General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

4.1.12 early adopters...

Am I the only one who is adopting a "once bitten, twice shy" approach when it comes to 4.1.12?The release notes claim that PAN have fixed the bugs I've been bitten by - the userID process problem, the App Override killing TCP sessions after 10 seconds and one other - but I'm wary of rushing out and just installing it.Has anyone run with 4.1.12 y...

darren_g by L4 Transporter
  • 5185 Views
  • 7 replies
  • 0 Likes

Resolved! Netconnect setup error message

HelloMy customer has installed 'NetConnect' on Window 7 32bits.It is failure with as below error message."Unable to extract installer Setup.msi Error: null"Why does it display??And How way does it resolve??Thanks

How is going when SSD failed with raid environment?

HelloI want to know how do PAN going on when SSD failed with raid environment. I guess PAN could keep to run normally without failover if one SSD failed on raid environment.1. Could PAN keep to run normally without any issue on raid 1 environment if one of SSD were failed?2. Would PAN be triggered to Failover on HA with raid 1 environment if one...

newenpa by Not applicable
  • 2143 Views
  • 1 replies
  • 0 Likes

Sophos Antivirus

Greetings,Was wondering if any one else has faced this problem.I have Sophos antivirus and when I create a rule with the vulnerability protection set to Strict, it blocks my connection to sophos server for updates. Once I relax the VP rule, it looks fine. Interestingly, I cannot see anything in the traffic/threat logs as well.Has anyone faced ...

Global Protect Portal Policy - Application Default breaks access

Hello,I have a Global Protect Portal setup which works properly with a policy set for the App-IDs of "SSL", "Web-Browsing" and "PANOS-Global-Protect" and "any" Service. If I set service to "Application-default" - the portal login page no longer displays. The logs then show that SSL (443) was "Allowed" and Web-Browsing (443) is "Deny". Is there...

MGoodnow by L4 Transporter
  • 3099 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC with Cisco ASA

Hello everyone. I'm hoping someone may be able to help me out with this. I am replacing Cisco ASAs with 5020s. I have a lab 3050 setup and I have an IPSEC VPN tunnel between the 3050 and the Cisco ASA. In my configuration, from the PA perspective, I have one local subnet and one remote subnet. I can pass traffic back and forth with no probl...

Instability of User ID Agent

Hi All, Trying to gather some hints/tips to provide some stability to our User Identification infrastructure. Currently we are running 2 x User ID Agents ( 4.1.6-5 ) on two Virtuals devices. After we upgrade 2 months back to this version we looked to have a stable setup but in the last 2 weeks we have to daily start the agents as they both s...

dpenhall by L2 Linker
  • 5356 Views
  • 5 replies
  • 0 Likes

Resolved! Cannot block site viooz.co

This is an illegal movie site that shows anything even stolen movies for free. The IP address is 5.199.170.104 I have tried blocking the site name, the ip. Nothing works. It's almost like the site is an anonymizer itself. I would love any help at all. I need to totally block this site from our network.I have redundant PA-500s.

Resolved! Commit Failing on 5.0.2

Hi,we have recently updated our our two PaloAlto 4050 from version 4.1.8 to version 5.0.2. Since after the update we face a lot of commit failing problems. and the device response becoming very slow. is it a known bug ? or is there any way around ?

omer by Not applicable
  • 6839 Views
  • 10 replies
  • 0 Likes

LACP LAG

Does anybody know how to setup LACP lag on PA 5000 ver 5.04. SInce I am configuring active passive configuration and I have two core switches. I want core 1 to be my primary link and my secondary core as my secondary link from single firewall. Thank you

knesan by Not applicable
  • 3415 Views
  • 2 replies
  • 2 Likes

Faild Starting Phase1

Hi Group I am really ready to pull the hair out of my head. 🙂For 3 months or so, I have had a VPN between my PA-200 to a PA-500 at my remote office. All was working fine.Last night I come back into the office to find the VPN down, and not sure why. I am looking at my PA-200 which has exact configuration.I can see via my pcaps that I am attempt...

scantwell by L4 Transporter
  • 2727 Views
  • 2 replies
  • 0 Likes

Variable for hostname on responsepage

Hi,I´m looking for a varible which resolves in the hostname of the responding Palo Alto. We are currently having an MPLS network with multiple subsidaries connect, each has it´s own lokal PA and one centrale internet breakout with a PA Cluster. I would like to include the name of the PA which "showed" the response page so in case of troubleshoot...

u18195 by Not applicable
  • 4249 Views
  • 3 replies
  • 0 Likes
  • 24430 Posts
  • 125 Subscriptions
Top Solution Authors
Labels