General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SMTP Authentication for Reports, Alerts, etc.

Hello,I'm trying to setup my PA-500 (running PAN-OS 5.0.0) to e-mail me reports and alerts. But, there are no options for SMTP authentication, which our mail server requires us to use. Am I missing the options somewhere, or is this feature not built-in to the PAN-OS?If it isn't, can we please add this to a feature request list, since I'm sure ...

ndblew by L0 Member
  • 4629 Views
  • 1 replies
  • 2 Likes

Resolved! unauthorized application goes to specific rule

Hello,I have defined a rule that allow pings (using the "ping" application). However there are a lots of other applications that flows through this rule, even "web-browsing" !!!How is this possible ?Regards,Laurent

ldormond by L3 Networker
  • 11508 Views
  • 10 replies
  • 0 Likes

Firefox Error ssl_error_rx_unexpected_new_session_ticket

Hi,after PA-500 upgrade (from 4.1.7 to 4.1.9) I solved SSL problem with Chrome but now I have a problem with firefox opening SSL pages (when they was decrypted by the firewall).For example opening https://www.google.com I receive this error:"SSL ha ricevuto un messaggio inatteso di tipo New Session Ticket handshake.(Codice di errore: ssl_error_r...

diennea by L3 Networker
  • 5117 Views
  • 2 replies
  • 0 Likes

Resolved! Application Blocking page for HTTPS traffic through Web Proxy

Hello,I experienced an issue with 'application blocking page' for https traffic through web proxy.The firewall is configured to decrypt the HTTPS traffic.Layout : Client -- Palo Alto FW -- Web proxy (Squid)If the traffic (https session like https://www.facebook.com) is sent directly to Internet, I receive the 'Application Blocked page' in the br...

licenselu by L4 Transporter
  • 6935 Views
  • 4 replies
  • 0 Likes

Resolved! LDAP authentication not matching user groups

Hi.I've got LDAP authentication configured to allow users into a Global protect portal. I'm 100% sure it works OK, because I can authenticate against it.Trouble is, I *can't* get it to authenticate against an Active Directory group. if I add individual usernames into the authentication profile used by the Global Protect setup, they work - which ...

darren_g by L4 Transporter
  • 12733 Views
  • 11 replies
  • 0 Likes

Resolved! Using wildcard cert

Being smart we thought it best to use a wildcard cert as we were going to be setting up about a half dozen SSL certs and various domains, that seem to be ever expanding.One place we wish to use is on our PAN device for VPN access.but as i go to import it, it requires a passphrase, something we never set up, and going thru the CSR process, on the...

rhawley by L0 Member
  • 3457 Views
  • 1 replies
  • 0 Likes

issue with uturn nat, please help!

Hi AllI have a u turn nat rule and security policy in place that has been working fine to allow internal access to the external url of our exchange owa and now it has stopped working - nothing has changed on the firewalls or on the exchange system that could explain the problem.The u-turn nat rule is setup as followsSource Zone: L3_InsideDestina...

no fpga memory for dfa

Hi all,I get some warning message as below, is there anybody meeting such messages?What does it mean?Nov 08 15:08:57 Warning: pan_fpga_alloc_dfa_partition(pan_fpga_handler.c:909): no fpga memory for dfa, subtype 2 size 180Nov 08 15:08:57 Warning: pan_fpga_alloc_dfa_partition(pan_fpga_handler.c:909): no fpga memory for dfa, subtype 2 size 180Nov ...

Blocking Downloads - Real World Examples?

We currently use our PAN in quite a dumb way where most internet access for end users is controlled by a single rule at the top of our rule set which simply allows https/https as outbound services, we don't block/allow specific applications but we do block by URL category and we do monitor using app-id.Could I please get a little feedback on how...

Ipad detection

We've configured the PA500 to accept IPAD connections using IPSEC, but is there a way to detect the fact that an Ipad is connected using HIP rules? We would like to only allow traffic to certain systems.Version PA OS = 4.1.4

Clearing URL Continue Timeout

Hello, Converting from BlueCoat ProxySG's to PAN URL Filtering... Within a BlueCoat environment when you "coach" a user... you can have the Bluecoat use a cookie to tell when next to "coach" the user. This can be cleared by deleting cookies... Can a person 'clear' the URL Continue Setting for a user causing the user to see the continue page...

Art by L3 Networker
  • 3167 Views
  • 1 replies
  • 0 Likes

Destination NAT with PBF

Hello all,I have a question if Destination NAT with PBF is supported.I have two site A and B. All internet bound traffic is supposed to go out site A. Site B sends its traffic over a VPN tunnel to site A due to a default route. There are however some devices that rely on the public IP's given to us so I had to maintain the static NAT locally.The...

andrew85 by L0 Member
  • 3447 Views
  • 3 replies
  • 0 Likes

Problem with certificate after upgrading GlobalProtect 1.1.7

Hi everybody.Up to now, I've had working a Globalprotect configuration, with only a Server Certificate, and it worked very well.After upgrading to version 1.1.7, I've received the message: "The paloalto.xxxxx.es certificate is not signed by a trusted certificate authority.". That is a problem for "no on demand" VPN connections, because you have ...

NTop NetFlow

Hi all,Does anyone have experience feeding NTop via NetFlow from their PA firewalls? I have it setup and sending flows but NTop sees all of the received flows as either "Flows with zero byte count" or "Flows with zero packet count" and discards them. Perhaps someone knows a fix for this?Thanks,Chris

GV27 by L1 Bithead
  • 5904 Views
  • 5 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels