General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

GP Agent error 12044

Hello people,Today we had an issue with a user moving from our old VPN setup to our new GP agent setup.The user kept being unable to connect the agent. The error thrown was 12044.Our setup is validating users w. client certificate against user AD account.It turned out that the cause was a " ' " in the user surname. Once removed and a new user ce...

sitecore by Not applicable
  • 3648 Views
  • 3 replies
  • 0 Likes

Resolved! PAN User ID agent consuming bandwidth

I have gone through these forums, and looked at the various admin guides, but I still need help. Is there really not *detailed* guide to this software?I have the user-id agent 4.1.4 installed on two domain controllers, for HA, and the Palo Alto firewall pointing to both user-id agents. That seems to be working.The problem is that the user agen...

EdwinD by L3 Networker
  • 7971 Views
  • 7 replies
  • 0 Likes

Perfomance on PA 4060 - Huge Disappointment

We are having a poc at an ISP with a 4060 . It is a huge disppointment performance wise . We are seeing very high dataplane utilization on very small sessions. 50% on 220,000 sessions. 38% on 149,000 sessions. This is a box that is supposedly can handle 2M sessions .Palo Alto is claiming there is nothing wrong with the unit as it is performing a...

usvi by L3 Networker
  • 9443 Views
  • 16 replies
  • 0 Likes

Trouble with customizing GP Login Page

Hi,I'm trying to customize my GlobalProtect Portal Login Page. I figured a good way to start would be to export the default page from the PA, modify it, then re-import it. I started out kinda complicated, but for troubleshooting purposes I've just changed a single letter in the page (instead of saying "Palo Alto Networks" it now says "Pallo Alto...

GV27 by L1 Bithead
  • 3728 Views
  • 2 replies
  • 0 Likes

User-ID mapping lost

model: PA-500sw-version: 4.0.11PanAgent: 3.1.2Domain controller: Windows server 2003Client SO: Windows XPUser-ID mapping from AD on my customer's network work fine, but only one user, who is logged on his workstation and also on his notebook, sometime loses IP-user association and PanAgent show his IP with user "unknown".I attach an image with ...

lauro7 by L0 Member
  • 4278 Views
  • 3 replies
  • 0 Likes

PPPoE on Active/Active HA configuration

Hi,I try to configure PPPoE on Active/Active HA system (2xPA-500). Configuration went OK, but PPPoE stays disconnected. No log entries in System log. After changing to Active/Pasive mode PPPoE starts get connected.Is PPPoE supported on Active/Active HA system ?

BLepenik by L1 Bithead
  • 3017 Views
  • 2 replies
  • 0 Likes

SSL Forward Proxy - Best Practise?

Can anyone point me to a document or some guidelines on current recommendations/best practise when using forward proxy please?I have the SSL certificate in place on my clients, my main target is SSL traffic to higher risk URL categories such as web based email and social networking sites.I'm currently running 4.0.9.Thanks.

Policy order

Is it important to have the Antivus, Vulnerability and Anti-Spyware rule as the first policy?thanks

jorge by Not applicable
  • 192465 Views
  • 3 replies
  • 0 Likes

URL and Threat filter before reach squid caching

Dear All,We have an existing squid proxy which going to use as a proxy caching and we want to use PAN to perform url and threat filteration in between user and squid proxy.The end user browser proxy has been configure to point its proxy setting to this squid proxy.What will be your advice to achieve such requirements? In terms of deployment mode...

eugene by Not applicable
  • 7336 Views
  • 9 replies
  • 0 Likes

Differentiating between an Error and a URL Filtering Block for Customizing the User Experience

Hello, I am working on customizing the user experience on the PAN's that we are installing. I would like to be able to have a different look and feel when an "error" occurs rather than when a website is blocked because of the content (ie the website is a category that we block). I have read the Tech Note on Customizing Block Pages (rev 00...

Art by L3 Networker
  • 2011 Views
  • 1 replies
  • 0 Likes

Resolved! URL Filtering - Student Rights, School Rights

Our school district's attorney just forwarded me this news release: http://www.franczek.com/frontcenter-Internet_Filtering_Software_First_Amendment.html So that we don't have a similar case against ourselves. How do we make sure that we are blocking the correct site categories regarding CIPA complaince and equal rights for students? Has anyone...

polgarm by Not applicable
  • 3272 Views
  • 2 replies
  • 0 Likes

Resolved! Monitor > Logs, Add Log Filter: Is there a Filtering Criterion Equiv.-To "# Of Sessions"

Hello. Via the Monitor page, I'm trying to build a log query, to report upon all threats regarded as critical within the last 24 hours that held / conducted a minimum of 12 (twelve) sessions. I've got the first 2 (two) filtering parameters - my "critical" vulnerability sensitivity; and my time frame eq. last 24 hours. However I'm "stuck", wit...

IMgrtrU by Not applicable
  • 4993 Views
  • 5 replies
  • 0 Likes

Maximum sessions for Captive Portal

Hi Guys,On a PA-500, is there any specification for the maximum number of sessions or user logins at any given point of time for Captive Portal users? Enquiring because, there is a known environment (school with boarding as well) (staff and student VLANs) where maximum traffic passes through Captive Portal.Many Thanks,Kal

PAN Agent stability

Hi All,Is there anybody meets PAN Agent stability issue?We always install PAN Agent version 3.1.2 on Windows Server 2003, but at lease tow customer meet the issue.PAN Agent service is down once 1to3 weeksNo advnaced log can be found no matter debug is turned on or not (on PAN Agent).Regards, Bobby

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels