General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4466 Views
  • 0 replies
  • 0 Likes

delete URL logs older then 7 days

Hello,we have the legale requirement to delete access logs (URL Filter is set to "alert") which are older then 7 days.Is that possible somehow?We cant accept an answer like "please export your log, delete old stuff and import it again". The logfiles are not allowed to leave the appliance.Thanks in advanceJörg

jacobsen by Not applicable
  • 2246 Views
  • 1 replies
  • 0 Likes

Resolved! Zone Protection - Reject Non-SYN TCP

Hi everyone!I've configured a zone protection profile with SYN Flood protection and SYN Cookies enabled. In the same profile I've set the option "Reject Non-SYN TCP" to "no". I've applied this profile to my untrust zone and run a commit.When I run the CLI command show session info i noticed that under session setup TCP - reject non-SYN first pac...

sturla by Not applicable
  • 8469 Views
  • 5 replies
  • 0 Likes

how to allow the access face book , but block the other social networking sites

Hi,I am testing paloalto firewall and have a basic question. How to enable accessto face book to some users , but block the other social networking sites.I setup a default policy to all users and my default URL policyis to blocked social networking. Then I created another policy for a group of people, and on application levelchoose face book an...

u13037 by Not applicable
  • 8119 Views
  • 7 replies
  • 0 Likes

Resolved! Security Policy with URLs

Is it possible to create a Security Policy with the Destination address as a URL? I would prefer to use the URL to avoid using the IP in case the destination service changes it.Thanks,Dennis

PANAgent show user ip-user-mapping has 0 users

PANAgent seems to be running fine...show user pan-agent statisticsreports "*connected, ok"show user pan-agent user IDsshow all users and groups as expectedbut show user ip-user-mappingreports 0 users.PAN-OS 3.1.8, and I have another firewall (same version) using the same PANAgent without issue.Any/all thoughts/comments greatly appreciated. Best...

TomS by L1 Bithead
  • 3229 Views
  • 2 replies
  • 0 Likes

Password Policy

Hello,does somebody know how to setup Password Policy for management users in PAN OS 4? I am talking about minimum password length, special characters etc.

volksbank by Not applicable
  • 3573 Views
  • 2 replies
  • 0 Likes

Deny search terms

Hello Is it possible to deny search terms if a user searches a term in google eg a student types the word in boobs then clicks images

Resolved! Using AD Groups in Panorama

Hi all,Is it possible to use AD groups in Panorama reports and monitoring? We have successfully configured user-id and group mapping on our devices, and we can utilize user id in Panorama as well. What I have not been able to do is use AD groups in Panorama. I get the "unknown group" error. I have seen a couple of threads discussing Panorama get...

Major Issues with SIP (VoIP)

Hi Guys,I am kind of stuck troubleshooting an issue with regards to SIP traffic. My customer integrated a new Digium Switchvox SIP VoIP in their network. A couple of weeks ago, the telephone system wasn't working i.e. no outbound and inbound calls were possible. In the beginning I thought it was something issuw with their providers including ...

Authentication using LDAP/AD

Hello,I'm trying to get LDAP authentication working using Active directory. I have created an LDAP server profile, an Authentication Profile and Group Mapping settings profile. When I'm setting up the Group mappings I can go in and see the entire directory tree and pick groups so I know that it is connecting the the AD server and pulling informa...

smithkopel by Not applicable
  • 15832 Views
  • 17 replies
  • 0 Likes

override response page

Hi allWhen accessing a URL category that requires password in order to continue (override) , the return page from PA comes in https and not in http as in regular “Continue” or “Block” page.Is this behavior is by design? Can it be change to regular http like any other response ?Alon

along by Not applicable
  • 2199 Views
  • 1 replies
  • 0 Likes

arp limit

hello whats the arp limit on the 500 device? is it 500? if so whats a work around? mark

Panorama Licensing

Do I still need to purchase a license for Panorama if I only want to make use of the log forwarding functionality. It would be useful if I could forward logs from my PA-4020 to a Panorama installation so that I can store more than a couple of days worth of traffic / threat logs etc. I only have a pair of HA active/passive PA's so I don't need an...

debsPal0 by Not applicable
  • 2285 Views
  • 1 replies
  • 0 Likes

Resolved! Port masking

Hi Everybody,Is there a way to implement port masking on a PA-200?I have an application that comes from the internet on a different destination port than the default port and I need the PA to change this port back to default value.Example:Http requests come to the PA on the port 1234 and the PA forwards this request to the server on the inside n...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels