General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4463 Views
  • 0 replies
  • 0 Likes

Resolved! differentiate between IE and FF

Hi,is it and when how is it possible to make a difference between a source which is using IE (company-standard) or firefox. I want to deny firefox-traffic.We use v5.0.3Cheers Klaus

kdd by L4 Transporter
  • 3307 Views
  • 2 replies
  • 0 Likes

SSL Sites bypass URL Category block

Good Day Guys and GalsI need ideas on the following issue please! I have a block on all Social networking sites for the company. The Policy works great when the user tries to access http://plus.google.com, but when they use SSL (https://plus.google.com) the user gains full access to the site. Same goes for all other Social networking sites! How ...

u7285 by Not applicable
  • 12564 Views
  • 13 replies
  • 0 Likes

Resolved! Multiple IP addresses on an interface

I know that I can add a second IP to my outside interface by using a /32 instead of /24 like the first one has. My question comes in with routing. My default route shows a 0.0.0.0/0 going out ethernet1/1. Since this interface has 2 IPs what IP does it use for the routing? Will it use the one with a /24 or /32.

nthen by L3 Networker
  • 4950 Views
  • 3 replies
  • 0 Likes

Unable to assign Security Policy to Users or Groups

Hi -We are using User-ID Agents to create user-to-IP mappings and I've got group mapping configured on the firewall itself and I can browse through my ldap groups. However, when I go to Policies > Security Policy I am unable to select either individual users OR groups to assign the policy to... Nothing populates. Am I missing something some...

Looking for advice on App-id configuration

Looking through the white papers and documentation, I didn't really find much as to a recommendation on how to tackle the task of app-id configuration as a whole. Have any of you found any documentation that was helpful in this area? One approach I was considering was running a report to identify the most widely used applications within our orga...

Resolved! What does it change in 'service route configuration' that Use kerberos for Global Protect??

Hello all,I use kerberos auth for Global Protect on PANOS-4.1.x.Remote users fail auth for GP connection that it appear 'invalid username'.So I want to collect PCAP on kerberos server and PA device.I know that PA use mgmt interface for communicated kerberos.I want to change interface from mgmt for collected PCAP.What does it change in 'service r...

Route checking using CLI issue ?

Hello,We are using PA3020 in L3 A/P cluster mode. PanOS is release 5.0.2.We are using static routes to reach our different subnets.When trying to check a route destination to verify the path using the CLI, nothing is shown as there was no route for this particular destination :TSadmin@PA-3020_M(active)> show routing route destination 10.198....

ldormond by L3 Networker
  • 5634 Views
  • 3 replies
  • 0 Likes

Current situation with Dropbox?

Hi,what is the current "state" with PAN firewalls when it comes to decrypting Dropbox traffic? I found a lot of threads on the forum, some with contradicting information. It was said that Dropbox was put on an internal ssl-exclude list so the firewall wouldn't decrypt it, in a later post it was said it has been removed from the list again. Gener...

Resolved! Packet Capture stopped working

Hi,the last days I did some captures on a PA-2020. At Yesterday I tried again but it doesn't work anymore. Tried via WebGUI and CLI. If I start the capture it is shown running but no files are created. PAN-OS is 4.1.12.Does anybody know this issue? Can it get fixed without restarting dataplane or device?ThanksJörg

JoergK by L2 Linker
  • 14526 Views
  • 9 replies
  • 1 Likes

Resolved! RADIUS and CISCO ACS v5.1

Hello!Is it possible to configure the PA to read the RADIUS logs in Cisco ACS v5.1? Can the PA map users which have authenticated to a RADIUS server, the external DB being AD?

Resolved! Palo Alto drops current local login when using RDP

Hi!We are currently using a PA500 appliance using User ID Agent on Windows Server 2008 R2.My profile account (ex. super_user) is exempted to all which means I have no restrictions in accessing any websites.Apparently, when I RDP our servers I have to login as our admin account (ex. adm_user). After my activity on our servers, I closed RDP and go...

mapfre by L0 Member
  • 2980 Views
  • 2 replies
  • 0 Likes

Palo-Alto 500 replace bluecoat proxy server

Hi gues!LAN -> Bluecoat | Palo-Alto -> InternetIs any one have an experiance with raplace bluecoat proxy server with palo-alto.Is palo-alto can be proxy server for network?Please share your experiance.Thanks in advance.

Ulugbekyu by Not applicable
  • 6317 Views
  • 4 replies
  • 0 Likes

Resolved! When doing inbound SSL decrypt via a Palo Alto firewall, how are the private keys that you load into the FW protected?

I had this question come up from a security minded colleague at work, and it was a good question that I didn't know the answer to.In order to do SSL decryption for inbound SSL connections to servers that sit "behind" the Palo Alto, the procedure involves loading the SSL private keys onto the PA. Under "normal common sense security best practices...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels