General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Global Protect 1.1.7

Hi,when we use this new version and with out wildcard certificate it gives an error.Can't we use wildcard cert with GP 1.1.7 ?Thanks.

Resolved! 4.1.7 Problem with Domain Users enumeration persists.

I am running PanOS 4.1.7 on a pair of HA 2050's which use direct LDAP connectivity to multiple AD servers for group membership. I also have the UaInstall-4.1.5-1.MSI 4.1.5 user to IP agents running on my DCs. I do not have the group membership coming from the user to IP agent running on the servers. I have the 2050's enumerating group member...

EdwinD by L3 Networker
  • 3419 Views
  • 2 replies
  • 0 Likes

Resolved! Google Chrome Update

I'm seeing an issue with the latest version of Chrome that was released earlier today (21.0.1180.60) and SSL-Decryption. On either Mac or Windows platforms, any sites that are in the decryption policy (google, gmail, facebook, etc) are met with the following error: Error 324 (net::ERR_EMPTY_RESPONSE): The server closed the connection without sen...

Problem connecting

Hi, I hope you can help me...thanks in advanceWe have installed useri-id in a ,machine (10.1.1.49) but when the user-id tries to connect to domain controller (apqtdc(10.1.1.16)) we have this error in the logs.( description contains 'UserID failed to connect to agent orgtdc02(10.1.1.16), source: 10.1.0.49: Device requires protocol ver. [3, 4] but...

PA-200 reported throughput and actual download speed

Hi,I have a PA-200 at home and am doing some tests with regard to the reported throughput speed using the "show system statistics session" command. To give an idea: I have a PA-200 sitting between my desktop computer and the internet, which is connected through a 60 Mbps line. I am testing with an SSL encrypted constant download, which went up...

fcremer by Not applicable
  • 2821 Views
  • 1 replies
  • 0 Likes

Howto read out ICMPv6 Token Bucket statistics?

Hi,Would there be a way how to read the statistics about the usage of the ICMP IPv6 token-bucket? Additionally what is the relation between token based rate limiting as a global device setting and theICMPv6 CPS rate limiting in on a per zone configuration setting? Thank you,Kind regrads,Wim

wimjuste by L1 Bithead
  • 2323 Views
  • 1 replies
  • 0 Likes

Dual power supplies

Dear All,We have more and more requests and complaints from prospective clients requesting dual power supplies on the PA 2xxx and upcoming 3xxx series. This is one of the first questions we get from many prospective clients, and the negative answer in this regard always starts off negotiations on the wrong foot. Most customers view the PAs as be...

Resolved! Problem with certificate after upgrading GlobalProtect 1.1.7

Hi everyboy.Up to now, I've had working a Globalprotect configuration, with only a Server Certificate, and it worked very well.After upgrading to version 1.1.7, I've received the message: "The paloalto.xxxxx.es certificate is not signed by a trusted certificate authority.". That is a problem for "no on demand" VPN connections, because you have t...

File Blocking, save file locally

Hello,With wildfire you can use a policy to send the files to the cloud, so that paloalto networks can analyze it.Is there a possibility to send the file to a an internal ftp or to save on the device?Thanks

aojea by Not applicable
  • 2794 Views
  • 1 replies
  • 0 Likes

Easily fooling App ID?

Recently I've seen some information posted on a forum and I was hoping someone could speak to this. Here is a quote:"I work as a security auditor and I've come across them a few times. The "application" is http (web) which is allowed from the client segment to the external one. The backdoor software mimics a regular web session, as per a user w...

tweaked2 by L0 Member
  • 13056 Views
  • 10 replies
  • 2 Likes

Default syslog string?

Would anyone by any chance know the "default" syslog string ie. with the parameters $path etc etc... Would be interesting to know to have something to start from instead of beginning, like now, clean... Br, Christian

criiser by Not applicable
  • 2448 Views
  • 1 replies
  • 0 Likes

Resolved! Moving from a Cisco ASA to PA-5020 Setting up a DMZ zone on the Palo Alto . There is suppose to be a tool to work with the existing cisco configuration to build a config for the Palo Alto

Moving from a Cisco ASA to PA-5020 Setting up a DMZ zone on the Palo Alto . There is suppose to be a tool to work with the existing cisco configuration to build a config for the Palo Alto any one used it or have a copy ?

dnagin by L1 Bithead
  • 2659 Views
  • 1 replies
  • 0 Likes

Resolved! How to include users directly belongs to OU (orgnisation unit) in include group option in LDAP group mapping for user id Agent,..?

Hi All,..We have installed User ID agent 4.1.5 showing ip to user mapping or traffic, now we are looking to place a user based policies but in AD users are directly belong to OU which we cant add in the include group option in group mapping.. is der any way to get user names in policies?Regards,Guru.

Gururaj by L4 Transporter
  • 2547 Views
  • 1 replies
  • 0 Likes

Resolved! On device in policies not showing user names, but in user-id agent we are able to see ip to user mapping.

Hi All,On device in policies not showing user names under the source user tab, but in user-id agent we are able to see ip to user mapping. PaloAlto device is connected to machine on which user-id agent has been installed. Is there any other configuration is required to get user names in policies ? Please help me.Regards,Guru

Gururaj by L4 Transporter
  • 4396 Views
  • 3 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels