General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! Limiting the "admin" logging sessions

Hello everyone; some of you know if there is a way to limit the admin logging sessions. This is, if I logging in the firewall with the "admin" account from the PC A; and I try to logging to the firewall with the "admin" account from the PC B too; I should be unable to do it.Thank you for your help.Best regards.

Smartekh by L1 Bithead
  • 3173 Views
  • 3 replies
  • 0 Likes

User ID agents showing as red

I have 3 separate domains on my network and they are not trusted together. On my main domain where the firewall is installed the agent shows green, however when I install the agent under the remote domains (on different subnets across the country) the icon is red. The settings match my 2 main domain controllers that are working. When I look a...

nthen by L3 Networker
  • 12812 Views
  • 22 replies
  • 0 Likes

NetConnect and GlobalProtect VPN Dual Setup in 4.0

We are still on 4.0. Is it possible to setup the GlobalProtect configuration while still in 4.0 and allowing Netconnect to continue working? This will allow us to create documentation for end users and distribute it and publish it before migrating. Thank you

parkerbc by Not applicable
  • 3661 Views
  • 3 replies
  • 0 Likes

Routing through virtual systems

Hello,I have such situation that I need to make routing through virtual system. I added a network diagram below.Maybe you guys can help me in this situation.I want that traffic from Vsys2 can access GW_default as it can Vsys1. Also I want to control traffic between zone_1 and zones_2, zones_3 .What solutions there can be ? I now that there is sh...

aaputis by L0 Member
  • 2577 Views
  • 1 replies
  • 0 Likes

Resolved! Connecting two L2 segments via PAN?

I am trying to connect two separate Layer2 segments using the same VLAN ID 569 and same IP subnet 10.10.69.0/24.The firewall has:ae1 (mode layer2) with members ethernet1/1 and ethernet1/2ae2 (mode layer2) with members ethernet1/5 and ethernet1/6VLAN 569 configured with name UC_Servers> show vlan "Unified Communications Net 569"total vlan show...

efellows by L1 Bithead
  • 3930 Views
  • 3 replies
  • 0 Likes

GlobalProtect algorithms

Hi,Does anyone know what kind of algorithms being used with GlobalProtect and how much a administrator can control this?/kristian

kristian by L3 Networker
  • 3344 Views
  • 4 replies
  • 0 Likes

Resolved! What are the available variables for response pages?

What are the available substitution keywords for the response pages? Do they differ by page?I am trying to incorporate an email with all the pertinent information to be sent to our internal systems. Unfortunately, the keywords that I have found for substitution are insuffficient. For example:<h1>Virus Download Blocked</h1><p&gt...

kpatten by Not applicable
  • 10575 Views
  • 7 replies
  • 0 Likes

Resolved! Licensing scheme

Hi All,Does anyone know the licensing scheme of PAN? Any document for based license? What will happen if they don't renew any of the license? will the box still works with outdated signatures? Hope you could share any document about the licensing rules. thanks.Regards,eUGeNe

TSPI by L1 Bithead
  • 2467 Views
  • 1 replies
  • 0 Likes

LifeSize

Anybody by chance have a signature for LifeSize? I added it to the applications list with just the ports used and generic categories but without a signature but it doesn't seem to be working. I thought before I dug into making my own signature I would find out if anybody has one already before I re-invent the wheel.Thanks!

Resolved! not-resolved URL catagories

Hello all,Last week I did the upgrade on my PA 2020 box from 4.18 to the latest 5.0.1 version. Today is the first day that most of the staff are back in and I have noticed that a lot of people are requesting websites to be unblocked. Having looked at the logs these URL's that are being blocked are showing as URL category not-resolved. This is ca...

JRussell by L3 Networker
  • 17764 Views
  • 8 replies
  • 0 Likes

How to tune wildfire rules

I am on a PA2050 using 4.1.12 in Device/Setup/Wildfire I have Wildfire enabled. In Objects / Security Profiles / File Blocking I have rules that "ALERT" and "FORWARD" on certain file types.My rule base for USERS connecting to the INTERNET consists of rules that allow certain AD groups access to certain PROFILES. These profiles include data fi...

EdwinD by L3 Networker
  • 6308 Views
  • 3 replies
  • 0 Likes

Resolved! missing block-url response page

Hi all,I have a very common security rule permitting all traffic in for 80, 8080 and 443 ports, no matter the applicationThe attached URL security profile denies all url categories except for one (custom).Now I've noticed not to be able to get the expected block page each time a try to access a web site, specifically I can obtain the response pa...

Resolved! Connection Problem with Polycom VSX7000

Hello All,I am having issues with video conferencing when using our Polycom VSX7000 which was working fine previously with our Checkpoint Firewall. When we switch over to PA-2020. We start having issues.We are able to dial out to connect with remote VC unit but when the remote VC units tried to connect to us, the VSX7000 shows connected but ther...

mmxong by Not applicable
  • 9058 Views
  • 8 replies
  • 1 Likes

Security Policy Organization

Anyone have any good tricks to organizing an ever-growing list of security policies? We have quite a few especially with inspecting internal to internal traffic. The firewall uses a top down approach to inspection, so I wanted to see if there was a way to insert a break or notation marker to keep things a little more organized. Was going to j...

gheimer by L0 Member
  • 7054 Views
  • 5 replies
  • 1 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels