General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

User-Id Agent no longer showing domain

I setup the user id agent with the PA for an organization several months back. They reported it not blocking correctly so I logged in to take a peek. The PA used to report their username as domain\user but now it is just reporting the username (with

...

SDorsey by L4 Transporter
  • 2382 Views
  • 1 replies
  • 0 Likes

Resolved! ftp export log traffic query example?

Can someone provide an example of the valid parameters and format for the query statement used in an FTP export? My immediate need is to limit to a specific vsys, and the size is too large to do through the GUI.

I know the base command is this:

     ft

...

u11756 by Not applicable
  • 2443 Views
  • 1 replies
  • 0 Likes

Resolved! How to Clear (remove) Pending CFG Changes

So I have a few changes that are in the candidate config waiting to be committed.

However there are a few changes in there that I dont remember doing and they make me a bit nervous.

How can I clear the candidate config so there is nothing to commit? I

...

choff123 by L3 Networker
  • 7898 Views
  • 2 replies
  • 0 Likes

Resolved! Brightcloud update in Palo alto

Hi,

On startm, I just want to stating that im french.  You may have some difficulty to read next !

Its a question about how Palo Alto take new update of Brightcloud URL DB.

We replace WebSense by Palo Alto, because PA manage more then just HTTP and a f

...

Resolved! reverse proxy key doesn't match certificate

We deployed our PA last month, generated an SSL certificate (forward trust, forward untrust, and trusted root CA), and created SSL decryption rules.  Since the creation of the rules we are getting weekly medium system alerts (8 of them) stating "reve

...

sconley by Not applicable
  • 5295 Views
  • 1 replies
  • 0 Likes

ISP Failover and Global Protect (Routing Issues)

Hello All,

I have a pretty simple setup here - single PA-2020 with dual ISP's (One Virtual Router).  We're also using Global Protect (SSL VPN only) currently.  I seem to have an issue that I cannot sort out.

ISP failover works great through the use of

...

Pan Agent Clear clear user-cache all issue

Hello,

I've an issue with a cluster of PA500 running PANOS 4.1.7.

I'm using User Agent (release 4.1.5-1 installed on two 2008R2 servers) to authenticate users.

When I clear the user cache (with the command 'clear user-cache all') on the firewall, the ca

...

licenselu by L4 Transporter
  • 2404 Views
  • 1 replies
  • 0 Likes

Resolved! Security Policy to block Dropbox

I have created a security policy to block Dropbox traffic, but so far it is not working. In my policy I have chosen:

Source:     Destination Zone:     User:                    Destination Address:                                        Application:   

...

Resolved! Radius PSK limitation

Hello,

Can somebody from paloalto give the limitation of the shared secret word size and characters that we can use in the RADIUS Server profile ?

(I had some trouble to use complex secret with 64 characters with Windows 2K8R2 NPS))

u5128 by Not applicable
  • 2803 Views
  • 2 replies
  • 0 Likes

Resolved! Multicast stream from one VR to another.

Hi,

We have a IPTV multicast stream coming in on one of our virtual routers, and its working very well for all networks in this VR.

However, when we try to "route" this multicast stream to another VR on the same box, we can't make it work.

We have basic

...

johnd by L2 Linker
  • 2220 Views
  • 2 replies
  • 0 Likes

VPN SSL & Linux

Hello,

Here are some questions about VPN SSL Linux support :

- When do you plan to provide a Linux SSL client ?

- It would be great to not need the root privilege to be able to download and/or upgrade the VPN client.

Thanks :smileycool:

bdaussin by L0 Member
  • 10008 Views
  • 29 replies
  • 0 Likes

Committing Firewall changes

Does committing firewall changes bring the firewall down or will it remain functional while updating the configuration. I basically want to know if I can commit a NAT policy change without bringing down my tunnels

Bagar390 by Not applicable
  • 2734 Views
  • 3 replies
  • 0 Likes

Resolved! User identification

Hi,

I´m trying to configure the User Identification based on LDAP to Win2K8 Domain Server.

Apparently everything is fine - I can connect to AD Server and see the directory in User Identification -> Group Mapping Settings -> Group Map Profile

My problem

...

rrunge by Not applicable
  • 3599 Views
  • 1 replies
  • 0 Likes

Resolved! Wildcard/UCC SSL Certificates

Are there any issue(s) when using one of these for the reverse proxy (i.e. DMZ websites that use SSL) on the PAN please?

Specifically thinking of using Digicert.

  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels