General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Skype requires 'unknown-tcp'

Why is 'unknown-tcp' an application dependency of Skype,  is it possible to remove a dependency from a pre-defined application.   Or do we have to setup an application overide?

I don't really want to allow unknown-tcp 'apps' just to allow someone to u

...

JohnP by L1 Bithead
  • 5726 Views
  • 6 replies
  • 0 Likes

DHCP Relay not returning address from MS AD DHCP Server

We setup a DHCP relay to a MS 2008R2 DHCP server, server recieves the relay and passes a client address back to PA 2050 running 4.1.3, the address does not get passed through to client, logs show only thr DHCP request going out but nothing back, no b

...

aardman by L1 Bithead
  • 4149 Views
  • 5 replies
  • 0 Likes

Possible solution to slow commit

Hi, regarding of the desperately slow commits in PA specially with a large number of rules and object. From our experiencie in other systems the rule shadow check is a very high CPU feature. It's sure that PA do a rule shadow and this it's in concord

...

ssancho by L2 Linker
  • 12059 Views
  • 14 replies
  • 1 Likes

The people complain about slow commit

Whenever we make a PoC, Everybody complains about slow commit.

As far as I know, the traffic is not effected during the commit.

But people request faster commit

First, How can we explain slow commit to people technically.

Secondly, Is there any plan to

...

Block file transfers in RDP connections?

Is the RDP application visibility granular in that we can figure the PAN to allow remote desktop connections but disable the mapping of local drives to prevent file transfer? 

Nick1 by Not applicable
  • 3946 Views
  • 5 replies
  • 0 Likes

User ID dissappears

On the monitor window I can see that a large number of our users are showing their AD "user".  However, when I filter by the IP, I am finding that a "user" will be associated with an IP and all of the sudden the "user" dissapears even though the traf

...

BobW by L4 Transporter
  • 1967 Views
  • 1 replies
  • 0 Likes

USE IDENTIFICATION WITH 100 PAN AGENT

Hello,

I must use 100 PAN AGENT (limit of product) for a project. Someone have already test to use 100 pan-agent ( 25 by VSYS*5)?

do you know if the Palo alto (PA5060) work fine with this number of pan-agent.

regards,

ALLE

alle by L3 Networker
  • 3107 Views
  • 5 replies
  • 0 Likes

PBR IN HARDWARE?

Hello!

just a little question on PBR!

PA4020 support PBR in HARDWARE? Which Limitation For PBR?

thks,

ALLE

alle by L3 Networker
  • 4413 Views
  • 10 replies
  • 0 Likes

Resolved! About non-syn-tcp option

Hello guys.

As you know that PAN has got a option of session that non-syn-tcp.

I have a question about non-syn-tcp.

When reject non-SYN first packet was false (when non-syn-tcp was not dropeed) and non-syn-tcp session already establised throught PAN dev

...

ttongfly by L3 Networker
  • 7785 Views
  • 2 replies
  • 1 Likes

Pros vs Cons with PAN?

I guess it would be a bit biased to ask for Pros vs Cons of PAN in the supportforum of PAN  but I recently stumbled upon an article (which I wish to share) regarding PAN which I think might be of interrest for most of us in this forum:

http://www.cym

...

mikand by L6 Presenter
  • 2360 Views
  • 1 replies
  • 0 Likes

Reports based on Specific Departments

Hi Guys,

Is there any way on the Palo Alto Firewall and Panorama to generate a Custom Report based on Departments from an Active Directory.

For example; me as a user Kal is a part of the Technical Department.  Will it be possible to have a report on so

...

User identification not working properly

Hi,

we are facing the issue that the user identification is not working properly.

I am running PAN OS 4.1.4 on a PA-200 device and User-ID-Agent 4.1.4-3 on a Windows 2008 R2 member server.

The UI agent is connected to both the DCs (Windows 2003 servers

...

cschmi by Not applicable
  • 4414 Views
  • 7 replies
  • 0 Likes

Connecting a videoconference to PAN without using NAT

Hello All,

I have this small question here that I hope can find answers or suggestions.

Currently we have a videoconference unit that was connected to the internet via NATting in the PAN ? I am wondering if there is a way to make it non-nat by connecti

...

mmxong by Not applicable
  • 1662 Views
  • 1 replies
  • 0 Likes

application vs url categories dependencies

I want to allow access to Twitter, but block all other social-networking services.

The obvious approach is to allow the Twitter application and then have a rule blocking the social-networking category for web-browsing and ssl, but this doesn't work, T

...

Resolved! How to handle jdownloader?

Hi guys,

I was wondering what the best way to handle jdownloader or other download managers? Are they treated as seperate apps? Is the only way to deal with this via QoS policies? I'd love to hear about your experiences.

Alex

Abs by L3 Networker
  • 5510 Views
  • 12 replies
  • 0 Likes
  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels