General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Why is Group Mapping Different in M-100?

Hi,

I'm about to deploy two PA-5060s in HA, and I am configuring everything from Panorama. When it comes to the Group Mapping on Panorama, the UI is different than it is on the firewalls.

On Panorama:

On the firewall:

Any input is appreciated.

Thanks,

Alex

Abs by L3 Networker
  • 3088 Views
  • 5 replies
  • 1 Likes

Resolved! TCP Flood ID: 8501

On our user TAP interface (a TAP that collects user trafic only), we see 1000's of TCP flood events from 0.0.0.0 to 0.0.0.0 ; port 0 to port 0; Zone user to Zone user. It is always Session ID of 0. I have tried to do packet captures, but I never seem

...

craymond by L4 Transporter
  • 11766 Views
  • 4 replies
  • 0 Likes

Multiple external IP's and Global protect (Not NAT)

Hi

I did a search on the forums for multiple IP's and found a lot of posts talking about how the Palo deals with multiple external IP's - i.e. if your ISP assigns you a /29 block and you need to NAT multiple application into your network. So basically

...

Quinton by L3 Networker
  • 8084 Views
  • 7 replies
  • 0 Likes

Resolved! Public IP not accessible from internal addresses.

Hey All;  When setting up GP and other external interfaces for access I found that any NAT inbound is not accessible when in the local network as well, only from outside. 

Can anyone explain if there is a NAT or GP gateway setting that will take inte

...

amansour by L4 Transporter
  • 2712 Views
  • 3 replies
  • 0 Likes

Resolved! Set VM-100 as gateway on host.

So I am wondering if there is any way to use the VMWare workstation (I know the VM-100 is for ESXi) as the gateway on your host and if anyone has had success with just monitoring EAST-WEST traffic from the VM-100 on ESXi?

amansour by L4 Transporter
  • 1603 Views
  • 1 replies
  • 0 Likes

Microsoft X-Auth RSA

Wanted to know if there was a native way to connect windows clients using IPSec directly to PAN.  So far L2TP is not supported by PANOS and X-Auth RSA is not supported by Microsoft. Using PKI it would be great to get this for ARM based microsoft tabl

...

amansour by L4 Transporter
  • 1174 Views
  • 0 replies
  • 0 Likes

Cisco IPSec Client

Hi All;  there was a document when netconnect was around about using the cisco anyconnect client for IPSec VPN connections. 

Can someone let me know if there's an update to this. 

amansour by L4 Transporter
  • 1369 Views
  • 0 replies
  • 0 Likes

Resolved! ZeroAccess.Gen

Our threat monitor shows a lot of ZeroAccess.Gen Command and Control traffic, type spyware.  The default threat action is to alert.  I want to either block or drop.  What is the best way to block traffic for a specific threat signature but to use def

...

oshcomp by Not applicable
  • 5185 Views
  • 4 replies
  • 0 Likes

Netflow

Can a PA500 support netflow version 5 - I know it does v9 - but my collector needs v5.  Thanks.

RCBTech by Not applicable
  • 2201 Views
  • 1 replies
  • 0 Likes

Resolved! How to find application in Palo Alto (by tcp/udp ports)

Dears,

I am working on a migration from Check Point to Palo Alto. We used that PA Migration Tool for CP rules into PA.

The main problem is all CP rules are based on services and we want to transform them into PA applications... BUT, the PA apps tool (a

...

Multi-factor Authentication

Does the PAN Netconnect client or browser initiated VPN connection support multi-factor authentication? I know that you support AD and Radius but can it be done at the same time. I only see a Password field in the logins and cannot see how one can ch

...

kime by L0 Member
  • 7287 Views
  • 15 replies
  • 0 Likes

Resolved! services (http,https)

Please excuse my ignorance, new to FW support and PAN.  What is the criteria for services, why is there only 2 http/https?

thx,

User identification (AD)

Dears,

We have PA2020 implemented (w/ HA) and sometimes the user identification doesn't work well.

In the picture below we can see the following scenario

1st line - PA2020 doesn’t relates my IP w/ my user and I got blocked accessing youtube.com (rule “B

...

Resolved! Allowing Skype through the PA

We have a business group that wants to use Skype. I am very concerned about allowing unknown-udp or unknown-tcp ports out through our PA. Has anyone allowed Skype through their PA and if so, can you offer any suggestions as to how to do it securely?

  • 24194 Posts
  • 100 Subscriptions
Labels