General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 779 Views
  • 0 replies
  • 0 Likes

VoIP over NAT issues: Ring but no audio; disconnects

I have our VoIP PBX set up with an IP on our external side via NAT. The policy is a simple static NAT from the internal IP to the external. I also have the correct security policies in place to allow SIP/RTP traffic to pass freely to and from the ext

...

Resolved! PA-2000 HA Timers

Currently if I hard power down my primary firewall it takes about 6 Seconds for the secondary to take over, a bit slow really.

Changed most of the HA timers to their minimum, just checking to see if there is any other configuration that can be changed

...

http forward to proxy

Hi,

I try to forward my WiFi mobile users http communications to my proxy.

WiFi mobile users and proxy are in two different VLAN plug on Palo Alto (default gateway of mobile users and proxy is Palo Alto Firewall).

Is it possible with Palo Alto?

The probl

...

mlop by Not applicable
  • 10317 Views
  • 13 replies
  • 0 Likes

Resolved! Using ISA for OWA

Hi All

I'm looking to replace our Fortigate 110c with a new PA-500 and I've managed to write the security and NAT policies which when tested seemed to work well apart from OWA.

We have an ISA 2006 server which publishes OWA and OMA on a public IP and h

...

TDC by L1 Bithead
  • 2889 Views
  • 3 replies
  • 0 Likes

Resolved! Session timeout

Hi All,

i want to ask about session timeout setting in palo alto.

if we create policy to allow traffic from trust to untrust with service http (custom http port 80)

1. what is default session timeout for http traffic?

from my testing it will hit web-brow

...

el by Not applicable
  • 4076 Views
  • 2 replies
  • 0 Likes

Palo Alto in Cisco network with VRF lite

BRosenba asked this question last year.  "We've recently purchased an HA pair of PA 5050s. We are planning to utilize the devices in cooperation with some Cisco core switching hardware and VRF lite to segment/secure internal traffic as well as traffi

...

oshcomp by Not applicable
  • 4920 Views
  • 1 replies
  • 1 Likes

Resolved! Control OWA

Hi

I want to stop our users from accessing company email from their home (non company supplied) PCs using OWA. I still want to allow access to our email systems through webmail/https

Can this be achieved by app filters (MAPI, Active sync) OR do I need

...

djrodb by L3 Networker
  • 4414 Views
  • 4 replies
  • 0 Likes

New Pan Agent.

We recently installed the new  PAN agent  4.1.4.3.

Since we installed this we don't seem to be able to get at our LDAP group against which we have many security rules.

i have been told that an option exist with userid agent option in the Device tab to

...

Resolved! CERT_DATE ERROR SSL-VPN Global Protect PanOS 4.1

Hello,

I configured the VPN-SSL on PANOS 4.1 using the "Configure Global Protect tech notes" document and the migration from Netconnect to Global Protect. Following these manuals I got this error.

(T5448) 01/19/12 12:21:10:825 Debug( 392): CPanHTTPSess

...

Resolved! Seperate policy for IPSec VPN and SSL VPN?

So I would like to have different policies based upon what device a user comes in from. If they use Globalprotect with HIP checking, they are given a less restrictive policy. Where as if they come from an iphone with ipsec, they are given a more rest

...

Resolved! Mac GlobalProtect = Detected another instance

I just setup SSL-VPN access on our PAN-2020s and downloaded the latest Global Protect Bundle that was released on June 20th, 2012 - v. 1.1.5.  I logged into the portal in my mac and installed the version for Mac running OS X 10.7.4 (64bit) and once t

...

cmateam by L3 Networker
  • 19033 Views
  • 12 replies
  • 0 Likes

Resolved! Captive Portal - identify user with certificate

Hello everybody.

I have a question regarding captive portal user identification.

As everybody know user like Mac, iPhone, Android are difficult to identify and manage without insert credential in captive portal.

For wireless policy in all my company dev

...

  • 23986 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels