General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Application = insufficient-data?

We have some outgoing UDP traffic that shows up in the traffic log with "insufficient-data" in the application field. The problem is that this traffic is being allowed through the firewall because it's being matched to a rule that allows FTP traffic through. What does the firewall mean by "insufficient data", and why does it think it's FTP traff...

ahopkins by L2 Linker
  • 22109 Views
  • 7 replies
  • 0 Likes

Alternative to sAMAccountname ,when using Ldap for Authentication

Hi,When we use to authenticate users through AD, we configure LDAP profile and in Authentication profile tab.We write "sAMAccountname" for attribute at this window.We want to change this attribute and we want users not to log in with just username; We want them to log in with username@domain or domain\username so What attribute should we use ?...

Resolved! Panorama license limit

Does anyone know if a customer owns a Panorama 25 device license and wants to add device #26, will it not allow them to add the 26th device or will it?Thx

jwolach by L4 Transporter
  • 7923 Views
  • 8 replies
  • 0 Likes

Threat exception for selected hosts

Hi,We have defined vulnerability group which consists of AV, Anti-Spyware and Vulnerability profile. The vulnerability profile is configured to block critical events and alert on high and med. I have a need to except few hosts which are alerting for SSH brute force (high). How do I achieve this? Assuming if I configure new profile group and poli...

Resolved! 4.1.7 inspection causes corrupt download and speed issues

I have two 2050's in an HA pair A/P on 4.1.7. I have a BGP setup with 100Mbps on one link and 250Mbps on another, and Gb to the LAN and DMZ. I have transferred just over 3G through the PA in the last 60 minutes.When I turn on inspection (Antivirus, IPS/IDS, Data Filtering, File forwarding) I see corruption in downloads. For example, when d...

EdwinD by L3 Networker
  • 9202 Views
  • 9 replies
  • 0 Likes

Exclude iTunes/App Store from decryption

I am using SSL decryption for all outbound traffic. Prior to the decryption rule I have a rule to attempt to exclude iTunes and App Store traffic from decryption. The rule seems to be working, but the App Store fails with "NSURLErrorDomain error -1012". When I turn off all decryption the App Store works.My rule is setup for no-decrypt from any...

Resolved! easy question, routing problem

Hello,I think it's an easy question, but I can't solve it.This is the situation. We have two routers.Router 1 (bintec RT1202) has two ethernet interfaces with different subnets sub1 (172.16.10.0/24), sub2 (172.16.20.0/24).Router 2 is our palo alto PA-200. It has one ethernet interface sub1(172.16.20.0/24)(just for the test).Now I want to make a ...

IDS_1 by Not applicable
  • 8841 Views
  • 6 replies
  • 0 Likes

Resolved! Can AD User Agent 5.0.0-22 be used with PanOS 4.1.x?

I have a large number of AD servers at remote locations all running AD User Agent 4.1.6-5. I do have problems with PanOS 4.1.7 talking to this user agent; it forgets who is signed onto a PC.Can I install User Agent 5.0.0-22 on my AD servers and expect my 4.1.7 - 4.1.9 PanOS firewalls to talk to this new user agent, as well as function properly?

EdwinD by L3 Networker
  • 2576 Views
  • 1 replies
  • 0 Likes

Resolved! Panorama 4.1.8 LDAP Failure

Having upgraded our Panorama from 4.1.7 to 4.1.8 - we can no longer use the LDAP user authentication.The user constantly gets "invalid username or password" (same message on the Panorama) - yet this worked without any problems with 4.1.7On Panorama - one can see that in the LDAP profile - the Base option is never getting populated (dropdown opti...

sitecore by Not applicable
  • 15208 Views
  • 22 replies
  • 1 Likes

Resolved! how to config data filtering profile?

Hi All,I want to setup data filtering profile for security issue, however the document is too old that I have, it for PANOS 2.1.5.Is there any recent update about how to config data filtering ?Regards,Joy

source nat with dual ISP configuration having issue.

Hi,am running panos 4.1.7 on PA-500 , recently i configure two isp on the pa500 for redundancy , i followed the procedure in DOC-3579 everything is fine except for the source nat policy when clicking on commit , it returns that nat rule1 shadows rule2 which leads to after a failover occurs the source nat for primary isp is taking precedence ove...

Resolved! Global Protect CLient "Startup Before Login"

Is there a way to have the Global Protect client interface show up before a user logs into Windows? For example, They want to manually connect to VPN before they login to their Windows machine. Thanks

eputnam by L1 Bithead
  • 4113 Views
  • 4 replies
  • 0 Likes
  • 24452 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels