General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 492 Views
  • 0 replies
  • 2 Likes

Resolved! User-ID agent 4.1.0 service logon account permissions.

User-ID agent 3.1.0 ran quite happily on our Domain Controller under a regular domain user account (no group membership apart from the default Domain Users, and I guess "Ran as service" was granted automatically during the installation).

The new versi

...

ST1985 by L1 Bithead
  • 8544 Views
  • 7 replies
  • 0 Likes

Anyone tried REVERSE PROXY on PAN

Hi,

I was just wondering if anyone was successful in implementing Reverse Proxy solution on the PAN.  As far as i know, Palo Alto does not do Reverse Proxy, but was even told that there was work around for it.  Anyone who has been successful in acheiv

...

Custom reports using different log archive

Hi all,

we are trying to create a custom report in which we want to include fields that belongs to, for exemple, the URL log database and wanted to add a field that is contained at the traffic log (bytes, for example).

Is it possible?

Best regards,

COMIP by L2 Linker
  • 2461 Views
  • 3 replies
  • 0 Likes

Captive Portal Persistence

Greetings,

A little background.  We have a wireless guest network at multiple facilities.  Currently we have Juniper wireless deployment and use their "SmartPass" product for guest authentication.  This gives us two things:

  1. Provides a splash page that
...

mrsold by Not applicable
  • 2537 Views
  • 2 replies
  • 0 Likes

Resolved! Packet Capture/Debug Flow based on an IPSec VPN

Hi

I am looking for a way doing a packet capture (or Debug Flow) with a filter based on a defined VPN Connection. The only thing I found, was a filter like "debug dataplane packet-diag set filter match ingress-interface tunnel" but with this I am not

...

User_333 by L2 Linker
  • 8913 Views
  • 4 replies
  • 0 Likes

Problem in RESTful API with predefined application

Hi,

Trying to retrieve list of predfined application with RESTfull api we recieve an error (Firefox):

ML Parsing Error: mismatched tag. Expected: </default>.Location: https://<server>/esp/restapi.esp?key=<key>&type=config&action=get&xpath=/config/prede

...

Resolved! LAN issue with PA200

Hi

gotta really wierd problem...

PA 200

configured for DHCP

eth1/2 Layer 3 IP address 10.130.8.25/24

default route via eth 1/2

eth1/2 connected to port on CISCO 2960S switch

PC connected to port on same CISCO 2960S switch

IP config IP Address. . . . . . . .

...

sue_town by Not applicable
  • 3071 Views
  • 3 replies
  • 0 Likes

VPN SSL with LDAP Group fail

Hi team, I have a problem with a OS 3.1.9.

If a try to configure VPN SSL with LDAP Groups, always I have the same error: Authentication failed: Invalid username or password.

If I change the configuration to LDAP users, athentication and connection are

...

ocampos by Not applicable
  • 1683 Views
  • 1 replies
  • 0 Likes

Resolved! DHCP Option 252 WPAD

Seeing since there is no support to push down client proxy settings via GP - does anyone know if we can set up a DHCP scope for SSL VPN clients that has/allows for option 252 WPAD support?

Thanks

Rod

djrodb by L3 Networker
  • 6667 Views
  • 8 replies
  • 0 Likes

Is there any way to monitor the state of a Virtual Wire?

We are testing vwire behavior with link state pass through enabled in our lab where it is working properly, but there is very little information to use as indicators of a transition.  Basically, all we can find in the log is the interface down messag

...

chrisp by L3 Networker
  • 3250 Views
  • 5 replies
  • 0 Likes

Global-protect clients not getting IPs

Hello,

One of ours client upgraded netconnect (4.0.8) to global-protect 1.1.2 (4.1.2).

In logs I can see that client is authenticated, but is not getting any IP. Communication is allowed so ipsec is not blocked. I've checked configuration at it seems

...

Still no way to set SPECIFIC threat exceptions???

I created this thread over a year ago...

https://live.paloaltonetworks.com/message/3636#3636

...is there still no more intuitive way to be more granular when it comes to creating threat exceptions? I'm still having the same problem I report at the bott

...

jambulo by L4 Transporter
  • 2801 Views
  • 4 replies
  • 0 Likes

Application bit-internal cannot be allowed.

How can I allow application bit-internal in my policy? This application is blocked by last rule (explicity block rule). I didn't see application bit-internal in my Object->application database and I can't use it in policy. We have PANOS 4.0.8 and app

...

darkfibre by Not applicable
  • 3690 Views
  • 5 replies
  • 0 Likes
  • 23718 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels