General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2168 Views
  • 0 replies
  • 0 Likes

Resolved! Policy migration question...

I am migrating from a port-based firewall to the PA and I want to put the application for all policies that cover inbound services instead of the ports.  I plan on temporarily doing a V-wire on the internet connection before the cutover to gather the

...

Rjschultz by Not applicable
  • 3280 Views
  • 4 replies
  • 0 Likes

Resolved! Cisco Telepresence test failing due to SDP being rewritten

We ran http://test.callway.com on our network to test Cisco WebEx Telepresence and it fails due to the following:

Issue

Your firewall is altering SIP messages and interfering with the proper operation of WebEx Telepresence.

What does this mean?

Your call

...

sconley by Not applicable
  • 3228 Views
  • 2 replies
  • 0 Likes

Resolved! Passive Mode in IPSec

Hello~  Guys~

I'd like to know Passive Mode in IPsec.

Anybody Help ME~~~

Thanks in advance.

Have a nice day~~~

blocking google apps via URL

Our users are getting on a regualar base phishing mails in which they are asked to fill in their username and password by clicking on a link.

We don't have the URL categorizing license but are using URL filtering via custom URL filtering and that work

...

holemans by L1 Bithead
  • 3080 Views
  • 2 replies
  • 0 Likes

Resolved! Cisco VCS random disconnects

Hi

We have a Cisco VCS-C on the inside network and a rule created on our PA to allow all traffic to the VCS-E which sits on the public facing network. I'm finding my calls to H323 or IP addresses are randomly disconnecting after a period of 50 minute

...

djrodb by L3 Networker
  • 5230 Views
  • 2 replies
  • 0 Likes

Resolved! Help: SSL decrypt vs yahoo & google driver

Hi all!

I config PA to decrypt SSL traffic.

I test traffic Https on gmail, facebook, it ok

But my yahoo and google driver client can not connect to servers.

This is my config.

Pls help me

thanks

dat.tran by L2 Linker
  • 4572 Views
  • 1 replies
  • 0 Likes

Is PAN OS buggy?

If I only had my personal experience and the amount of chatter on the support forum, I'd say that the PAN OS is buggy.  Is there more comprehensive information available on bugs in the various releases, like Cisco's Bug Toolkit?  I'd like to make mor

...

msullivan by L3 Networker
  • 8210 Views
  • 11 replies
  • 0 Likes

User-ID-Agent Traffic

We have user-id-agents on ou core DC's and all our local DC's (across the WAN).  We receive reports with high SMB traffic polling from the core DC -> local DC.  Anyway to eliminate or reduce?

rrau by L3 Networker
  • 4547 Views
  • 6 replies
  • 0 Likes

Resolved! Update application v 339

Hello,

Since I have updated my active/passive cluster with latest Application and threat content (version 339, released yesterday), some ssl traffic is now recognized as "tor" application.

This traffic is only ssl, not tor.

Is someone else have this pro

...

Performance with Spirent

Hi All,

Test with PA 5020, with PAN OS 4.0.11 with tcp reject non syn disable

Traffic generate from 50k IP Source and 1 IP Destination

Can anyone give explain about why in small packet (64 bytes) test in Spirent, there is no result ?

Or someone already t

...

mgp by Not applicable
  • 2571 Views
  • 2 replies
  • 0 Likes

Resolved! SMTP Authentication for Reports, Alerts, etc.

Hello,

I'm trying to setup my PA-500 (running PAN-OS 5.0.0) to e-mail me reports and alerts.  But, there are no options for SMTP authentication, which our mail server requires us to use.  Am I missing the options somewhere, or is this feature not buil

...

ndblew by L0 Member
  • 4382 Views
  • 1 replies
  • 2 Likes

Resolved! unauthorized application goes to specific rule

Hello,

I have defined a rule that allow pings (using the "ping" application). However there are a lots of other applications that flows through this rule, even "web-browsing" !!!

How is this possible ?

Regards,

Laurent

ldormond by L3 Networker
  • 9929 Views
  • 10 replies
  • 0 Likes

Firefox Error ssl_error_rx_unexpected_new_session_ticket

Hi,

after PA-500 upgrade (from 4.1.7 to 4.1.9) I solved SSL problem with Chrome but now I have a problem with firefox opening SSL pages (when they was decrypted by the firewall).

For example opening https://www.google.com I receive this error:

"SSL ha r

...

diennea by L3 Networker
  • 4554 Views
  • 2 replies
  • 0 Likes
  • 24249 Posts
  • 119 Subscriptions
Top Liked Authors
Labels