General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4137 Views
  • 0 replies
  • 0 Likes

One way traffic over IPSEC tunnel

Hi All,Just having an issue with a newly created IPSEC tunnel on a new PA-500. I have tried 4 different devices at the remote end with the same results, so I'm really thinking my problem is due to mis-configuration at the PA-500 end.The tunnel comes up fine every time (Green lights), but I can only ever achieve traffic flow from Site B (remote...

Dual ISP's - How to PA-500

Does anyone know of any good documentation that explains how to set up dual ISP's into my PA-500 device? I currently have a single T1 running into the PA-500, but am going to be adding a cable connection within the next couple weeks. I would like to use the Cable Connection for all Internet surfing, and the T-1 for E-mail and such. Can this be...

kaysun by L1 Bithead
  • 11089 Views
  • 16 replies
  • 0 Likes

bandwidth use

I can see the live-time bandwidth by using the CLI:Show system statistics sessionBut that only shows the real time download bandwidth – it doesn't show our upload bandwidth. Is there a command to use to see this traffic instead or combined with our download bandwidth?I'd just like to see a real time readout of our bandwidth use inbound and outbound

wesa by Not applicable
  • 3131 Views
  • 1 replies
  • 1 Likes

How to apply Data Filtering effectively

It seems obvious to me that you can't simply apply the built in CC and SS filters in a Security Profile with an "any any". In my testing it really fouls up general web surfing.Why is there no detailed documentation (at least any I can find in KnowledgePoint or elsewhere) about how to craft an effective data filtering profile. Should it be applie...

CWillms by L2 Linker
  • 14680 Views
  • 9 replies
  • 0 Likes

Resolved! Websites with just text

I recently turned on URL Filtering and now some sites are coming up with just text. CNN for example, has bullet points on the left next to titles that I can click on, the header is a small square with what looks like a jpeg avatar in the middle.No graphics at all......Any help would be appreciated!TIA

Resolved! VPN client-to-site

Hi!I wonder if anyone managed to configure the IPsec VPN with AD authentication.Note: No license Global protect.At.,

Bismarck by L1 Bithead
  • 4162 Views
  • 5 replies
  • 0 Likes

How to force generating a daily pdf report?

Is it possible to force generating a daily pdf report? I am working on fine tuning reports to be send out on a daily bases, but I really don't want to wait 24 hours to wait for the result. Is there a way to force sending our the daily reports? There is a button to send a test email, but that only sends a plain text email. (Please see attached sc...

bbsoc by L2 Linker
  • 4333 Views
  • 4 replies
  • 0 Likes

Resolved! How do I reset a PA activated address block action?

Since you are able to Block the source and/or destination IP address as an action taken in a protection rule (IPS, Spyware, Zone protection etc...) is there a way to reset the timer before the elapsed time has been reached. If you block for 3600 seconds and find out 5 minutes after the event took place that it is a false alarm do you have the a...

HITSSEC by L4 Transporter
  • 2402 Views
  • 2 replies
  • 0 Likes

VPN tunnel config question

I'm running PANOS 4.0.13. Can I set up a tunnel where the peer IP is 1.1.1.1 and the remote proxy id is the same IP as the peer? I think I tried this before on an earlier release and it didn't work, so I had to NAT. Thanks!

iguarino by L0 Member
  • 2502 Views
  • 2 replies
  • 0 Likes

OCSP query

Hi,We are implementing a SSL-VPN solution using Global Protect and our own CA. From what I have seen the OCSP queries are made on demand, when the certificate is presented for the first time, and then at a fixed interval(60 minutes). I tried changing the interval using the "debug sslmgr set ocsp-next-update-time" but did not have any effect on t...

  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels