General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! UserID Agent - Required User Rights

HiI'm in the process of implementing the UserID Agent into a Windows 2008 DomainMy goal is to have a single user in the AD for all features required by PaloAlto.So I created a "panagent" user and added it to the "EventLog Readers" group, so it has access to the event logsI the configured the Agent to use this user in it's service settings to sta...

u13550 by L3 Networker
  • 8333 Views
  • 2 replies
  • 1 Likes

GlobalProtect without license on 4.1.1

I have a problem with global protect without license i have configured it as in tech notes says, but when i commit i get the following message.•Warning: No valid GlobalProtect portal license!(Module: useridd)When i launch Global Protect Client it not connets.In GlobalProtect Client I get the following Logs.(T4988) 01/13/12 15:36:45:998 Error(808...

LDAP group based rules versus Policy based URL filters

I am coming from an M86 (8E6) R3000 and Surfcontrol install to the Palo Alto URL filtering. I have multiple AD groups in my AD that are specific to URL filtering on the M86 R3000.I am re-using those groups on the Palo Alto to recreate my functionality... One group is "Blocked Internet Users." I have LDAP bound to my PA through my GC servers...

EdwinD by L3 Networker
  • 3876 Views
  • 2 replies
  • 0 Likes

Outlook Anywhere

we recently moved to Palo Alto for our firwall needs. Is it possible to get Microsoft's Outlook Aynwhere to work with the Palo Alto firewall?Thanks

Resolved! Threat Protection

I hope you may be able to answer a couple of quick questions for me as i am planning on switching Threat Protection on in the next few weeks.1. When we turn on Threat Protection i remember you saying that the throughput for the dataplane is cut in half, Is there any way of monitoring the throughput of the dataplane?2. When Threat protection ...

BBHLTD by Not applicable
  • 2527 Views
  • 1 replies
  • 0 Likes

Resolved! Brute Force Attemps - How many attempts exactly?

If you look in the Threat Vault you can see there are many different brute force sigs listed (ssh, rdp, postgres, smb, etc..).My issue is the descriptions dont mention how many attempts it takes to trigger this alert? is it 5 or 50 or 5000? 5 im not really worried, 50 attempts and I'm definately going to do some digging. Am I correct that this i...

choff123 by L3 Networker
  • 3674 Views
  • 2 replies
  • 0 Likes

Resolved! Strange Sharepoint upload problem.

Hi,I have a bit of a strange one hence the strange question.I have a user who wants to upload files to a company's sharepoint website. Now as my rules stand currently they are not allowed to upload or use certain web applications.I tried making a custom rule just for testing purposes on a machine with the same ip range as the user in question an...

Resolved! Problem installing PAN User-ID agent V 4

We currently have User ID agent 3.1.2 installed on my 2 domain controllers and I am trying to upgrade them to V 4.1.4-3. Every time I try to install it I get it failing to install. I get the errors below in the logs.07/23/12 10:57:55:960[ Info 1775]: UA: service is already stopped. 07/23/12 10:57:56:038[Error 1374]: Start service fails with erro...

is it possible to export firewall rule only??

Hi all.Is it possible to export security policy with CSV, PDF or txt format?? I can’t find any export menu only for firewall rule.If it is possible, is it able to modify that exported firewall rule??And then is it possible to import modified firewall rule to PA device?? Customer wants to review their firewall rule with readable file format.Of co...

willstech by L3 Networker
  • 13833 Views
  • 19 replies
  • 0 Likes

Lot of 'insufficient-data'

Hello,We see a lot of 'insufficient-data' traffic on our firewall and we couldn't find any reason so far. Does anyone have a good idea on how we can troubleshoot the issue?If we click on the insufficient-data bar we get redirected to the ACC but it doesn't show much there...Thanks,Oliver

oschuler by L4 Transporter
  • 8979 Views
  • 6 replies
  • 0 Likes

CNSE Anyone?

Just wondering if anyone out there has done the CNSE and can offer any advice regarding recommended reading etc?Thanks

brownn by L0 Member
  • 16597 Views
  • 27 replies
  • 1 Likes

DMZ Setup

I'm in a position where I need to move a device that is currently inside my network to a DMZ on my Palo 2050. Which puts me in a position where I need to create a DMZ on my Palo. Does PA have a good document for creating a DMZ? I haven't been able to find one searching the forums.

interface failover on PA500

Since link aggregation (LACP or etherchannel) is only supported on PA4000++ I want to build a simple interface-failover / interface-group setup (like any other enterprise firewall allows even on low-end devices).groupTo do this I would do the following:1. change interface mode to Layer2 on both interfaces making up the interface-group2. create a...

ctr_ts by L1 Bithead
  • 4123 Views
  • 1 replies
  • 0 Likes

Resolved! Does WildFire work in "Tap" mode?

We have had WildFire turned on for almost a week. In the Data Filtering logs, it has "forwarded" numerous "PE" files and only 1 "PE" file was logged as "wildfire-upload-success". That 1 file happened to be coming through the interfaces that are set to Virtual Wire. All of the other files that say "Forward" are coming through "Tap" mode.1) Can...

jambulo by L4 Transporter
  • 5526 Views
  • 3 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels