General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Join the Fuel User Spark Event on March 19: Dealing with Threats !

Join us at the Fuel User Group Spark Event on March 19! Get ready to ignite your cybersecurity knowledge and connect with industry experts at our upcoming Spark event hosted by the Fuel User Group. Whether you're a seasoned professional or just starting your journey in cybersecurity, this event is designed to spark inspiration, innovation, and...

kiwi_0-1709893724672.jpeg
kiwi by Community Team Member
  • 3700 Views
  • 5 replies
  • 3 Likes

Security policy matches traffic, but custom URL category doesn't work

Hello, We're running VM appliance with PAN-OS 10.1.4I've created custom URL category matching several wcard domain names, that we want to whitelist for only some LDAP users and added security policy placing it above internet access policy for all users (where URL filtering profile is applied to block URLs by predefined categories). We're decrypt...

Flang3r by L2 Linker
  • 17603 Views
  • 8 replies
  • 0 Likes

HA A/P: BGP routes synchronzation

Hi all, I have a doubt regarding the synchronization of BGP routes learnt by the active firewall.Reviewing the BGP route informationin in the active node with the following commands:> show routing protocol bgp loc-rib> show routing protocol bgp rib-out BGP seems is working fine in the active firewall, as the firewall has routes in his loc-...

Resolved! Best way of doing user-ID mapping? WMI, Winrm-http? There is also Kerberos and NTLM?

Hi, new to PA here. We just got the firewall and I'm trying to figure out what is the best way to set up User-ID mapping. I don't want to install any agents on the domain controllers and the goal is users can access Internet as long as they log into their computers with their Windows credentials, no other login required. From the User-ID screen,...

Certain TCP traffic not showing at the Azure Palo firewalls.

Certain TCP traffic not showing at the Azure Palo firewalls. There are tcp traffic from on-prem to Azure test subnet vm. The connection path is as below: on-prem user laptop -> onprem palo fw -> express route ->Azure Palo fw -> test vm. There is no NSG on any of the interfaces at Azure side. The RDP traffic from the on-prem user lapt...

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity! Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting-edge techniques, and real-world case studies. In each episode, you'll hear engaging discussions—...

jforsythe by Community Team Member
  • 1510 Views
  • 0 replies
  • 0 Likes

Issue: New Palo Altos crashing domain controller with migrated config

Morning all!Have an odd one for y'all that has defeated us so far. We are currently attempting to side-grade from PA-5250s to new PA-3440s but have experienced a showstopper twice that caused us to revert back to the PA-5250sIssue: New Palo Alto firewalls (seemingly) crash domain controllers once load hits the network (KB5035849 is uninstalled f...

Resolved! Firewall OSPF Area configuration - range or interface specification - Area 0.0.0.0 general questions...

Configuring an area 0.0.0.0 on PAN firewall (10.2 and higher). 1. Does PAN attribute 0.0.0.0 to area 0? Is that the only way to define area 0? or other options? 2. Area IP range: in cisco world, the range command implies that all connected interfaces on the router, which fall within the range, get include as LSA's in the area and start commu...

anon4all by L2 Linker
  • 3921 Views
  • 2 replies
  • 0 Likes

Connect Before Logon + Enforce GlobalProtect for Network Access + Captive portal

Hi all, we are enforcing to our devices an always on company connection, without vpn our users cannot login to their windows desktop (no local password cache), so we have implemented "Connect Before Logon" + "Enforce GlobalProtect for Network Access" but we have problems with captive portals. Is the captive portal detection working also in the p...

Resolved! Log forwarding profile in all security policies

Is there any other way to configure Log forwarding profile in all 300+ security policies in single shot. currently there is no log forwarding profile in all 300+ policies. So below method is not applicable: Not through web interface but you can export config out.It is one single xml file. Device > Setup > Operations > Export configurat...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels