General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Monitor vpn interfaces

Hi,According other discution I know that monitoring for tunnel interfaces through snmp is currently not possible. Would like to know if someone have done something to monitor them through the API ans can agree to share with us ....V.

VinceM by L5 Sessionator
  • 4464 Views
  • 4 replies
  • 0 Likes

App History and Old Release Notes

We recently had the issue where something that was working broke. It may have been a case where a new App was added or updated by PAN and some traffic that used to match a more general application (e.g. "ssl" or "web-browsing") now seen as a new application. The new App was not listed as allowed and got blocked. In particular, it's the "intuit-q...

cosx by L2 Linker
  • 3879 Views
  • 3 replies
  • 0 Likes

Auto update polices to Palo Alto

Hi all!I use Splunk to monitor the system. I use a script to automatically extract the IP from Splunk and want to send it to Palo Alto to block this IP?How do i do it?Thanks

dat.tran by L2 Linker
  • 5372 Views
  • 5 replies
  • 0 Likes

Problem exporting logs

Hi everybodyI'm trying to export a traffic monitor log but I always have the same problem. If I try to export a week or a single day I only get about 7-8 hours and a file of 16Mbs with no more than 50000 or 60000 rows. I have modified the "Logging and Reporting Settings" to increase the "Max Rows in CSV Export" to 1 million.My device is a PA-205...

SOC_CSG by L4 Transporter
  • 5009 Views
  • 6 replies
  • 0 Likes

PAN AGENT WITH MULTI-FOREST

Hello,I have Two FOREST A and B, I have a trust relation between this two forest.When I add a user of the forest A in the group (local) of the forest B I can't see in the pan agent the users.Any Idea to see the user of the forest A in the group of the forest B?regards,

alle by L3 Networker
  • 9940 Views
  • 12 replies
  • 0 Likes

LDAP and trusted domains

I use Active Directory groups to control my content filter policies. One of the groups is currently set to Domain Local as it contains a member of one of the trusted domains. I have an agent running in this trusted domain and the PAN appliance can properly detect the username. When I look in AD I can see the membership containing members of b...

nthen by L3 Networker
  • 5343 Views
  • 5 replies
  • 0 Likes

Resolved! 378-1833 update and Citrix with IE

Hello,one of our customer has an issue with the last update, it break the access to Citrix 6.5 Server for users with Internet Explorer (8 or 9 same behavior), but no issue with Firefox.They revert the Apps and Threats to 376-1817 update and now it works.The problem seems to be caused by the added Spyware Signature ID 13371 in this update.Are you...

rled by L1 Bithead
  • 6413 Views
  • 7 replies
  • 0 Likes

Possible Commit Lock Bug?

If I have a commit lock set, then I log in as another user and try to commit, the firewall stops me like it is supposed to. But if I hit commit, then I uncheck "Include Policy and Object configuration", it will allow me to commit the changes I have made. (i.e. modify the route table) Is this supposed to do this or is this a bug?Thanks

revans by Not applicable
  • 5029 Views
  • 8 replies
  • 0 Likes

SSL Decryption

Heywhy PA doesnt do SSL Decryption for this site: WeTransferi can see PA is recognizing it as this application: wetransferbut ican see the original Go daddy ceritifcate in the browser windows, and in the PA logs i cannot see "decrypted" on this traffic why is this?this is my decryption policy:-----------------------------------------------------...

minow by L4 Transporter
  • 4695 Views
  • 6 replies
  • 0 Likes

iPhone Applications

I have turned on SSL Decryption for my organization and am now receiving reports that iPhone/iPad applications have stopped working and there is nothing in the logs. To test whether the PAN firewall was the cause I contacted a user and put in a policy just for that mobile device source address as a no-decrypt exception. Everything worked.Q - I...

  • 24449 Posts
  • 125 Subscriptions
Top Solution Authors
Labels