General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Third Party VPN Clients

There is an option for 3rd party VPN clients in the interface and there used to be articles on Cisco Anyconnect as an option for 3.1. We have tested this without the use of these parameters, how do these adjust the communication to the firewall, is there any documentation on supported version for this component of the GlobalProtect configuratio...

amansour by L4 Transporter
  • 4708 Views
  • 3 replies
  • 0 Likes

Resolved! Reason for VSYS

Has anyone found a situation where VSYS is ever truly the best course of action when deploying the firewalls. I have been continually asked about this feature with very little cause to deploy the firewall in this way in most situations. Can anyone share examples where this could not be avoided or advantages it provides other than segmentation o...

amansour by L4 Transporter
  • 5492 Views
  • 6 replies
  • 0 Likes

Resolved! ThreatID and CVE

Hi Out there. For users of SIEM, some have Vulnerability scanners, anti-virus and other tools reporting CVE through syslog. In most cases the logs from PAN have threatID, other than the special Splunk integration does anyone know of a way to get the annotatations/descriptions into the log and/or publish the CVE against it, I do see it referenc...

amansour by L4 Transporter
  • 3388 Views
  • 1 replies
  • 0 Likes

How did your SSL Decryption deployment go?

We are in the process of making a case to deploy SSL Decryption. While I am sure this will happen, predeployment, I would like to hear any horror stories or even success stories on how your deployment went. Also any do's and dont's would be fantastic. Currently our environment is 4.1.7-h2 if that is a factor in your deployment stories, that much...

Application web-browsing blocked using ssl decryption

I've defined a simple rule for acces to a ssl-crypted website using application filtering.Also all ssl-crypted access to that site will be decrypted.The running Software ist PanOS 5.02.When I define a rule for access to that destination and leave the service in "application-default"The access wil be blocked an I get two entries in my LOG-File:1....

Sizing an appliance

I commented on threads outside the knowledgebase on sizing an appliance. I thought I would start the discussion here as well. Usually we run the tap mode install to get the stats and found all the counters relevant to sizing the sessions etc by SPAN or Mirror of the main egress. Datacenter is harder because you usually can't do that.

amansour by L4 Transporter
  • 2121 Views
  • 1 replies
  • 0 Likes

PANOS 4.1 vs 5.0

Which version PANOS is better 4.1 or 5.0I have installed 4.1.8 on PA-500, should i upgrade to 5.0.2?

Server error : op command for client dagger timed out

Hi,Recently when performing a show session all I recieved a response:Server error : opcommand for client dagger timed outAfter a few minutes this resolved itself. This was on code 4.1.10. Could this be related to a memory leak and the system didnt have enough resource to my request? Rgds,Gordon

gaitken by L0 Member
  • 17654 Views
  • 3 replies
  • 0 Likes

I want my telnet back!

Don't get me wrong, I really like PAN-OS 5, but why did they take my favorite troubleshooting tool away?The PA is the new device in our environment and if anything is not working all blame on the 'new guy'. User claims: 'since we have the new firewall I can't get to webpage xyz anymore' Admin: A quick telnet from the PA to xyz on port 80 is tim...

panwmod by L0 Member
  • 18330 Views
  • 23 replies
  • 3 Likes

File zeroization error: No such file or directory

Does anyone know what this means? I've never seen this before, but I got a bunch of these errors after committing a change on my passive device. I changed the network interface settings and I just recently upgraded to 4.0.13 from 4.0.11.

iguarino by L0 Member
  • 3091 Views
  • 2 replies
  • 0 Likes

Resolved! NAT Pool Usage

Hi,Is there a way to determine the usage levels of NAT pools over a time period. I believe we are running out of addresses in some of our pools and I would like to check what the usage levels are in of pools to see where I have flexibility for changes. Thanks

parkerbc by Not applicable
  • 9223 Views
  • 4 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels