General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1698 Views
  • 0 replies
  • 0 Likes

Resolved! cannot put a interface to work

hello everybody,

I configured an interface, ethernet/5, with ip 192.168.230.1/29 and connected to a device with ip 192.168.230.3/29

Theres no way i can see each other, cannot ping PaloAlto from the other device and vice versa

Ive already changed cables,

...

Resolved! Interface or gateway monitoring

I'm looking for an option which will disable an interface if a remote gateway is not available.

This option exist for ipsec vpn (tunnel monitor) but I didn't find it for an L3 interface.

For exemple, I want to use an interface for outgoing traffic and

...

lguiraud by Not applicable
  • 2640 Views
  • 2 replies
  • 0 Likes

drop-reset application list

Hello,

I found this explanation about TCP REJECT today :

"The deny action used in a security policy will either ‘drop’ or ‘drop-reset’ based on the app being used in the policy.

For most browser-based apps, it is drop-reset - this prevents the browser f

...

Duplem by L2 Linker
  • 5376 Views
  • 4 replies
  • 0 Likes

delete URL logs older then 7 days

Hello,

we have the legale requirement to delete access logs (URL Filter is set to "alert") which are older then 7 days.

Is that possible somehow?

We cant accept an answer like "please export your log, delete old stuff and import it again". The logfiles

...

jacobsen by Not applicable
  • 2043 Views
  • 1 replies
  • 0 Likes

Resolved! Zone Protection - Reject Non-SYN TCP

Hi everyone!

I've configured a zone protection profile with SYN Flood protection and SYN Cookies enabled. In the same profile I've set the option "Reject Non-SYN TCP" to "no". I've applied this profile to my untrust zone and run a commit.

When I run th

...

sturla by Not applicable
  • 7019 Views
  • 5 replies
  • 0 Likes

Resolved! Security Policy with URLs

Is it possible to create a Security Policy with the Destination address as a URL? I would prefer to use the URL to avoid using the IP in case the destination service changes it.

Thanks,

Dennis

PANAgent show user ip-user-mapping has 0 users

PANAgent seems to be running fine...

show user pan-agent statistics

reports "*connected, ok"

show user pan-agent user IDs

show all users and groups as expected

but show user ip-user-mapping

reports 0 users.

PAN-OS 3.1.8, and I have another firewall (same ve

...

TomS by L1 Bithead
  • 2900 Views
  • 2 replies
  • 0 Likes

Password Policy

Hello,

does somebody know how to setup Password Policy for management users in PAN OS 4? I am talking about minimum password length, special characters etc.

volksbank by Not applicable
  • 3221 Views
  • 2 replies
  • 0 Likes

Deny search terms

Hello Is it possible to deny search terms if a user searches a term in google eg a student types the word in boobs then clicks images

Resolved! Using AD Groups in Panorama

Hi all,

Is it possible to use AD groups in Panorama reports and monitoring? We have successfully configured user-id and group mapping on our devices, and we can utilize user id in Panorama as well. What I have not been able to do is use AD groups in P

...

Major Issues with SIP (VoIP)

Hi Guys,

I am kind of stuck troubleshooting an issue with regards to SIP traffic.  My customer integrated a new Digium Switchvox SIP VoIP in their network.  A couple of weeks ago, the telephone system wasn't working i.e. no outbound and inbound calls

...

Authentication using LDAP/AD

Hello,

I'm trying to get LDAP authentication working using Active directory. I have created an LDAP server profile, an Authentication Profile and Group Mapping settings profile. When I'm setting up the Group mappings I can go in and see the entire dir

...

smithkopel by Not applicable
  • 13434 Views
  • 17 replies
  • 0 Likes

override response page

Hi all

When accessing a URL  category that requires password in order to continue (override) , the return page from PA comes in https and not in http as in regular “Continue” or “Block” page.

Is this behavior is by design? Can it be change to regular h

...

along by Not applicable
  • 1982 Views
  • 1 replies
  • 0 Likes
  • 24217 Posts
  • 117 Subscriptions
Top Liked Authors
Labels