General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Virtual-wire active/passive HA issue

Hello!We are testing out a topology in the lab, with 2 PA-2020 in an active/passive HA cluster. They are between 2 pairs of Cisco switches and should play a role of redundant in-line firewalls. The connection to the switches is with FO modules on ports e1/13 and e1/14 (these ports are in a monitor group).What we have noticed is some strange beha...

cannot block hotspot shield

HIit seems it has became vey diffcult to block hotspot shield , even though the application is being idenfied by palo alto , still hot spot finds it way by port 80 . is there any way to block hot spot shield.Also From IPAD/IPHONE it is easily connectingThanksShabeer

shabeerc by L2 Linker
  • 8446 Views
  • 7 replies
  • 0 Likes

Resolved! User-ID agent , custom agent sequence or agent priority.

Hello,I know PANOS-5.0 provide custom agent sequence function.Does PANOS-4.1 have same function such as custom agent sequence or agent priority???I use two User-ID agent.Does Palo Alto Device receive ip-user mapping information from all(two) agents or one agent?????If it receive information from one agent, how way do I check device receive what...

Globalprotect and Lenovo/Stoneware's Lanschool

Good morning, all!For the past several months, we've had an ongoing issue with our student's take-home 1:1 netbooks. Once they attach to the globalprotect portal/gateway, they won't work with LanSchool any longer.First, the environment background:PA-2050 running 4.1.9, GP 1.1.4. GP is configured to recognize internal to the network, and does w...

bau55536 by L0 Member
  • 3289 Views
  • 2 replies
  • 0 Likes

PanAgent support

After upgrading to Panos 5 from panos 4.0.11 ; Can we use panagent or should we use user-id agent ?panagent version 3.1.2

Resolved! Block users

Is there a way to block Guest users using their personal device with the virus or malicious software on it from accessing our network and notify them immediately using response or some sort of redirect page to contact support. Can PAN do this? If so how

wesa by Not applicable
  • 2913 Views
  • 2 replies
  • 0 Likes

5.0.3 - Panorama Hanging on Commit

Has anyone else, with a 5.0.3 install, seen Panorama hang - requiring a hard (in the VM sense!) reset?Twice within 48 hours of upgrading to this version have I had Panorama freeze totally when commiting. First time was a local commit (saving a policy change) - GUI froze, SSH console hung after accepting credentials.Second time was when pushing a...

apackard by L4 Transporter
  • 4027 Views
  • 5 replies
  • 0 Likes

What are recommended storage retention thresholds for URL Filter logs to achieve custom detailed date range reporting?

What are recommended storage retention thresholds for URL Filter logs to achieve custom detailed date range reporting?Depending on the hardware and disk sizes e.g PAN-5020, what are recommended URL Filter logs retention durations.Most often we'd get requests for 90 day custom date range reports.Also, what is the groups experience with sending lo...

Resolved! PanVPN agent

Hello admins.I read in documentiotion that there is VPN client software for Palo Alto devices.I wanted to try it out, but my licence expired and I can`t access to software page (if there is one).I would like to know if system supports "client VPNs" (and not only "server VPNs").Thx

Internet load balancing

Hi i have 5 internet connections (two dedicated links with different ISPs and 3 shared links with one ISP) , I need to configure the 5 untrust zones for internet and one for trust how i can configure the VR and how i can i use PBF per group of users. and create a backup link in case the first internet link goes down.Regards,

Resolved! Deploying LSVPN ( Large Scale VPN) with NAT !!!

I'm newcomer with Palo Alto. I have project to deploy PA using LSVPN . But there is a problem because The Internet Link from ISP & MPLS must Via Router Cisco.But I wonder , when using Router at Border , that means you must NAT Public IP to Private IP of PA. So when deploy LSVPN, Traffic is encryped , that mean Router cann't NAT . So how to s...

MinhTuan by L0 Member
  • 6157 Views
  • 5 replies
  • 1 Likes

Resolved! GlobalProtect certificates

In my company we have AD and our internal CA. I want to use our internal CA for GlobalProtect. What I have done so far: I've import our root CA to PA500 (PANOS 5.0.3). I've generated web server certificate and imported it in PA500 I've created GP gateway and portal.When I try to submit changes it says "invalid certificate chain".We h...

marjan by Not applicable
  • 3243 Views
  • 2 replies
  • 0 Likes

Monitoring and Blocking eMail

Hello,I want to know how I can do the following questions:1.- How can I block in gmail application the access to all the mails like this [email protected], but allow the access to emalis like this [email protected] that also are associated with Gmail.2.- How to monitor the users who access to public mails and know what are the access account and the d...

Angel by Not applicable
  • 2382 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect Usage Report

I have created a custom report to track all VPN users by subnet.. I parsed it to user and total bytes.. however, I can only get maximum 500 lines.. we have 1000 GP users, anyway around this?

rrau by L3 Networker
  • 2586 Views
  • 1 replies
  • 0 Likes

Resolved! FIPS mode IPSec cipher suite subset

When you enable FIPS mode on the firewall, what are the subsets of cipher suites available that the admin guide is referring to?Admin guide - "When configuring IPSec, a subset of the normally available cipher suites is available."

  • 24436 Posts
  • 125 Subscriptions
Top Solution Authors
Labels