General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4441 Views
  • 0 replies
  • 0 Likes

Application Dependency PAN-OS 5.0.0 more

Hi~Since more PAN OS 5.0.0 has upgraded application dependencyand then I added one rule from securityI would like to allow to only gmail-baseand then Click commitI expected sucesse result,,but Popup window represented warning message;;what -_-;;I knew that PAN-OS support Application Dependency about http, ssl, somethig like thatI red PAN OS 5.0....

2050 only handles 1/4 of its advertised throughput

Has anyone here tried to benchmark there Palo Alto Firewalls? We are using Breaking Point(same company that Palo Alto uses)to test our Lab 2050's. We have come to the conclusion that the PA 2050 starts dropping packets at about 250Mbps(with about 5-600 new sessions per second). This is with Threat Prevention disabled. The 2050 is spec'd out t...

jambulo by L4 Transporter
  • 8430 Views
  • 11 replies
  • 0 Likes

Resolved! unknown-tcp / udp - please explain

Hi,I know that these two applications stand for unrecognized traffic. It worries me though that for some of the other applications to work, I have to add unknown-tcp/udp to the firewall rule. Example for this would be Bittorrent traffic. To allow Bittorrent, I also have to allow web-browsing and unknown-tcp and unknown-udp.Can someone please ela...

Resolved! SCP Config backup "No DSA host key"

Hello,After upgrading both firewalls and the panorama to version 5.0.4, I want to change the configuration backup in Panorama.I want to change it from FTP to SCP.I am using the tool WinSCP on an windows machine. In this tool i've created an account called "Panorama" with a password.At this account I also mapped an ssh host key.But a test at the ...

ppater by Not applicable
  • 4534 Views
  • 2 replies
  • 0 Likes

New Feature Request

I don't know if this would be classified as a new feature, but it would be nice if on the policies/security if there was a separation of the inbound rules and the outbound rules. Right now these rules are all thrown in the same view.

snormoyle by Not applicable
  • 4964 Views
  • 7 replies
  • 0 Likes

Resolved! Nat with loopback int ip

HI all,Could we do the nat with loopback ip?I facing a scenarios my customers wish to set their public ip at loopback ip. Internal ip will nat to the loopback ip and send to cloud with external interface.

afiq by L1 Bithead
  • 7154 Views
  • 1 replies
  • 0 Likes

Resolved! MIB for 5.0 PAN

HelloI'm trying to monitir traffic on my PA 200. I found tech doc There is stated that I need MIB file for my PAN. I'm using 5.0.3 and there isn't anyt 5.0 MIBs.Where I can find it?I found also but maybe someone can share their config file? it could save many time to me and others.RegardsSLawek

_slv_ by L4 Transporter
  • 3019 Views
  • 2 replies
  • 0 Likes

Captive Portal - users not supplying domain info

Our captive portal is configured to use RADIUS (Cisco Secure ACS) to authenticate our AD users. The Cisco ACS will authenticate a user even if they do not include their domain information in the userid string... 'userid' rather than 'domain\userid'. The problem with this is that a user who authenticates with only their userid ends up with a ip-...

Jeff_K by L2 Linker
  • 3939 Views
  • 3 replies
  • 0 Likes

Resolved! 5060s SFP ports

Hello,I have one 5060s and I would like to know what types of fibre can support. Unfortunately I couldn't find any info in the hardware doc. Can support LX or SX fibres?Many thnaks,Thomas

BOOMMAX by Not applicable
  • 3877 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect 3G issue on Windows 8 pro tablet

Hi,we installed GP 1.2.1 on a Windows 8 32 bit pro tablet (thinkpad 2). With WiFi it works perfectly but when we use 3G, we can't even open the Portal website in the Internet Explorer and the GP client can't connect. I thought it could be a problem with the certificate but then it would not work with WiFi?

sboelter by L1 Bithead
  • 5900 Views
  • 5 replies
  • 0 Likes

Virtual Routers

Hi,I have the WAN it's vlan 9 with the IP x.x.9.1 and I have to give access to vlan 6 which is the part of users, the Palo Alto must make the routing, vlan 6 has the IP's: x.x.6.0/24, x.x.109.0/24, which should go out x.x.6.254.How can I do routing with the virtual routers?Thanks.Regards.

Angel by Not applicable
  • 2141 Views
  • 1 replies
  • 0 Likes

Resolved! Dynamic Updates using an Interface with dynamic IP address

Hi,I would like to know how to configure the Palo Alto Updates in Service Route Configuration using an interface with dynamic ip address?When I´m using dynamic ip the interface doesn´t appear in Device -> Setup -> Services -> Service Route Configuration.Thank you and regards,

rrunge by Not applicable
  • 3686 Views
  • 1 replies
  • 2 Likes

Resolved! AD group for administratoin using authentication through LDAP

I'm trying to authenticate an AD group for administrative access for our PA. I'm missing the last step to implement it and I may have some of the steps messed up. could someone fill in the blanks for me?Create an LDAP profileCreate an authentication profile???Sorry if this question has been covered before.Thanks

What am I doing wrong? This policy to block unknown traffic to countries outside the US.

Hi all!I have a new policy that I pushed yesterday that was a total failure and any help you can offer would be appreciated.We have a policy that looks like this:Source <Internal IP addresses>Destination <Negate Region US>Application <unknown-tcp, unknown-udp>DENYHowever, it is catching and DENYing all unknown-tcp and unknown-u...

  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels