General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4142 Views
  • 0 replies
  • 0 Likes

PA2020 Web monitoring

Quick question that may have an even quicker answer. Is there any functionality to monitor users web browsing history through a Palo Alto 2020 box?And if the answer is yes then is there any functionality to perform traffic shaping? And I don't just mean block/allow, but I mean throlling if say for instance it is a youtube video or hotmail, then ...

Global Protect impacting PGP Single Sign-on

Hello,Just installed Global Protect 1.1.6 for first time and it seems to be interfering with our companies PGP Single Sign-on. Initial authentication to the System PGP works fine. Normally the system then takes you to your normal windows screen and startup begins. Since the install of the GP you have to authenticate at the normal WINDOWS login...

Resolved! PAN 2050 Front Panel Alarm

Hello,We have a PAN 2050 that the front panel alarm is red, I wantto know how can I determine which Hardware is in failure state ? from CLI orweb interface?ThanksBelal Sadozai

BSadozai by L2 Linker
  • 2796 Views
  • 2 replies
  • 0 Likes

Resolved! Performance Impact when installing new content?

Hi all,We're currently deploying a PA-2050 firewall in HA mode in our headquarters. We plan to protect all data lines entering or leaving the HQ through the new firewall - including our MPLS WAN infrastructure where we run a lot of time-sensitive Citrix applications (actually our world-wide users turned out to have an advanced sensitivity for th...

oschuler by L4 Transporter
  • 4572 Views
  • 5 replies
  • 0 Likes

Resolved! In captive portal, not asking for authentication for https traffic.

Hi All,Captive portal is working fine for http traffic( asking for authentication ), But for https traffic it is not asking for the authentication. For example if user types facebook.com, asking authentication if types https://facebook.com then it is allowing without asking for authentication. I have added both http and https services in captive...

Gururaj by L4 Transporter
  • 5559 Views
  • 6 replies
  • 0 Likes

The publisher could not be verified

I noticed that when I download programs from the Internet with Decryption turned on, the downloaded file says "The publisher could not be verified", whereas if I grab the same file off a non-decrypted connection I do not get this same message.How do I resolve this?

EdwinD by L3 Networker
  • 1919 Views
  • 1 replies
  • 0 Likes

Blocking Application Filters

I've browsed through these forums regarding the best way to block applications. I've saw the posts of folks blocking applications by app filter. I have AD integrated AD groups. These groups tie to individual Palo Alto security rules that allow any port any service as the destination, and then use group profiles to block specific categories.I a...

EdwinD by L3 Networker
  • 2251 Views
  • 1 replies
  • 0 Likes

fqdn - policies - wildcard

Hi,i want to place a policy with fqdn entrys completed with wildcards.e.g.Our PCs have names like this:LABPC01, LABPC02, LABPC03Now i want to deny the internet traffic for every PC with the name LABPC*But i also want to allow it to a special list of pcs.I wanted to use a policy with fqdn entrys - but i'm not allowed.When i want to do an address ...

axel5le by Not applicable
  • 3272 Views
  • 1 replies
  • 0 Likes

Resolved! Eicar Testvirus will not be recognized

On the website EICAT TESTVIRUS resides a lot of different kinds of eicar. Most of them will not be recognized by the Palo Alto Networks AV-Engine. The behaviour of the firewall is thereby a bit confusing. It seems: if you click on the links more then one time, you can download the virus on the second or third instance. Especially the PDF-Eicar ...

mhuels by L3 Networker
  • 11173 Views
  • 5 replies
  • 0 Likes

Resolved! Security Policy Rule for Application and URL Category

Hi,We have recently updated to 4.1.6 which gives more funtioinality regarding Security Policies.I would like to know what steps are required to mix apps and URL categories in a single policy.I had wanted to grant a user iTunes Access by Adding App-ID - 'itunes' and under the Service/URL Category - have 'Online Music'.I believe this would remove...

gaitken by L0 Member
  • 3596 Views
  • 1 replies
  • 0 Likes

FTP Brute Force attack blocked only after 13 seconds

Hello,Two months ago we correctly set up a rule to block Brute Force attacks on our FTP server in DMZ.The related information can be found here: https://live.paloaltonetworks.com/message/16977#16977We tested it manually by just entering wrong passwords quickly for the FTP server and after 10 attempts we were blocked from our own FTP server.The c...

palo alto安全防范是否支持一下功能????

具备Land攻击防范功能 具备Smurf攻击防范功能 具备Fraggle攻击防范功能 具备ICMP Flood攻击防范功能 具备地址扫描攻击防范功能 具备带路由记录选项IP报文攻击防范功能 具备超大ICMP报文攻击防范功能具备time-stamp攻击防范功能 具备带源路由选项报文攻击防范功能 具备端口扫描攻击防范功能 具备ICMP不可达报文攻击防范功能 具备ICMP重定向报文攻击防范功能 WinNuke攻击防范功能

Resolved! Pan-agent settings over the WAN

We are having some issues with our remote sites as they browse the internet through the central site however they authenticate to Domain Controllers locally in the remote sites.When we enter the remote site DC's in the pan-agent (which resides in the central site) the traffic generated by the agent when pulling the security event logs kills the ...

rds by L2 Linker
  • 9619 Views
  • 12 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels