General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ignore_user_list

Hello,I'm using PAN Agent 3.1.2 on WIN2008 server and somethimes after restart the Ignore_user_list seams to be ignored )user on the lista are still identified by the PAN firewall).Does someone had this problem ? there is way to have an alert or log in case of this problem ?Can we debug PAN agent to see if the ignore_user_list is not loaded ?The...

Security policies did not take effect after Sleep Mode

Hi,Just like to find out if there is a known issue with Palo Alto and Windows 8 for direct internet policy. Currently, we have defined a policy in PA to allow AD user to connect to internet. However, based on my observation, once my notebook goes to sleep mode, then wake up, then login the policy doesn’t seem to take effect. To gain direct i...

Operation Failed: Invalid Sequence

Hello,I recently upgraded to Panorama 5.1.0 (I know, I'm a glutton for punishment!) and am experiencing an issue when attempting to add items to an application group. We've tested this with several workstations and both IE and Chrome and each result is the same. As soon as we attempt to type in a new application to find it in the list, we are gr...

Resolved! syslog no log sometimes

Hi,Pa200 configured to send all to syslog.Sometimes(Random) no log comes to syslog.Did Anyone see an issue like this ?5.0.5 panos.

Resolved! GlobalProtect assigning zone based on AD group membership?

I'm fairly sure I can't do as the subject line, so I'll explain why I think I want it, and hope someone can suggest a better workaround.We're a college campus with (roughly) 3 classes of users: students, general faculty and staff, and "special" staff. On the wired/wireless networks, we segregate users based on 802.1X and some pretense of physica...

rgraves by Not applicable
  • 6336 Views
  • 6 replies
  • 0 Likes

In HA, Pasive firewall sent the traps and CACTI shows data, Active send nothing

Hello everybodyI have 2 PA-2050 with PanOS 4.0.11 configured with HA. The traps are sent by the Pasive Firewall not the Active, also source IP of the trap belongs to Pasive not by the shared management IP.I just checked the managemtn Profile and SNMP its available.Moreover, I have a CACTI server, the graphs of the Pasive firewall works fine but ...

SOC_CSG by L4 Transporter
  • 2150 Views
  • 1 replies
  • 0 Likes

DHCP issue in vwire

Hi all,Having a really simple archie with two ports in vwire (Allow all vlan and multicast on it), create a rule "trust to untrust allow all".Issue is for dhcp request, I have to create a rule allowing dhcp answer from untrust to trust ....In my mind there is no reason to do that .. If request is allowed, answer should be automatically.Maybe som...

VinceM by L5 Sessionator
  • 4244 Views
  • 4 replies
  • 0 Likes

Need help for HA Active/Active configuration with two ISPs with IPs in different subnets.

Hi All,In below scenario firewall external interfaces of both firewall has configured with IPs in the same subnet (topology 1)what if configured with the different IPs for different ISPs (topology 2). Kindly consider the above query all the HA Active/Active methods (Floating IP, ARP load sharing and Mixed mode of both).Thank you,Gururaj

Gururaj by L4 Transporter
  • 5367 Views
  • 4 replies
  • 0 Likes

Is it possible to block method POST in any website?

Hi guys, Our company don't want employee to post anything on internet so we're trying to create custom application that block method POST on http-request-message. But when we're trying to write a pattern. It's always pop up an alert to say that at least 7 bytes require. we've tried it so many ways such as [a-zA-Z0-9] but it still w...

Global Protect Portal/Gateway Certificate Issue

Hi,Just recently after upgrading to Global Protect Version 1.2.4 we started getting error messages on our external users laptops that there was an " CN Mismatch Name" but continuing still allowed them to connect..After determing it was a Common Name issue with the Device Certificate " web-server" - Subject "Local Host"I am now after some instruc...

acmi by L1 Bithead
  • 2798 Views
  • 1 replies
  • 0 Likes

Resolved! Daily packet capture limit of PA-3000?

I would like to know Daily packet capture limit of PA-3000 serial.Do you know this?other serial device is...>  PA-5000 : 786432>  PA-2000 : 131072>  PA-500 : 32768>  PA-200 : 65536Regards.

smaekawa by Not applicable
  • 4763 Views
  • 4 replies
  • 0 Likes

Certificate Error in Global Protect Portal

Hi All,I'm trying to setup the Globalprotect VPN and have followed the (only partially helpful) GlobalProtect-Configuration-4.1.pdf to create certs and set everything up. When I try to connect to the portal site with my browser I get a certificate error - "Error code: sec_error_bad_signature".It doesn't matter if I conect to the host name or the...

smithkopel by Not applicable
  • 38477 Views
  • 23 replies
  • 0 Likes

Resolved! IOS Global Protect APP - Required Client Certificate is not found

Hi l am trying to configure the IOS App with our PA 2050 and l am getting the message :Gateway " IP Address " : Required Client certificate is not foundI have installed a 30 Day Trial license of the Gateway to test this but still the same error message.. Do l need to import a security certificate to the IOS iphone ?Thanks Simon

acmi by L1 Bithead
  • 9563 Views
  • 5 replies
  • 0 Likes

How to control URL Filtering bypass by IP?

Hi all,How can the Palo Alto control the age-old URL filtering bypass of typing in the IP address of a site, rather than the hostname?As an example, some of our students last week did:1. www.minecraft.net via web browser is blocked (category: games)2. do an nslookup or dig for www.minecraft.net3. type IP address into browser and then get through...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels