General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 388 Views
  • 0 replies
  • 0 Likes

Global Protect Configuration Help - Windows 7 issues

So I have a few questions.  We have netconnect working just fine for our mac users (PanOS 4.0.4) but we get an error about being unable to build nat interface on all windows 7 clients.  If I enable the global protect feature, do I need to have it ans

...

thesl by Not applicable
  • 6140 Views
  • 1 replies
  • 0 Likes

Resolved! PA dont catches Trojan JS.Redirector

Hi folks,

the Palo Alto Networks threat prevention is not able to recognize the following code as malicious:

<script>d=Date;d=new d();h=-parseInt('012')/5;if(window.document)try /
{new document.getElementById("qwe").prototype}catch(qqq){st=String;zz='al...

mhuels by L3 Networker
  • 2700 Views
  • 3 replies
  • 0 Likes

VPN WITH PIX AND FQDN

hello,

I try to migrate a vpn between pix and palo-alto

when I try to generate traffic I can see the following error :

IKE phase-1 negotiation is failed. When pre-shared key is used, peer-ID must be type IP address. Received type FQDN

I understand that m

...

alle by L3 Networker
  • 3675 Views
  • 5 replies
  • 0 Likes

Resolved! policy based forwarding to proxy

We use ntlm (CP) to authenticate our users against the PA.

We want any http traffic forwarded to a proxy. The proxy would have http access to the internet through the PA. I was thinking of using a policy based forwarding rule to forward service-http t

...

dieter_b by L4 Transporter
  • 6516 Views
  • 4 replies
  • 0 Likes

Skype only zone configuration...

Hi!

I am trying to setup a zone with Skype only configuration with the following "Application Group":

  • skype
  • skype-probe
  • web-browsing

The end result is that Skype voice works fine; however, Add Contacts feature in Skype doesn't work.

I am testing with the 5

...

gebis_it by Not applicable
  • 3222 Views
  • 4 replies
  • 0 Likes

File Uploads to Wildfire

I have seen another thread on this issue in the KnowledgePoint database; however, there was no resolution or answer to the question.  I have setup the Wildfire configuration on all of my PA500's per the documentation provided.  When matching the fil

...

Steven by L1 Bithead
  • 3674 Views
  • 4 replies
  • 0 Likes

Resolved! show config running xpath syntax

Hello,

I try to figure out the correct sytax for the xpath option of the show config running CLI-command (running PAN-OS 3.0.6).

? says:

+ xpath    xpath of the node to retrieve

but every way I tried to describe the node I want gives me a "Invalid syntax

...

PAkeeper by L0 Member
  • 9185 Views
  • 5 replies
  • 0 Likes

Bittorent session identification

On PA-500 with PAN-OS 4.0.7, I have seen a session on dashboard-top application-last hour, but in corresponding ACC and in Monitor Traffic Log I don't find a record session. There is any reason ? Thanks

lauro7 by L0 Member
  • 3365 Views
  • 5 replies
  • 0 Likes

After migration from Checkpoint, any tips?

All,

We recently migrated from Checkpoint to PANOS (via the conversion tool) and so far things are looking pretty good. The next step of our project is to convert port based rules to app type rules and I wanted to get some feedback, tips, etc from oth

...

steveo by L3 Networker
  • 4491 Views
  • 4 replies
  • 0 Likes

Service Objects and multiple ports

I have the need to create a rule with three applications, ncp, ms-update and ssl.  Two of those applications use their standard ports - ncp (524) and ms-update (80 & 443).  The ssl application uses port 13000 - not the standard 443.

  1. If I create a sing
...

UID Agent Not Recognizing Docked Laptops

Last week we depolyed a PA500 for the first time and are seeing an issue with certain computers.  The issue is affecting some users who have laptops and are using them on a docking station.  When they are docked the computer essentially has two NICs

...

polgarm by Not applicable
  • 3230 Views
  • 2 replies
  • 0 Likes

Resolved! Cannot import certificates

Hello

I know the instruction how to convert the SubCA certificate from an MS CA

the pem files are OK

but I can't import them into the PA, with 4.1.4

Te PA starts Uploadding but nothing happens

The WebGUI keep showing the upload process for over 5 min

The s

...

  • 23842 Posts
  • 112 Subscriptions
Labels