General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Passive Mode in IPSec

Hello~ Guys~I'd like to know Passive Mode in IPsec. Anybody Help ME~~~Thanks in advance.Have a nice day~~~

blocking google apps via URL

Our users are getting on a regualar base phishing mails in which they are asked to fill in their username and password by clicking on a link.We don't have the URL categorizing license but are using URL filtering via custom URL filtering and that works fine (most of the time). We put the links of the phishing mails in the custom URL category with...

holemans by L1 Bithead
  • 3321 Views
  • 2 replies
  • 0 Likes

Resolved! Cisco VCS random disconnects

Hi We have a Cisco VCS-C on the inside network and a rule created on our PA to allow all traffic to the VCS-E which sits on the public facing network. I'm finding my calls to H323 or IP addresses are randomly disconnecting after a period of 50 minutes.I've checked with Cisco and they've said to check my FirewallHas anyone any experience with PA'...

djrodb by L3 Networker
  • 5636 Views
  • 2 replies
  • 0 Likes

Resolved! Help: SSL decrypt vs yahoo & google driver

Hi all!I config PA to decrypt SSL traffic.I test traffic Https on gmail, facebook, it okBut my yahoo and google driver client can not connect to servers.This is my config.Pls help methanks

dat.tran by L2 Linker
  • 5042 Views
  • 1 replies
  • 0 Likes

Is PAN OS buggy?

If I only had my personal experience and the amount of chatter on the support forum, I'd say that the PAN OS is buggy. Is there more comprehensive information available on bugs in the various releases, like Cisco's Bug Toolkit? I'd like to make more informed decisions on when to take the plunge into the next release.Thanks,Mike

msullivan by L3 Networker
  • 9049 Views
  • 11 replies
  • 0 Likes

User-ID-Agent Traffic

We have user-id-agents on ou core DC's and all our local DC's (across the WAN). We receive reports with high SMB traffic polling from the core DC -> local DC. Anyway to eliminate or reduce?

rrau by L3 Networker
  • 4952 Views
  • 6 replies
  • 0 Likes

Resolved! Update application v 339

Hello,Since I have updated my active/passive cluster with latest Application and threat content (version 339, released yesterday), some ssl traffic is now recognized as "tor" application.This traffic is only ssl, not tor.Is someone else have this problem ??I have 2 PA-4020 version 4.1.9.I open a case for this with my network integrator.I returne...

Performance with Spirent

Hi All,Test with PA 5020, with PAN OS 4.0.11 with tcp reject non syn disableTraffic generate from 50k IP Source and 1 IP DestinationCan anyone give explain about why in small packet (64 bytes) test in Spirent, there is no result ?Or someone already test it?Thanks.

mgp by Not applicable
  • 2795 Views
  • 2 replies
  • 0 Likes

Resolved! SMTP Authentication for Reports, Alerts, etc.

Hello,I'm trying to setup my PA-500 (running PAN-OS 5.0.0) to e-mail me reports and alerts. But, there are no options for SMTP authentication, which our mail server requires us to use. Am I missing the options somewhere, or is this feature not built-in to the PAN-OS?If it isn't, can we please add this to a feature request list, since I'm sure ...

ndblew by L0 Member
  • 4589 Views
  • 1 replies
  • 2 Likes

Resolved! unauthorized application goes to specific rule

Hello,I have defined a rule that allow pings (using the "ping" application). However there are a lots of other applications that flows through this rule, even "web-browsing" !!!How is this possible ?Regards,Laurent

ldormond by L3 Networker
  • 11240 Views
  • 10 replies
  • 0 Likes

Firefox Error ssl_error_rx_unexpected_new_session_ticket

Hi,after PA-500 upgrade (from 4.1.7 to 4.1.9) I solved SSL problem with Chrome but now I have a problem with firefox opening SSL pages (when they was decrypted by the firewall).For example opening https://www.google.com I receive this error:"SSL ha ricevuto un messaggio inatteso di tipo New Session Ticket handshake.(Codice di errore: ssl_error_r...

diennea by L3 Networker
  • 5024 Views
  • 2 replies
  • 0 Likes

Resolved! Application Blocking page for HTTPS traffic through Web Proxy

Hello,I experienced an issue with 'application blocking page' for https traffic through web proxy.The firewall is configured to decrypt the HTTPS traffic.Layout : Client -- Palo Alto FW -- Web proxy (Squid)If the traffic (https session like https://www.facebook.com) is sent directly to Internet, I receive the 'Application Blocked page' in the br...

licenselu by L4 Transporter
  • 6803 Views
  • 4 replies
  • 0 Likes

Resolved! LDAP authentication not matching user groups

Hi.I've got LDAP authentication configured to allow users into a Global protect portal. I'm 100% sure it works OK, because I can authenticate against it.Trouble is, I *can't* get it to authenticate against an Active Directory group. if I add individual usernames into the authentication profile used by the Global Protect setup, they work - which ...

darren_g by L4 Transporter
  • 12489 Views
  • 11 replies
  • 0 Likes

Resolved! Using wildcard cert

Being smart we thought it best to use a wildcard cert as we were going to be setting up about a half dozen SSL certs and various domains, that seem to be ever expanding.One place we wish to use is on our PAN device for VPN access.but as i go to import it, it requires a passphrase, something we never set up, and going thru the CSR process, on the...

rhawley by L0 Member
  • 3415 Views
  • 1 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels