General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4142 Views
  • 0 replies
  • 0 Likes

LifeSize

Anybody by chance have a signature for LifeSize? I added it to the applications list with just the ports used and generic categories but without a signature but it doesn't seem to be working. I thought before I dug into making my own signature I would find out if anybody has one already before I re-invent the wheel.Thanks!

Resolved! not-resolved URL catagories

Hello all,Last week I did the upgrade on my PA 2020 box from 4.18 to the latest 5.0.1 version. Today is the first day that most of the staff are back in and I have noticed that a lot of people are requesting websites to be unblocked. Having looked at the logs these URL's that are being blocked are showing as URL category not-resolved. This is ca...

JRussell by L3 Networker
  • 17823 Views
  • 8 replies
  • 0 Likes

How to tune wildfire rules

I am on a PA2050 using 4.1.12 in Device/Setup/Wildfire I have Wildfire enabled. In Objects / Security Profiles / File Blocking I have rules that "ALERT" and "FORWARD" on certain file types.My rule base for USERS connecting to the INTERNET consists of rules that allow certain AD groups access to certain PROFILES. These profiles include data fi...

EdwinD by L3 Networker
  • 6320 Views
  • 3 replies
  • 0 Likes

Resolved! missing block-url response page

Hi all,I have a very common security rule permitting all traffic in for 80, 8080 and 443 ports, no matter the applicationThe attached URL security profile denies all url categories except for one (custom).Now I've noticed not to be able to get the expected block page each time a try to access a web site, specifically I can obtain the response pa...

Resolved! Connection Problem with Polycom VSX7000

Hello All,I am having issues with video conferencing when using our Polycom VSX7000 which was working fine previously with our Checkpoint Firewall. When we switch over to PA-2020. We start having issues.We are able to dial out to connect with remote VC unit but when the remote VC units tried to connect to us, the VSX7000 shows connected but ther...

mmxong by Not applicable
  • 9105 Views
  • 8 replies
  • 1 Likes

Security Policy Organization

Anyone have any good tricks to organizing an ever-growing list of security policies? We have quite a few especially with inspecting internal to internal traffic. The firewall uses a top down approach to inspection, so I wanted to see if there was a way to insert a break or notation marker to keep things a little more organized. Was going to j...

gheimer by L0 Member
  • 7089 Views
  • 5 replies
  • 1 Likes

Resolved! differentiate between IE and FF

Hi,is it and when how is it possible to make a difference between a source which is using IE (company-standard) or firefox. I want to deny firefox-traffic.We use v5.0.3Cheers Klaus

kdd by L4 Transporter
  • 3249 Views
  • 2 replies
  • 0 Likes

SSL Sites bypass URL Category block

Good Day Guys and GalsI need ideas on the following issue please! I have a block on all Social networking sites for the company. The Policy works great when the user tries to access http://plus.google.com, but when they use SSL (https://plus.google.com) the user gains full access to the site. Same goes for all other Social networking sites! How ...

u7285 by Not applicable
  • 12063 Views
  • 13 replies
  • 0 Likes

Resolved! Multiple IP addresses on an interface

I know that I can add a second IP to my outside interface by using a /32 instead of /24 like the first one has. My question comes in with routing. My default route shows a 0.0.0.0/0 going out ethernet1/1. Since this interface has 2 IPs what IP does it use for the routing? Will it use the one with a /24 or /32.

nthen by L3 Networker
  • 4859 Views
  • 3 replies
  • 0 Likes

Unable to assign Security Policy to Users or Groups

Hi -We are using User-ID Agents to create user-to-IP mappings and I've got group mapping configured on the firewall itself and I can browse through my ldap groups. However, when I go to Policies > Security Policy I am unable to select either individual users OR groups to assign the policy to... Nothing populates. Am I missing something some...

Looking for advice on App-id configuration

Looking through the white papers and documentation, I didn't really find much as to a recommendation on how to tackle the task of app-id configuration as a whole. Have any of you found any documentation that was helpful in this area? One approach I was considering was running a report to identify the most widely used applications within our orga...

Resolved! What does it change in 'service route configuration' that Use kerberos for Global Protect??

Hello all,I use kerberos auth for Global Protect on PANOS-4.1.x.Remote users fail auth for GP connection that it appear 'invalid username'.So I want to collect PCAP on kerberos server and PA device.I know that PA use mgmt interface for communicated kerberos.I want to change interface from mgmt for collected PCAP.What does it change in 'service r...

Route checking using CLI issue ?

Hello,We are using PA3020 in L3 A/P cluster mode. PanOS is release 5.0.2.We are using static routes to reach our different subnets.When trying to check a route destination to verify the path using the CLI, nothing is shown as there was no route for this particular destination :TSadmin@PA-3020_M(active)> show routing route destination 10.198....

ldormond by L3 Networker
  • 5481 Views
  • 3 replies
  • 0 Likes

Current situation with Dropbox?

Hi,what is the current "state" with PAN firewalls when it comes to decrypting Dropbox traffic? I found a lot of threads on the forum, some with contradicting information. It was said that Dropbox was put on an internal ssl-exclude list so the firewall wouldn't decrypt it, in a later post it was said it has been removed from the list again. Gener...

Resolved! Packet Capture stopped working

Hi,the last days I did some captures on a PA-2020. At Yesterday I tried again but it doesn't work anymore. Tried via WebGUI and CLI. If I start the capture it is shown running but no files are created. PAN-OS is 4.1.12.Does anybody know this issue? Can it get fixed without restarting dataplane or device?ThanksJörg

JoergK by L2 Linker
  • 14141 Views
  • 9 replies
  • 1 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels