General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Source Address/Source User

When both a source address and a source user are specified, is the rule match

  1. source address AND source user?
  2. source address OR source user?

My guess is #1, but I can't find documentation to back that up.

Thanks,

Bart

user group mapping

Using PanOS 4.1.2 on 5020

listing group mapping:

show user group name "<DOMAIN>\<GROUP NAME>"

we get something like this

[1     ] <DOMAIN>\<name>.<surname>

....

though in "user id identification->group mapping settings" under "user objects"

we discretely ch

...

mpaskevic by Not applicable
  • 3887 Views
  • 1 replies
  • 0 Likes

Intercept DNS requests

Hi all,

I've read in an article that it's possible to intercept DNS requests with DNS proxy without setting PA IP address as the computer DNS Server.

Following this article, I've enabled DNS proxy in a PA interface (inside), redirecting DNS request to

...

SYSTEM ALERT : high : SSL connect error

Have any body got such error message as below:

domain: 1
receive_time: 2012/02/13  19:10:00
serial: 0002C123456
seqno: 0
actionflags: 0x0
type:  SYSTEM
subtype: general
config_ver: 0
time_generated: 2012/02/13  19:10:00
vsys:
eventid: general
object:
fmt: 0
id:

...

Apostrophe in user name breaks query builder

Hi all,

I have a username in my organisation that is domain\john.o'neill and I'm finding that when I try to do a query such as (user.src eq 'domain\john.doe') it's fine, but when I put in (user.src eq 'domain\john.o'neill'). I appreciate that this is

...

UKRB by L3 Networker
  • 1890 Views
  • 1 replies
  • 0 Likes

PAN 500 - 4.1.2 - Bypass Mgmt Interface

Hi,

I am pretty new to PAN Firewalls, and my question is really basic.

I would like to use only two interfaces on my Firewall : ethernet1/7 as my Lan and ethernet1/8 as my Internet Acess.

I would like to avoid using Mgmt Interface port.

I have found a th

...

Resolved! Qos Guaranteed

Hi, all we would like to better understand the QoS for setting "guaranteed"

The question is: the "guaranteed" is pre-allocated or it's dynamic configuration?

Suppose to have:5 Mbps of total bandwidth available; if we set guaranteed to 3 Mbps for calss

...

vzit by L1 Bithead
  • 3717 Views
  • 2 replies
  • 0 Likes

Resolved! g.ceipmsn.com

Has anyone dealt with this url before? It seems like it's trying to call home as soon as my machine login and it's reating some issue with some of my user. Wonder if Palo can recognize it for now it just saying web-browsing app.

thanks.

friento by L3 Networker
  • 2726 Views
  • 2 replies
  • 0 Likes

URL Filtering - DNS Proxy

Hi,

I have the PAN devices in the main datacentres that do DNS lookups for all clients globally. What I am trying to figureout is how to have those servers forward to the PAN and the PAN proxy off to external servers then filter the returns based on a

...

bcsgroup by L2 Linker
  • 3620 Views
  • 5 replies
  • 0 Likes
  • 23699 Posts
  • 105 Subscriptions
Top Solution Authors
Top Liked Authors
Labels