General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 382 Views
  • 0 replies
  • 0 Likes

Resolved! Ldap Proxy

Hi,

in what situations should we use user-id agent as Ldap Proxy ? And when we select this function, how agent behaves?

panos by L6 Presenter
  • 2906 Views
  • 2 replies
  • 0 Likes

Resolved! Exclude config snippet from HA sync?

Hi,

I've deployed two standalone firewalls...i.e., non-HA.  And have been using the interface comment field to document the switch port that interface is connected to.  I'm now building an active/passive cluster and noticed that when I sync the config

...

Empty Reports, What a I missing?

I am new to the PaloAlto world, and admittedly somewhat overwhelmed at the moment. I am working with the reporting features and not getting even close to the results I expect. Particularly when I run a "User Activity Report", I get a 5 page PDF and a

...

Process to change to HA from cold spare

The HA documentation states that one should start with a 'clean slate' when implementing HA. I currently have one PA-500 in production on 4.1.4 and another PA-500 as a cold spare. The production PA-500 has 2 unused traffic ports that can be used for

...

pkuhnen by L0 Member
  • 4566 Views
  • 6 replies
  • 0 Likes

top bandwidth usage

is there a way to fined the top bandwidth usage in PA 4.1.x in the exact moment that i need , because usually i have to wait for 15 minutes to get it from the ACC.bandwidth

Question regarding unknown application behaviour

Lets say you configure a rule with:

Application = Any

Service = Custom Service (TCP port 12345)

Now when the AppID engine cannot match anything I guess it classifies the traffic as "unknown-tcp".

Will the traffic be allowed (because unknown-tcp is part o

...

Anon1 by L4 Transporter
  • 3577 Views
  • 5 replies
  • 0 Likes

Resolved! MDT and GP client

What's everyone using to deploy GP client? We're finding that because the GP client is not populated with any information(when downloading it from our PA firewall) it's causing problems with the MDT process. The MDT process stops as the GP client pop

...

djrodb by L3 Networker
  • 2699 Views
  • 1 replies
  • 0 Likes

Resolved! How to Fix - Error in getting locked users?


I have users locked out and yet when I go to Device > Authentication Profile is how this error in the Locked Users column "Error in getting locked users".  What is cause and how do I fix it?

This has now come up fairly often.

System PA-2020 with 4.0.4

...

Assigning VPN User a Static IP

We have a customer who is running a specific thick application that requires the user to have the same IP address every time they attempt to authenticate to their servers. In the office this is not an issue since we can assign them a static IP and th

...

jmahoney by L1 Bithead
  • 3334 Views
  • 2 replies
  • 0 Likes

How to block upload dropbox with upstream proxy

Hi to all,

I have to implement a block dropbox upload.

The architecture that I have to provide the user network, the internal firewall Palo Alto, an external proxy, an external firewall, Internet.

I configured the various points to implement the block a

...

SOCMAECI by L0 Member
  • 1870 Views
  • 1 replies
  • 0 Likes

Resolved! Allow domain services through PAN 2050

I am trying to allow windows active directory services (2008 domain) through the firewall, in between zones.  I have created my policy to allow the following applications:

active-directory

ms-ds-smb

msrpc

netbios-ss

dns

ms-win-dns

ms-wins

netbios-dg

ms-netlog

...

UncleRico by Not applicable
  • 3724 Views
  • 2 replies
  • 0 Likes
  • 23837 Posts
  • 112 Subscriptions
Top Liked Authors
Labels