General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

Resolved! Physical connectivity validation on passive device

Hello,We use vsys on our PaloAlto cluster. During a new vsys deployment, I would like to validate that the passive device's physical connectivity to a switch is working. But I don't wish to launch a failover just for this, because it could impact the whole cluster.Is there any way to test physical or logical interfaces connectivity without any f...

Duplem by L2 Linker
  • 4397 Views
  • 2 replies
  • 0 Likes

Resolved! GP agent takes 30 seconds to connect

HelloWe are currently testing the GlobalProtect VPN client. One issue that bothers us is that the GP agent takes more than 30 seconds to connect to the gateway. Is that really the time it takes to establish a tunnel? Our earlier PPTP solution took 1-2 seconds to connect...Our setup looks quite simple. We followed the setup in the official docume...

oschuler by L4 Transporter
  • 4883 Views
  • 4 replies
  • 0 Likes

Resolved! How does the firewall work when they received unknown-user's packet?

Hello, Guys. Nice to meet you.I'm testing User-ID in PAN OS 4.1 and USER Agent 4.1.There's something curious situation during my lab test.I've deleted all ip-user-mapping information with 'clear user-cache all'.So all users is unknown to firewall.But the user agent still has ip-user mapping information using WMI probing.In this case, I think the...

JTR by Not applicable
  • 3750 Views
  • 2 replies
  • 0 Likes

Resolved! Vulnerability

When you add a custom vulnerability signature to the Palo, is it added to the default vulnerability profile by default?

cdamore by L1 Bithead
  • 2358 Views
  • 1 replies
  • 0 Likes

Resolved! Inbound SSL Inspection with mis-matched certificates (or SSL handoff)

Hi,I'm kind of expecting a no to this question, but I noticed whilst setting up inbound SSL inspection for a client the other day that if the Cert on the Palo Alto and the cert on the SSL web server do not match then the firewall will refuse to decrypt the traffic and just pass it though as SSL using the server certificate.It would be great to b...

Dpeters1 by L2 Linker
  • 8692 Views
  • 5 replies
  • 0 Likes

Resolved! Can anyone explain this vulnerability in more detail "Service Enum Through SMB ServiceEnum2"

I am trying to find more detail on what this vulnerability is and what could possibly be triggering it in a Windows Server environment. I am thinking that it might be a mis-configured service or application native to Windows Server but looking for a system expert to confirm or deny that theory.When I look it up in the Threat Vault all it says i...

u11712 by Not applicable
  • 11067 Views
  • 1 replies
  • 0 Likes

User/Group based policy questions

Hi,I have a need to configured user/group based policy. I having difficulties with the same and have multiple questions. I hope someone will help me with the configuration.1. We push all our policies from Panorama. Can I configure user/group based policy on Panorama and push to all firewalls?2. I have pushed the LDAP config from Panorama to all ...

Resolved! PanOS 5.0 User-ID Redistribution

So a new feature within 5.0 is to allow a PA to act as a user-id redistribution point for other PA's. Has anyone gotten this to work? I tried testing this out, but I am not seeing how to configure. I setup our core PA's to act as a redistribution point using a collector name and shared key.I then tried configuring one of my remote PA's to connec...

Resolved! Settings for getting Hyper-V working in PAN

setupHello,I have been struggling with this all day, and I think I have it narrowed down, but can't seem to nail it down yet.I have a test Hyper-V 2012 server in the data center, and all my services are working properly, except being able to connect to the VM's via Virtual Machine Connection. It uses TCP Port 2179 and is basically RDP, just runn...

Resolved! Receive time of logs ("Traffic Log") in a custom report

Hello all,I've created a custom report for gettings logs (from Database "Traffic Log") and I need the exact receive time for the entries.Unfortunately, there is no such column to choose from. The only column that contains time information is "quarter hour" - but this is not precise enough. If you take a look at the traffic logs directly (no cust...

Resolved! L3 setup for DMZ link

I currently have the following setup. Two PA's in active-passive with an L3 interface configured with zone DMZ-Web connected into a single switch. That same switch is connected to a VM host that is also in an active-passive configuration. The problem here is that the switch is a single point of failure. If we put in a second switch, can I ag...

iguarino by L0 Member
  • 3322 Views
  • 3 replies
  • 0 Likes

Resolved! ISP Support

Hi,Just want to know how many ISP does Palo Alto supports?Thanks in advance.Rex

ANY policy not matching host traffic

Hi,I am troubleshooting SMTP access issue and for the same I have configured ANY allow policy for the host (src). I however dont see the SMTP matched in the policy. The ANY policy is device specific and is configured at top. All policies after that are pushed via Panorama. We have a default catch-all policy at the bottom and the SMTP traffic mat...

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels