General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! IP - User mapping has stopped working

Hi all,

I'm having a IP-user mapping problem with my PA-500 unit running software version 3.1.8.

This unit is due to be upgraded shortly, but it would really be appreciated if anybody knew a way of resolving my issue without rebooting the unit please. 

...

DavePalo by L4 Transporter
  • 3458 Views
  • 4 replies
  • 0 Likes

TS-Agent problem

Hi,

we ve got a problem with the TS Agent on out terminalserver. After some time the TS Agent doesnt submit new users to the PA Device or the users submitted have a form error. Nomally the syntax is domain\username, but when the error occurs all submi

...

Resolved! Selective Access to Facebook and Twitter

What's the best way to configure selective access to Facebook and Twitter (where some users have full access, while everyone else has no access). 

The sources will be identified by IP address for right now (usernames later when I get to that).

So far,

...

PSC_IT by L1 Bithead
  • 9160 Views
  • 12 replies
  • 1 Likes

Resolved! Management CPU ends up stuck on 100% after several commits

Hi,

we are on a 2050 4.1.2 and are seeing consistenly that the management CPU heads towards and gets stuck on 100% after a series of commits, re-boot is only way to fix.

Is there a way to deal with this without a re-boot as this drops all sessions for

...

aardman by L1 Bithead
  • 6942 Views
  • 11 replies
  • 0 Likes

Wildcard for URL White/black list?

Is it possible to wildcard a URL for whitelist/blacklist? The issue we run into is that we will whitelist www.cooldomain.com, but if the user goes to just cooldomain.com it blocks it.  Vice versa if we just put whitelist cooldomain.com. So we end up

...

trentc77 by Not applicable
  • 2557 Views
  • 1 replies
  • 1 Likes

Resolved! Logging of URL Categories in Security policy

All,

I have my normal URL Filtering rules setup as Policy and referenced in Profile of each rule. In those policies I have either alert or block set for each category or custom category. This works as expected, however I'm trying to setup some special

...

steveo by L3 Networker
  • 8550 Views
  • 9 replies
  • 0 Likes

Resolved! User-ID Agent Losing Users

We've been running into an issue with our User-ID Agent where it seems to not have enough discovered users but its also losing them randomly as well. Running User ID Agent version 4.1.4-3, we have it pointed at 5 DCs and it is picking up around 1500

...

Terry by L0 Member
  • 4114 Views
  • 3 replies
  • 0 Likes

KeyWord Search

Hello

On our old firewall which was fortinet we could block keyword search in the web in google etc.

is there anyway to do this on Palo Alto?

Thanks

Darren

daz1981dp by Not applicable
  • 2617 Views
  • 3 replies
  • 0 Likes

Data Filtering keywords

hello can you use data filtering as a block if a user types those words in google search? eg someone types football hits search but block due to the data filter? is this possible? mark

Resolved! cannot put a interface to work

hello everybody,

I configured an interface, ethernet/5, with ip 192.168.230.1/29 and connected to a device with ip 192.168.230.3/29

Theres no way i can see each other, cannot ping PaloAlto from the other device and vice versa

Ive already changed cables,

...

Resolved! Interface or gateway monitoring

I'm looking for an option which will disable an interface if a remote gateway is not available.

This option exist for ipsec vpn (tunnel monitor) but I didn't find it for an L3 interface.

For exemple, I want to use an interface for outgoing traffic and

...

lguiraud by Not applicable
  • 2228 Views
  • 2 replies
  • 0 Likes

drop-reset application list

Hello,

I found this explanation about TCP REJECT today :

"The deny action used in a security policy will either ‘drop’ or ‘drop-reset’ based on the app being used in the policy.

For most browser-based apps, it is drop-reset - this prevents the browser f

...

Duplem by L2 Linker
  • 4474 Views
  • 4 replies
  • 0 Likes
  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels