General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 2947 Views
  • 2 replies
  • 14 Likes

VPN SSL with LDAP Group fail

Hi team, I have a problem with a OS 3.1.9.

If a try to configure VPN SSL with LDAP Groups, always I have the same error: Authentication failed: Invalid username or password.

If I change the configuration to LDAP users, athentication and connection are

...

ocampos by Not applicable
  • 1519 Views
  • 1 replies
  • 0 Likes

PAN Agent AD 3.1.2 install on Windows 2008 r2 64 bit

  • Install on a Domain Controller as a Domain Admin
  • Right click on the PanAgent-3.1.2 installer
    • Go to the Compatibility tab
    • Check "Run this program in compatability mode for:  Previous version of Windows"
    • Click Apply, OK
  • Run the installer
  • Open services.msc
    • Ope
...

svse by Not applicable
  • 1340 Views
  • 0 replies
  • 0 Likes

Resolved! DHCP Option 252 WPAD

Seeing since there is no support to push down client proxy settings via GP - does anyone know if we can set up a DHCP scope for SSL VPN clients that has/allows for option 252 WPAD support?

Thanks

Rod

djrodb by L3 Networker
  • 5673 Views
  • 8 replies
  • 0 Likes

Is there any way to monitor the state of a Virtual Wire?

We are testing vwire behavior with link state pass through enabled in our lab where it is working properly, but there is very little information to use as indicators of a transition.  Basically, all we can find in the log is the interface down messag

...

chrisp by L3 Networker
  • 2776 Views
  • 5 replies
  • 0 Likes

Global-protect clients not getting IPs

Hello,

One of ours client upgraded netconnect (4.0.8) to global-protect 1.1.2 (4.1.2).

In logs I can see that client is authenticated, but is not getting any IP. Communication is allowed so ipsec is not blocked. I've checked configuration at it seems

...

Still no way to set SPECIFIC threat exceptions???

I created this thread over a year ago...

https://live.paloaltonetworks.com/message/3636#3636

...is there still no more intuitive way to be more granular when it comes to creating threat exceptions? I'm still having the same problem I report at the bott

...

jambulo by L4 Transporter
  • 2414 Views
  • 4 replies
  • 0 Likes

Application bit-internal cannot be allowed.

How can I allow application bit-internal in my policy? This application is blocked by last rule (explicity block rule). I didn't see application bit-internal in my Object->application database and I can't use it in policy. We have PANOS 4.0.8 and app

...

darkfibre by Not applicable
  • 3283 Views
  • 5 replies
  • 0 Likes

Trouble setting up Globalprotect

Hello,
I'm tring for a week now to configure Global Protect. And have only been partially successful.

My config is PanOS 4.1.1 and GP client 1.1.2 on PA 2050 Boxes. No GlobalProtect Licence.

I encountered 2 Problems which I can't solve.

1.
I have configur

...

PA 5000 series users

Is anyone else running this new hardware platform besides my company?  We are running into a huge amount of issues and I would like to know if it's just us or not.

Creating Zones (Sub-Zones) on PA-500

Hello,

This question might sound very stupid, but never mind: 

I have a PA-500 configured which does a specific job which does layer 3 and that requires creating a lot of zones in-order to differentiate the traffic ( as per my understanding, zones are

...

SSL Over-Ride Page

Hi,

Anyone had any luck with getting the SSL URL Over-ride page to display without a certificate error?

If I have 'transparent' mode enabled for this function I get a certificate error (it appears to replace my URL with the IP address, port 6083, which

...

apackard by L4 Transporter
  • 1435 Views
  • 1 replies
  • 0 Likes

Virtual Routers as High Availability

We have a less critical PA firewall system connected to an HSRP pair on the internal interface and an HSRP pair on the external interface.

What is the best way to configure these systems to ensure the most availability of the routes so traffic can con

...

blogspot.com application

Hello,

I'd like to differenciate blogspot.com websites that contain adult content from others blogspot.com sites.

I noticed  that blogspot.com adult content sites redirect the requested url to a page for content acceptance.

Is possible to block this beh

...

  • 24033 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors