General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

dependency warning - how to force it?

HiI'm bit confused about dependency ...During commit i have: vsys1: Rule 'XXXXXXXXXXX' application dependency warning: Application 'gmail-base' requires 'imap' be allowed, but 'imap' is denied in Rule 'Scholastycy - deny rest' Application 'gmail-base' requires 'pop3' be allowed, but 'pop3' is denied in Rule 'Scholastycy - deny rest' ...

_slv_ by L4 Transporter
  • 4634 Views
  • 4 replies
  • 0 Likes

Resolved! Security Policies - Terminology

I am coming from a Checkpoint environment and I am struggling with some of the terminology. I see a number of references in the Getting Started and the Administrator's guides to "Security Policies". To me this implies that I can create a number of policies but it looks like in fact there is only one policy per box and the policy has multiple rul...

jmayne by Not applicable
  • 5199 Views
  • 8 replies
  • 0 Likes

Resolved! Global Protect and two gateway

HelloI have PA200 without licence for second GP Portal.I did a second gateway because I thought that this should solve my problem.I need to let access to some website to my users but with my IP address. Thease people has accounts on radius server. I did second gateway for them.I have separate IP and SSL certyfiacate for this, separate config (di...

_slv_ by L4 Transporter
  • 6314 Views
  • 7 replies
  • 0 Likes

ICMP reply size in 4.1

Is it possible in 4.1 to limit the size of icmp replies or strip any payload in order to discourage tunneling via ICMP ?

mbecker by Not applicable
  • 3670 Views
  • 5 replies
  • 0 Likes

Resolved! OCSP on SSL decrypt with self signed certificate

When enabling OCSP and having a self signed certificate for SSL decryption(we push the certificate to all our domain clients)will OCSP check my self signed certificate against the OCSP responder (and fail because it is unknown)?Or will it only check the original destination server certificate (for example that of facebook)?

mr.linus by L4 Transporter
  • 10005 Views
  • 10 replies
  • 0 Likes

Resolved! Problem VPN Split-Tunneling

Hi everybody.I've got a strange problem related to split tunneling in PAN configuration. The situation is:- Portal and Gateway configuration in PAN-2050 with PANOS 4.1.7 (same results with 4.1.6 and 4.1.5).- VPN client Cisco compatible (Windows and Linux, same results)- IP Pool: 192.168.46.0/24- Access routes: 10.0.0.0/8 and 172.16.0.0/12The pro...

Packet capture of specific Security Rule?

I need to confirm what traffic data (specific DNS Request strings inside the packet) is hitting two specific Security rules, so would like to capture just the traffic that is hitting these rules. Is there any way to do this?I have run the Packet Capture (in,out,firewall, and drop), filtered to port 53 (DNS), but have no way of knowing WHICH rule...

Netconnect File Extension

When I try to download the latest netconnect install file from the Software Updates web page it downloads without a valid file extension. When I download the file PanVPN-1.3.4 shouldnt it be PanVPN-1.3.4.msi ? I've tried renaming the file...

awdinfra by L0 Member
  • 3985 Views
  • 3 replies
  • 0 Likes

Resolved! Antivirus Compatibility Mismatch

Hi, i just realised that my two PA (active/passive) have an alert of HA Antivirus Compatibility. I have checked the version in Dynamic Updates and its the same in bot devices. CAn you tell me why this mismatch happens???I attached an screenshot with 2 device and the antivirus version

Facebook is not displaying its page/images properly when SSL Decryption is enabled

Facebook is not displaying its page/images properly when SSL Decryption is enabledany ideas why ?*Note: I have a rule allowing ANY destination with ANY application with ANY service, also another rule i tried was with ANY destination with Explicitly allowing all facebook applications on service ANY, and yet it didn't work.My SSL Forward certifica...

AKamal by L0 Member
  • 9270 Views
  • 7 replies
  • 0 Likes

Nested Active Directory Groups

Can it handle nested Active Directory groups?Security policy with a group which a user is not direct member of. When user tries connection through firewall then it checks the groups within the group (an so on).Can it be configured how deep the nesting is checked?

Anon1 by L4 Transporter
  • 7763 Views
  • 5 replies
  • 0 Likes

Resolved! Mac OSx & UserID

I have a question. Maybe someone has run across this.I am using the server monitoring function of PaloI realize that I can use the user-ID agent and set it to never forget the user mapping, but I am looking for a more accurate way of keeping this mapping.We have mac's that authenticate to a win 2008 domain. Initially I get the user to ip mapping...

Security Policy's and NAT

Hi,I Have configured a BYOD wireless ssid that is being forced to the internet via a port on our 2050. I am trying to get the network to be able to contact our mail server for exchange on mobile devices and also to have access to our content server redirect page. Our internal IP address for the BYOD is in the 172.x.x.x range. I am NATing these i...

mavant by Not applicable
  • 7561 Views
  • 11 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels