General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Palo Alto drops current local login when using RDP

Hi!We are currently using a PA500 appliance using User ID Agent on Windows Server 2008 R2.My profile account (ex. super_user) is exempted to all which means I have no restrictions in accessing any websites.Apparently, when I RDP our servers I have to login as our admin account (ex. adm_user). After my activity on our servers, I closed RDP and go...

mapfre by L0 Member
  • 3056 Views
  • 2 replies
  • 0 Likes

Palo-Alto 500 replace bluecoat proxy server

Hi gues!LAN -> Bluecoat | Palo-Alto -> InternetIs any one have an experiance with raplace bluecoat proxy server with palo-alto.Is palo-alto can be proxy server for network?Please share your experiance.Thanks in advance.

Ulugbekyu by Not applicable
  • 6568 Views
  • 4 replies
  • 0 Likes

Resolved! When doing inbound SSL decrypt via a Palo Alto firewall, how are the private keys that you load into the FW protected?

I had this question come up from a security minded colleague at work, and it was a good question that I didn't know the answer to.In order to do SSL decryption for inbound SSL connections to servers that sit "behind" the Palo Alto, the procedure involves loading the SSL private keys onto the PA. Under "normal common sense security best practices...

Resolved! Security Profile Antivirus mail block

Hi,when you configure imap,smtp and pop3 block and in another profile alert;is the only difference between them is just sending back 541 response on block ? Or They are same (block or alert no difference)Thanks.

Resolved! Question on Anti-Spyware DNS signatures

Hi,as far as I understand Anti-Spyware profiles, the DNS options will find DNS lookups to known malware sites. How exactly does this work? Will the actual DNS lookup be blocked or will the client's access to the site be blocked?Quote from the documentation:Additionally, hosts that perform DNS queries for malware domains will appear in the botnet...

Resolved! SSL: Firewall uses untrust-forward cert. for every site

Hi,I just set up SSL Decryption exactly as described in the Getting Started Guide (English)I have one trusted-forward certificate, imported into browsers, and one untrust-orward certificate, not imported into browsers.Now when I connect to SSL sites, my browsers complain about untrusted certificates, the firewall is clearly using the untrust-for...

Google Drive (Web) slow to load

Anyone experience slowness loading Google Drive on the web? On my network when i launch the Google Drive webpage it takes several seconds to load the content, however, if i load the page off of my network the content loads nearly instantly. There are no other signs of slowness on my network. Is there something on the back end that my PA 2050 ...

mgonzalez by Not applicable
  • 4500 Views
  • 4 replies
  • 0 Likes

Dataplane PA2050 restart with no reasons. why?

Hi, i hope someone can help me about this error.My primary (active) Palo Alto suddenly restarted yesterday with no reasons, thanks god HA worked and we are actually working with the secondary PA. I have checked the monitor system log and i cant find the reasons why my PA was restarted.I attached a screenshot with the monitor system log. Thanks ...

BBC iPlayer

Hi there,I have a PA5050 running 5.0.4 that I'm in the process of configuring (replacing an ASA). I'm new to PANOS but so far so good!The requirement is simple, allow access to BBC iPlayer (App-ID exists) but not general web browsing. My first step was allowing the 'app' iPlayer but this requires web-browsing. So I created a custom URL category ...

SteveG by Not applicable
  • 4029 Views
  • 2 replies
  • 0 Likes

PA send out '192.168.1.1' GARP when it boot up.

Hello Guys, When PA boot up , it send out 192.168.1.1 GARP through the MGMT port no matter what you set the MGMT IP.And after 30 second later, it send out its MGMT ip address you set with GARP.I know that '192.168.1.1' is the factory default setting for the PA. But I think this mechanism can spoil the customers network if they use 192.168.1.1 fo...

JTR by Not applicable
  • 2903 Views
  • 2 replies
  • 0 Likes

Cisco - trunk- PA - trunk - Juniper SRX

Cisco - trunk- PA - trunk - Juniper SRXPlease help to configure PA-2050 for trunk ports between cisco and juniper.Which type of interface I should to use for this config.We can not use VirtualWire interfes, because from one side one port is connected to Cisco and for Juniper we have two ports. (Juniper Cluster)Thanks in advance.Bek.

Ulugbekyu by Not applicable
  • 4556 Views
  • 5 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels