General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 709 Views
  • 0 replies
  • 0 Likes

Resolved! Google Translate

Is there any update on the issue discussed here - https://live.paloaltonetworks.com/message/7468

as mentioned in that thread, if you allow translation you can access sites in blocked categories.  This is despite Google including the original URL in th

...

4.1.5 withdrawn?

has 4.1.5 been withdrawn - I don't see it on the download page any longer though 4.1.4 and 4.1.6 are there.

if so, why?

Submitting Suggestions

While creating some File Blocking Profile, I discovered a particular file type I wanted to block was not available.  After searching the KnowledgePoint, I came to the realization, that we can't simply add a file type.  Other discussions, pertaining t

...

TLC_IT by L0 Member
  • 2119 Views
  • 1 replies
  • 0 Likes

tcp_drop_out_of_wnd

Hi,

on PanOS 4.0 I have to disable "tcp_drop_out_of_wnd" check with this command :

>configuration
>set deviceconfig setting tcp drop-out-of-wnd no
>commit

How to disable "tcp_drop_out_of_wnd" check on PanOS 4.1 (4.1.5) ??

Thanks,

Regards.

TCP Timeouts ... Again

I have a bunch of connection, 12 to be exact. From a webserver to a Oracle DB Server. They timeout every 2 hours. 

They pass through a Cisco ASA and a PA 4020. I've created and override rule with a custom app with no timeout. (see attached)

I'm in the

...

jickfoo by Not applicable
  • 8307 Views
  • 7 replies
  • 0 Likes

Help - Userid Responsiveness

We're at the point where we want to apply URL Filtering policies based on userid. This means its very important that Pan-Agent is accurately identifying users. We did a test and added a user to a monitored group. The policy started working properly.

...

jhickey by L3 Networker
  • 2248 Views
  • 2 replies
  • 0 Likes

Resolved! How to debug commit?

Hi folks,

does anybody know how to debug the failing commits on a Palo Alto Firewall? The onliest what i can see is "failure on pushing config to device".

user@pan> show jobs all

Enqueued                     ID             Type    Status Result Complete

...

mhuels by L3 Networker
  • 10574 Views
  • 10 replies
  • 0 Likes

Resolved! redhat ssl-vpn

Is there away to get netconnect to work with redhat?

Looking to use it with RHEL 5/6 servers.

If so does anyone have a write-up?

The client is java based, so I would guess that it should not be hard to get this integrated.

erantanen by Not applicable
  • 2138 Views
  • 1 replies
  • 0 Likes

Issue with Global Protect on 4.1

Hi guys,

This is my first Global Protect implementation and running into a snag with I think the portal piece of it.  This particular box is not the licensed product with extra features like HIP its just basically the netconnect option.  Basically I h

...

malleus by Not applicable
  • 2023 Views
  • 1 replies
  • 0 Likes

Resolved! NetConnect using AD logins - catastrophic apostrophe

Seems using non-alphanumeric chars in a username for the NetConnect login is causing an invalid user/pass error.  At least one user with the name "O'Brien".  You could argue it's not wise to use punctuation in a username, and I'd be inclined to agree

...

nwallette by Not applicable
  • 2992 Views
  • 2 replies
  • 0 Likes

SSL VPN Routing

Client SSL VPN configuration is working from client to server.  The client can ping the server no problem.  The server however, can not ping the client.  What am I missing?  The routes on the server appear to be correct, and I'm confident the packets

...

cenders by L3 Networker
  • 3075 Views
  • 3 replies
  • 1 Likes

Problem authenticating SSL VPN with eDirectory Users

Hi

I have set up a SSL VPN on a PA-500 with Pan OS 4.0.7.

The problem is that I cannot log in with certain eDirectory users. I have checked those users are in the same group as the ones that work; that group is the one allowed to log in.

I would appreci

...

emaneiro by Not applicable
  • 3499 Views
  • 5 replies
  • 0 Likes
  • 23972 Posts
  • 114 Subscriptions
Top Liked Authors
Labels