General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 307 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 982 Views
  • 0 replies
  • 0 Likes

Resolved! Adding domain to username for user identification

Hello

We are using RSA for user authentication with Global Protect.

We need to identify the LDAP group (Windows Active Directory) the user belongs to, but It doesn't work.

The reason is that the user we use for authentication doesn't include the domain

...

iOS device "network errors" when SSL Decryption is turned on

Regarding SSL Decryption:

I originally put the whole category of "social-networking" under a Decrypt rule (mainly to decrypt Facebook to block Facebook games).  However, when I tested on my iPhone after that, LinkedIn, Twitter and Facebook all had "ne

...

uscit by Not applicable
  • 2879 Views
  • 2 replies
  • 0 Likes

GlobalProtect VPN with Windows-PKI (W2K8R2)

Hi

Currently we have a beta-environment for GlobalProtect-VPN on Windows7 (64bit).

Authentication with LDAP works fine.

But we want to use a client-certificate (user) from our internal Windows-PKI which is already rolled out to the endpoints.

Where can i

...

Resolved! OpenVPN

Hi,

Since application version 370 released, I have some trouble with openvpn :

Openvpn udp on port 443 didn't work anymore

Openvpn udp on port 1194 works

Maybe there is a bug on the new application version. Openvpn not on the default port didn't be recon

...

Policy Based Forwarding

We have a branch in a different state to which we have a DS3 MPLS circuit. We and our  branch office have there own ISP connections for Internet access. I would like to have redundancy build between both of our companies through IPSec VPN tunnel in t

...

how to clear TCP options using Palo Alto firewalls?

At the moment we are replacing our Cisco ASA firewalls with Palo Alto firewalls and one thing we cannot still figure out is how to make the Palo Alto firewalls to clear the TCP options on TCP sessions. This can be done, in Cisco ASA firewalls, using

...

netexgb by L1 Bithead
  • 4986 Views
  • 8 replies
  • 0 Likes

Resolved! L2 "switch" ports?

Hi All,

Am I right in saying if I configure a selection of interfaces (in this case on a 3020) as L2, and then assign them to a VLAN with a L3 VLAN interface all those ports will sort-of act like a switch (or more likely a hub)?

A bit like the handful

...

Dpeters1 by L2 Linker
  • 3068 Views
  • 2 replies
  • 0 Likes

Resolved! minimum PanOS version for UserID version

PanOS release notes call out the minimum User ID agent version supported. UserID agent release notes do not call out a minimum PanOS version. Is there any issue in getting ahead on the UserID agent version? For example, we have several devices runnin

...

gmparis by Not applicable
  • 2759 Views
  • 1 replies
  • 0 Likes

Resolved! All sites registering as "unknown"

Came in today with users screaming that they were getting blocked on all websites.  Finally extracted enough information from them that the category was coming up as “unknown” for all sites…even Google.  Decided it had to be an issue in the URL filte

...

mmartin by L1 Bithead
  • 15984 Views
  • 34 replies
  • 1 Likes

PBF rule

Hi,

Could you please help me with the below query.

What exactly it happens when I enable "Disable this rule if nexthop/monitor ip is unreachable" in the PBF rule - > Forwarding Tab - > Monitor Check Box.

Suppose , if the Monitored IP is not reachable ,

...

Upgrade to 5.x - the good, the bad, the ugly?

OK, one for you guys who have upgraded to the 5.x stream.

Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?

I have a single HA pair, no Panorama, no Wildfire subscri

...

darren_g by L4 Transporter
  • 3662 Views
  • 5 replies
  • 0 Likes

PA 2000 platforms rebooting in our network

We have deployed around 10 pairs of PA 2000 platforms in different networks within our environment.

These networks almost generate the same type of traffic. What we experience is that, these firewalls which ever is active, goes in for an automatic reb

...

  • 24040 Posts
  • 115 Subscriptions
Top Liked Authors
Labels