General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4129 Views
  • 0 replies
  • 0 Likes

Multiple syslog servers under one profile

A client has set up two syslog servers as destinations on one syslog server profile, but only one of the servers is receiving data. Is that expected behavior on 4.1.3? The hope was to be able to send syslog traffic to both devices.ThanksJames

jcostello by L4 Transporter
  • 5345 Views
  • 3 replies
  • 0 Likes

Resolved! Static IP Address to User Mapping

Is there any way to statically assign a Username (ID) to an IP address on the PA? I have a very small install with no AD. There are two computers that I would like to run User Activity Reports on, but they can only be run against a User and not against an IP Address. Captive portal seems like too much of a pain to require the users to log in ...

njoyzrd by L1 Bithead
  • 3675 Views
  • 3 replies
  • 0 Likes

https://www.google.com does not work on 4.0.10

there seems to be a problem with ssl connect from PA to google.The browsers shows a timeout. It takes a couple of minutes, until i get an entry in my logfile. The logfile shows an "unknown application" first (which is denied in my company by default) and thereafter pretendedly a working "ssl" and "web-browsing" application, as you can see in the...

mhuels by L3 Networker
  • 3623 Views
  • 3 replies
  • 0 Likes

PAN AGENT CAPACITY BY VSYS

hello,I have seen the following information for pan agent capacityCapacityUser Identification capacity limits:• The PA-4000 series can support up to 64,000 concurrent users; the PA-2000 series cansupport up to 47,000 concurrent users.• Up to 640 groups can be used in policies for each virtual system (vsys)• Each UIA can connect to up to 10 Domai...

alle by L3 Networker
  • 2755 Views
  • 3 replies
  • 0 Likes

Blocking Google Drive ?

Hi,We are relatively new to Palo Alto appliances, but are wondering if we can block Google Drive already?We did some searching in the application objects database + on this forum, but we cannot find it for now...Is google drive available yet for scanning/filtering?Or how long does it normally take for P.A. for this app to be added to the availab...

Daily packet capture limit

Hello everybody,can somebody tell me, what this log entry means.And is it possible to change this limit?Apr 8 19:24:2619:24:26,,SYSTEM,general,0,2011/04/0819:24:26,,general,,0,0,general,high,"Daily packet capture limit (directory threat/20110408\, limit 131072) has been reached."ReagrdsChristian

indevis by L2 Linker
  • 4430 Views
  • 2 replies
  • 0 Likes

question about part of CPU log in mp-mointor.log.

Hi. I've generated a Tech support file on the PAN device and then look into mp-moniotor log.I can't understand the part of log during look into the mp-monitor. question is below.1. What command have a print like below on the screen? i know one of command to see the mgmt resource like below. "show system resource". but it shows different...

willstech by L3 Networker
  • 2377 Views
  • 1 replies
  • 0 Likes

idle timeout 0 not working?

We have a couple of machines that are set to display the PANOS web UI Dashboard so that we can see the current Risk Factor and System Resources, etc... so we set the Authentication Settings Idle Timeout to 0 so that the sessions do not time out, as indicated by the help. However, they still do time out. Is there something else we need to change...

Mack by L2 Linker
  • 5756 Views
  • 7 replies
  • 0 Likes

Demo Rules Examples from Real-Life???

I am looking for documentation of example rules (Real-World rules) much like Checkpoint has if you run their SmartDash board in demo mode. It illustrates a large corporation's simple to complex rules for about every rule you can thing of. A novice to veteran can learn from these example rules. I can't find anything like it in KnowlegePoint bu...

shiftkey by Not applicable
  • 3746 Views
  • 2 replies
  • 0 Likes

PAN application for Ironport updates

Hello,I have an Ironport behind my PAN. In the logs, I can see it going toward the Cisco update server.Nevertheless, the application is sometimes "web-browsing" and sometimes "http-video".Do you meet the same behavior?Regards,Guillaume Dupuis

gdupuis by Not applicable
  • 3137 Views
  • 2 replies
  • 0 Likes

IP to User Mapping Error

Hi,I'm having problems in resolving IP address to usernames. PA2050 is integrated with active directory to resolve IP address to usernames. We also create security policies based on usernames. This configuration works great in version 3.1.6 but after the upgrade to version 4.1.4 we encountered errors. Some IP addresses are unable to resolve to t...

Resolved! Question regarding initial configuration / setup

Hi, Everyone,I have a question that I was hoping I could recieve some help with; I am doing an initial configuration of my firewall (I am new to Pan-OS, and I can't seem to ping my upstream router). I have an 802.1q trunk link coming into my device with a single VLAN on it (VLAN 3357). When I do a packet capture, I see the hearbeat traffic fo...

dsulli99 by Not applicable
  • 5194 Views
  • 3 replies
  • 0 Likes

Resolved! Mac of local layer 3 VLAN interface

Hi, EveryoneI am sorry I am posting a few questions today I am still learning the PAN-OS platform and this is kind of a basic one; is it possible to tell the MAC address of a local layer 3 VLAN interface? I can ping it, and verify that the IP address is configured locally on the interface, however the MAC does not show up in the local VLAN inte...

dsulli99 by Not applicable
  • 4753 Views
  • 1 replies
  • 0 Likes

Firefox11 log details not showing up

I have updated to firefox 11 and now the log details window starts to pop up but just sits there spinning trying to display the data.I have tried this on a linux installation and windows as well. Is anyone else experiencing this and if so other than backing down version is there a fix for this?Thanks in advanceMike

mhorne by L1 Bithead
  • 5200 Views
  • 8 replies
  • 0 Likes

How to confirm Email Scheduler send test email

Hi AllI would like to set a Daily schedule report and send it by Email Scheduler, the gateway of email server profile is our smtp-relay server(win2003 smtp service), and it will transfer all email request to Exchange server, all in our environment client can send email normally, however when i complete settings and click "send test mail" button ...

  • 24336 Posts
  • 124 Subscriptions
Labels