General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Possible Commit Lock Bug?

If I have a commit lock set, then I log in as another user and try to commit, the firewall stops me like it is supposed to. But if I hit commit, then I uncheck "Include Policy and Object configuration", it will allow me to commit the changes I have made. (i.e. modify the route table) Is this supposed to do this or is this a bug?Thanks

revans by Not applicable
  • 4694 Views
  • 8 replies
  • 0 Likes

SSL Decryption

Heywhy PA doesnt do SSL Decryption for this site: WeTransferi can see PA is recognizing it as this application: wetransferbut ican see the original Go daddy ceritifcate in the browser windows, and in the PA logs i cannot see "decrypted" on this traffic why is this?this is my decryption policy:-----------------------------------------------------...

minow by L4 Transporter
  • 4387 Views
  • 6 replies
  • 0 Likes

iPhone Applications

I have turned on SSL Decryption for my organization and am now receiving reports that iPhone/iPad applications have stopped working and there is nothing in the logs. To test whether the PAN firewall was the cause I contacted a user and put in a policy just for that mobile device source address as a no-decrypt exception. Everything worked.Q - I...

Resolved! Session Averages

I have been looking but I have not noticed a way to get an report on the number of sessions that have been active for the past month, does anyone know a way to determine that?

murphyj by L2 Linker
  • 3366 Views
  • 3 replies
  • 0 Likes

VoIP Traffic, strange behavior, need help to understand please.

Greetings All,I have an issue where we are seeing some strange issues with VoIP traffic.Device: PA-2020S/W Version: 4.1.9VoIP Provider: Foehn IP Telephone systems.Latest Application version.A new VoIP system has been deployed which has SIP traffic passing through the PA-2020.Application override policies setup for incoming and outgoing SIP tra...

Trouble decrypting Google traffic

Hi,we have some trouble with a lot of Google sites when we enable SSL decryption and also enable CRL and OCSP checks. We either get no response at all, or error messages like the one in the attached screenshot. If we disable the CRL/OCSP checks (which is undesirable I guess), then we have no problems at all. Google is the only destination we hav...

Update 377-1826 breaks youtube-safemode

Just a heads up - it appears that update 377 has broken the detection of youtube-safemode, with everything being detected as youtube-base ; revert to 376-1817 appears to resolve the issue.

SimmSimm by L2 Linker
  • 6180 Views
  • 9 replies
  • 0 Likes

policy and security profiles

heyyi tried to troubleshoot some traffic behaviuor, an i created a rull without any security profile and with application overide.when i run those commands to look at the traffic i found this.admin@PA-500> show session all filter destination 147.235.246.154--------------------------------------------------------------------------------ID ...

minow by L4 Transporter
  • 4229 Views
  • 6 replies
  • 0 Likes

dependency warning - how to force it?

HiI'm bit confused about dependency ...During commit i have: vsys1: Rule 'XXXXXXXXXXX' application dependency warning: Application 'gmail-base' requires 'imap' be allowed, but 'imap' is denied in Rule 'Scholastycy - deny rest' Application 'gmail-base' requires 'pop3' be allowed, but 'pop3' is denied in Rule 'Scholastycy - deny rest' ...

_slv_ by L4 Transporter
  • 4416 Views
  • 4 replies
  • 0 Likes

Resolved! Security Policies - Terminology

I am coming from a Checkpoint environment and I am struggling with some of the terminology. I see a number of references in the Getting Started and the Administrator's guides to "Security Policies". To me this implies that I can create a number of policies but it looks like in fact there is only one policy per box and the policy has multiple rul...

jmayne by Not applicable
  • 4831 Views
  • 8 replies
  • 0 Likes

Resolved! Global Protect and two gateway

HelloI have PA200 without licence for second GP Portal.I did a second gateway because I thought that this should solve my problem.I need to let access to some website to my users but with my IP address. Thease people has accounts on radius server. I did second gateway for them.I have separate IP and SSL certyfiacate for this, separate config (di...

_slv_ by L4 Transporter
  • 5925 Views
  • 7 replies
  • 0 Likes

ICMP reply size in 4.1

Is it possible in 4.1 to limit the size of icmp replies or strip any payload in order to discourage tunneling via ICMP ?

mbecker by Not applicable
  • 3444 Views
  • 5 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels