General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Issue with facebook pictures being blocked

Hey guys got one I am stuck on. We are not blocking facebook at the moment and it was working just fine until Friday afternoon. No config changes were made. No updates to the PA5050's we have. Facebook comes up still but certain pictures on it will not. Just the ones that are in the users albums seem to be having issues. Pictures in links still ...

JeffTQT by L2 Linker
  • 3398 Views
  • 1 replies
  • 0 Likes

Third Party VPN Clients

There is an option for 3rd party VPN clients in the interface and there used to be articles on Cisco Anyconnect as an option for 3.1. We have tested this without the use of these parameters, how do these adjust the communication to the firewall, is there any documentation on supported version for this component of the GlobalProtect configuratio...

amansour by L4 Transporter
  • 4735 Views
  • 3 replies
  • 0 Likes

Resolved! Reason for VSYS

Has anyone found a situation where VSYS is ever truly the best course of action when deploying the firewalls. I have been continually asked about this feature with very little cause to deploy the firewall in this way in most situations. Can anyone share examples where this could not be avoided or advantages it provides other than segmentation o...

amansour by L4 Transporter
  • 5526 Views
  • 6 replies
  • 0 Likes

Resolved! ThreatID and CVE

Hi Out there. For users of SIEM, some have Vulnerability scanners, anti-virus and other tools reporting CVE through syslog. In most cases the logs from PAN have threatID, other than the special Splunk integration does anyone know of a way to get the annotatations/descriptions into the log and/or publish the CVE against it, I do see it referenc...

amansour by L4 Transporter
  • 3410 Views
  • 1 replies
  • 0 Likes

How did your SSL Decryption deployment go?

We are in the process of making a case to deploy SSL Decryption. While I am sure this will happen, predeployment, I would like to hear any horror stories or even success stories on how your deployment went. Also any do's and dont's would be fantastic. Currently our environment is 4.1.7-h2 if that is a factor in your deployment stories, that much...

Application web-browsing blocked using ssl decryption

I've defined a simple rule for acces to a ssl-crypted website using application filtering.Also all ssl-crypted access to that site will be decrypted.The running Software ist PanOS 5.02.When I define a rule for access to that destination and leave the service in "application-default"The access wil be blocked an I get two entries in my LOG-File:1....

Sizing an appliance

I commented on threads outside the knowledgebase on sizing an appliance. I thought I would start the discussion here as well. Usually we run the tap mode install to get the stats and found all the counters relevant to sizing the sessions etc by SPAN or Mirror of the main egress. Datacenter is harder because you usually can't do that.

amansour by L4 Transporter
  • 2141 Views
  • 1 replies
  • 0 Likes

PANOS 4.1 vs 5.0

Which version PANOS is better 4.1 or 5.0I have installed 4.1.8 on PA-500, should i upgrade to 5.0.2?

Server error : op command for client dagger timed out

Hi,Recently when performing a show session all I recieved a response:Server error : opcommand for client dagger timed outAfter a few minutes this resolved itself. This was on code 4.1.10. Could this be related to a memory leak and the system didnt have enough resource to my request? Rgds,Gordon

gaitken by L0 Member
  • 17722 Views
  • 3 replies
  • 0 Likes

I want my telnet back!

Don't get me wrong, I really like PAN-OS 5, but why did they take my favorite troubleshooting tool away?The PA is the new device in our environment and if anything is not working all blame on the 'new guy'. User claims: 'since we have the new firewall I can't get to webpage xyz anymore' Admin: A quick telnet from the PA to xyz on port 80 is tim...

panwmod by L0 Member
  • 18475 Views
  • 23 replies
  • 3 Likes

File zeroization error: No such file or directory

Does anyone know what this means? I've never seen this before, but I got a bunch of these errors after committing a change on my passive device. I changed the network interface settings and I just recently upgraded to 4.0.13 from 4.0.11.

iguarino by L0 Member
  • 3107 Views
  • 2 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels