General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Authentication after blocked page

Dear All,If I have two groups of users, one with more restrictive access to the internet via URL Filtering than the other.If the more restrictive group access the internet and receive a block page as their policies do not allow access to that resource. I would like the possibility for a user that is in the less restrictive group to authenticatio...

JAG by L1 Bithead
  • 3043 Views
  • 3 replies
  • 0 Likes

SSL Decryption

Hi All, I have an issue with SSL decryption and using the inbuilt CA. What appears to happen is that various parts of SSL websites don't trust the CA on the palo alto and as a consequence sites do not load fully and report various certificate issues.This is what https facebook looks like:The corresponding browser complaints:I'm running the very ...

Resolved! Ubuntu and PA-200 DHCP

I'm having a problem with mostly Ubuntu users not being able to resolve DNS. I say mostly because there is at least one Windows user having the same problem. None of the Mac workstations are having the same problem and the majority of the Windows machines work as well.I have the PA-200 configured with DHCP on the trust interface all users are co...

Global Protect - How does patch matching work?

Can someone please detail how a HIP profile for missing patches works? I have tried every combination possible and I always get the same result.My Criteria is as follows:Patching is Enabled Yes is Installed CheckedSeverity - Greater than 2 (Which means 3 or Critical for Microsoft related patches)Check - Has NoneVendor - Microsoft Corp.My Gatewa...

allens by Not applicable
  • 2968 Views
  • 1 replies
  • 0 Likes

Antivirus DB not showing up on inactive HA node

Hi,I have a pair of PA-500 in an active/passive cluster. The Dashboard says that all content is matching between the nodes. However, if I go into Device->Dynamic Update on the secondary node, there is no Antivirus in there. I can only see it on the primary node. When I do a 'request anti-virus upgrade install' on the command line of the inact...

Resolved! Policy Based Forwarding - Enforce Symmetric Return

Hi,I am planning a firewall migration right now and trying to solve the problem that traffic comes in through two different interfaces during the migration (Internet through old firewall, Internet through new firewall). I was looking at policy based forwarding and stumbeled across the "e, nforce symmetric return" option, which unfortunately is n...

Port Forwarding Without NAT

So, I have a very interesting network. I have a media server that is on a separate VLAN. There is no way for me to statically configure the client(s) with a static IP (they just search for the server). It uses tcp/32400. Basically, my host will show as coming from a different zone than where my media server is. So, I need to forward any tcp...

Resolved! NAT exclude

Hi,is it possible to make exceptions/exclusions for a NAT rule? Think of this scenario:small PA-200 setuponly one external/public IP addressthat IP address is used for a lot of incoming NATthe NAT rule basically forwards everything from the external IP to an internal hostnow I also want to enable GlobalProtect and incoming VPN connections on the...

Best practice for demo PAN in Tap mode

Hi,I have to demo PAN in 3 Legs firewall compose Internet, DMZ and Internal zones. so I have some question regarding to this.1. What mode on mirror I should config on the firewall, TX or RX or TX and RX ?2. Should I configure virtual system for each tap interface and why?

Report creating Question

Hi,I'm quite new to PAN firewalls, and I find the ACC page to be very informative and can usually find all the info I need from there.However, I've just had the IT manager request (and omg hes not a happy camper at me) a report of the usage of our internet as we just received an email stating we had gone over our limit for the month, which is st...

Monitoring site-to-site IPsec tunnel bandwidth via SNMP?

Do the tunnel interfaces that get created as part of building a Site-to-Site IPSec tunnel show up via SNMP interface polling? That would be awesome if we could monitor tunnel bandwidth by walking the device and monitoring the ifInOctets and ifOutOctets for the tunnel interfaces themselves.

Resolved! User-ID Management Setting

In the device management settings there is now a "User-ID" checkbox. I have looked at the administrators guide but it doesn't mention it, presumably because it is fairly new.What does this actually control, because the user-id agent on the box works fine without that checked (or seems to). Other options such as SSH, ping etc are obviously mana...

djr by L4 Transporter
  • 4324 Views
  • 5 replies
  • 0 Likes

Global Protect Architecture

Guys ,Need some guidance here . One of our client with an MPLS network wants to build a GP network . They are looking at buying a portal for a PA 5050 and have GP gateway licenses for each local box . The issue is the local boxes wre on different networks . All the users will hit the portal and the portal will now send them to their local gatewa...

usvi by L3 Networker
  • 2921 Views
  • 3 replies
  • 0 Likes

Resolved! Debug Flow Basic in PAN-OS 5.0.4 (PA 2050)

I have been having problems with running Debug Flow Basic since upgrading from PAN-OS version 4.1.6 to 5.0.4.I am using the following commands to setup my debug:debug dataplane packet-diag set log feature flow basicdebug dataplane packet-diag set capture on(I have not applied a capture filter as this is our test PA so very little traffic being p...

debsPal0 by Not applicable
  • 3722 Views
  • 2 replies
  • 0 Likes

Resolved! I don't know how to set zone protection

Hi~I have a question,,We know that,,,Paloalto appliance is not primary dos soultionso one support some dos feature (TCP Flood, UDP Flood, ICMP 0 Packet someting like that etc,,)I had poc from customer siteI set zone protection between Tap Zone and Tap zonecustomer asked me;;why is palaalto do not represent about source ip and dst ip,,,also I don...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Labels