General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

Login failure notification

I am looking for a method to send a notification by email when authentication to the firewall management is attempted but fails. It would be acceptable to get an email for successful authentications as well. Overall I am looking for methods to help ensure someone isn't trying to gain unauthorized access and be notified when potential unauthori...

bogleric by Not applicable
  • 3953 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect Port 80 ,443 Incomplete

HiI'm Trying to set an enviorment to my mobile users (Laptops of Salesman), I used the Globalprotect to provide a secure tunnel to the office Firewall andthen gave the users access to terminal server, and it worked fine.last week we installed a new SharePoint Server, I need to give the users with laptops direct access to my SharePoint ServerI us...

ShayBar by L1 Bithead
  • 13329 Views
  • 11 replies
  • 0 Likes

Resolved! Cisco Guest Wireless - Issues?

Hi all,I recently installed a PAN 5050 cluster in-line between my internal Cisco Wireless Controllers and the DMZ guest access mobility controller and saw the control and data paths flap constantly. I put in an application override rule (along with a number of other measures not related to PAN) and the behaviour seemed to stop. Can anyone conf...

Packet Capture (VLAN)

How can i capture the packets for only one VLAN? I have a virtual Interface ethernet1/6.40 and if i use a filter for only the interface (ethernet1/6) the PA doesn't capture anything.

Data Filtering / URL Logs into Splunk

Hey Guys,I have the Palo Alto App working for the Threat/Traffic Logs.However, I would like to do the same for the Data Filtering / URL Logs.Is this possible?Let me know if it is and how to do it.Thanks.Brian

ikinnexi by Not applicable
  • 6991 Views
  • 3 replies
  • 1 Likes

Youtube video seen as http-audio application

Greetings,We have run into an issue in our deployment where SOME (really only a few) Youtube videos don't play, the user gets an error 'An error occurred, please try again later'. In the traffic logs, I see traffic that is recognized as application 'http-audio'. We have configured an application whitelist of the applications we allow from our ...

Resolved! Manage IDS signature through the Panorama

My environment has firewalls, which are being managed by the Panorama. Today I am not managing the rule sets of these firewalls from the Panorama, but I intend to do so in the near future.Is it possible to modify/create new IDS signatures and push it through the Panorama to all the firewalls??

Resolved! Logging IM

Greetings PA community. I have a question about leveraging our PA firewalls (pair of 5020's) to log instant messaging. We're a government agency and some of our employees use instant messaging for business purposes and we MUST log these chats as part of our public records policy. Everything they do with other government agencies over this cha...

josh_ward by Not applicable
  • 2769 Views
  • 1 replies
  • 0 Likes

High Availability with Virtual Wires?

Hi, I've been looking everywhere and I can only find information on virtual wires being used for path-monitoring in HA. What I'm looking for is if when in HA, do the virtual wires fail over? If they do fail over is there a best practices document detailing how and what type of interfaces fail over? Fail over of a L3 interface makes sense since t...

nugentec by L1 Bithead
  • 17822 Views
  • 9 replies
  • 0 Likes

HA path monitoring in virtual wire

I've seen a couple answers here about using Path Monitoring in Virtual Wire. They say that one must use an IP address within the Virtual Wire subnet as the source address. OK, I get that. What I don't get is how to configure such an address. I don't see a way to add an address to a vwire interface. I've tried creating a loopback with no good res...

gmparis by Not applicable
  • 19273 Views
  • 22 replies
  • 0 Likes

Resolved! licensing VPN clients

hi!I would need some help understanding the PAN licensing model fo VPN clients. we are planning a new deployment and would like to offer our clients (Windows and iOS based) the possibility to access corporate resources. since only a very basic functionality is needed in this case (the ability to establish a SSL/IPSec session and assign a remote ...

santonic by L6 Presenter
  • 5160 Views
  • 4 replies
  • 0 Likes

Resolved! Do I configure proxy-id in ipsec-vpn certainly?

Hello all,What is proxy-id in ipsec-vpn configuration??Why does it need??I will use ipsec-vpn on PA-2020 & PA-500.Each devices have 15 proxy-id(remote-networks).I know one tunnel interface has 10 proxy-ids.So I have tested without proxy-id that traffics are processed routing-table(next-hop tunnel interface) to 15 remote-networks.It is normal...

PA 5050 Admin Account Rename/Deletion

Hi AllI am using one PA 5050 firewall and all is working fine. Just want to know if I can rename or delete the Admin (Default) account in the box. This account is default account and is there any limitation if we delete it or rename it. If I delete it , is there anything which I will loose as far as the Administration of the box is concerned.Pl...

itsecll by L1 Bithead
  • 3770 Views
  • 2 replies
  • 1 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels