General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Moving from Global Protect 1.1.6 -> 1.1.7

I believe moving away from 1.1.6 now requires a trusted certificate? I have about 600 remote users on 1.1.6.. trying to get to the latest rev (1.2.1) without any user interruption. I tested with our QA firerwall and I am getting certificate errors.. is there any detailed instructions on how to proceed?

rrau by L3 Networker
  • 2855 Views
  • 2 replies
  • 0 Likes

Skype - Cannot add Contacts and Skype Home Page Unavailable

Greetings,I have come across an issue which is confusing me and I am running out of options to find a solution:PANOS version: 4.1.9User-ID agent : 4.1.3-2I had issues with ip-user mapping and group-mapping ever since I've upgraded to 4.1.9. Any new users post upgrade to staff group weren't being picked up by the firewall or User-ID agent. Thi...

Resolved! Maximum number of virtual wire on PA 500

Hi all, I try to found the suitable PAN model for support my environment. I design PAN to support 2 virtual wire and 1 NAT network. I'm not sure that PA 500 will support 2 virtual wire. I prefer throughput and session number that support by PA500. Thank youTU

Resolved! Security/App-ID Bypass?

Can someone within Palo Alto Networks comment on this video? This seems like it could be an easy attack vector...Palo Alto Networks Security Bypass - YouTube

kellenc by Not applicable
  • 4951 Views
  • 3 replies
  • 0 Likes

Resolved! Maint partition is empty

Hello, I have two PA-2020 in an HA Active Passive scenario. Just looking around in my CLI, I noticed that the maint partition is empty on one of my nodes, but has an older 4.0.3 on the other node.Partition State Version--------------------------------------------------------------------------------sysroot0 REVERTABLE 4.1.7s...

cenders by L3 Networker
  • 3967 Views
  • 1 replies
  • 0 Likes

Upgrading 4.07 to 4.1.2 in HA environment

The following change log may be useful to all of you wondering how an upgrade goes in an HA active-passive pair. It would be nice if PAN support were to put this into a tech note. Each step is essentially a check or an observation from top to bottom.2050 Firewall Upgrade 4.07 to 4.1.2 Log:Pre download of PAN-OS 4.1.0 and 4.1.2 to both unitsNo co...

gmoerschel by Not applicable
  • 13025 Views
  • 16 replies
  • 0 Likes

Resolved! HA recovery advice after upgrading Active first

Being a newb and never having updated my Active/Passive HA pair, I took the 4.1.10 release notes at face value. There is no mention of special provisions for HA upgrades so I clicked "install" and now have a 4.1.10 Active member and a mismatched 4.1.7 passive member. Having now read the full product documentation I understand the "proper" way to...

MCmgt by L2 Linker
  • 4090 Views
  • 2 replies
  • 0 Likes

Reports - i cant see source ip complete.

Hi,I have a PAN-2050 (Software version 4.1.5) and i have configured a predefined report with diferents tops (top 5 connections, top 5 destinations, top 5 applications). The problem is that when i dowload and see the PDF with the report i cant see the entire ip in the Top 5 connections and i dont know where i can do more bigger the field where th...

Agentless User-ID not processing ingore-user list

I've been working on trying to configure all the firewalls with the Agentless User-ID setup but despite several attempts to enable it I cannot get it to ignore users.I establish a session and enter config mode and type in the command set user-id-collector ignore-user [ domain\serviceaccount ] then commit the changes and despite doing so I still ...

jfarm by L1 Bithead
  • 6481 Views
  • 6 replies
  • 1 Likes

Resolved! issue downloading release notes

I've been having issues downloading release notes regularly. The download doesn't even start, no matter if initiated from the support page or from the PA UI (Device-Software).Not a policy issue...Anyone else noticed that ?

dieter_b by L4 Transporter
  • 2579 Views
  • 2 replies
  • 0 Likes

SSL VPN client is sending the PA traffic with other local interface IP

I realised that some traffic from several remote clients is going through the firewall with another remote-local IP address, different from my remote assigned-pool. Obviously, this traffic is beeing dropped. It happens with users accessing correctly to other services (with the correct VPN-assigned IP). Could it be a Global Protect issue?It start...

Resolved! Installing an Intermediate CA

I'm getting the following error when I perform a commit on a PA-3020. PAN-OS 5.0.1. I know I'm doing something wrong. I'm new to installing certs so feel free to point and laugh.I had a certificate signed by GoDaddy for use by Global Protect. It came signed by an Intermediate CA.I've created a chained certificate to make sure the Intermediat...

Intermittent Group Membership problem

We are currently having a problem with a new domain where the group membership intermittently disappears. If you run the command "show user user-IDs match-user domain\" (4.1.x) or "show user pan-agent user-IDs match-user domain\" (4.0.x) it shows users mapped to AD groups.This is happening on a single new domain where all other domains are worki...

rds by L2 Linker
  • 3324 Views
  • 3 replies
  • 0 Likes

Resolved! How to import device configuration into Panorama ?

Hello,We have a customer who has installed and configured a PanOS 5.0.0 A/P cluster of devices a few time ago.Now he has bought a Panorama licence to centrally manage and report his devices.Is there a quick and straight way to import devices congigurations into Panorama ?I have seen this documentation that describes how to manually import a conf...

ldormond by L3 Networker
  • 3524 Views
  • 3 replies
  • 0 Likes

BGP Route Table

So in discussions with a few customers the BGP functionality has come up when peering with ISPs and replacing dedicated BGP equipment. The route table size on the PAN5060 is roughly 64000 routes. Most Universities have tables upwards of a 1/2 Million. Also Dynamic routing is currently unsupported on IPv6 as of PANOS5.0.2. As a workaround we...

amansour by L4 Transporter
  • 3486 Views
  • 1 replies
  • 1 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels