAT exclude

Hi,

is it possible to make exceptions/exclusions for a NAT rule? Think of this scenario:

  • small PA-200 setup
  • only one external/public IP address
  • that IP address is used for a lot of incoming NAT
  • the NAT rule basically forwards everything from the external
...

Best practice for demo PAN in Tap mode

Hi,

I have to demo PAN in 3 Legs firewall compose Internet, DMZ and Internal zones. so I have some question regarding to this.

1. What mode on mirror I should config on the firewall, TX or RX or TX and RX ?

2. Should I configure virtual system for each

...

  • 24195 Posts
  • 100 Subscriptions
Top Liked Authors
Labels