General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA500 Configuring a Static Routing Question?

Hello all.I have a fairly easy deployment - a set of PA500s with internal trusted and external trusted zones. On the inside, they are currently connected to a router hsrp pair and on the outside pointing to another brand FW. I have only a handful of networks inside, so I have static routes pointing to the inside/outside configured in the VR area...

dudesdad by Not applicable
  • 3223 Views
  • 2 replies
  • 0 Likes

Source NAT confusion

I am trying to provide for some 1-to-1 NAT on our PAN, which I thought we be an easy task. However, my configuration insist on using the interface IP address for outbound connections. Here is my setup.Untrusted Network Interface IP: x.x.x.10/29Trusted Network Interface IP: y.y.y.4/16Mail Server Public IP: x.x.x.12/32Mail Server Private IP: y.y...

cdpadmin by Not applicable
  • 4684 Views
  • 5 replies
  • 0 Likes

PA-5020 4.1.5 issue

Hello,Anyone else experienced any issues when upgrading to version 4.1.5?We have done one upgrade to 4.1.5 and the PA-5020 just goes into a reboot cycle.After doing the initial commit the firewall reboots and the cycle repeats.Doing a factory reset from maintenance did not help.But we tried one more thing.Since this PA-5020 does have an redundan...

How do I allow udp port 33001?

Hello All,I have encountered an issue where a downloaded client installed on Internet Explorer called Aspera client for downloading video content experienced an error.It states to check the UDP port and firewall based on code 15.Since this is application based (HTTP), where is the most effective place to allow and create the rule for the client ...

User-ID Agent AD Group Limitation?

All,Digging around in the various docs I've found I can't seem to find an answer to this question so I'll ask here..I'm curious if there is a limit on the number of AD groups per user that the Agent can handle? I'm worried we might run into some limitation cause our group situation is really out of control with no fix in sight..Thanks!-Steve

steveo by L3 Networker
  • 4254 Views
  • 3 replies
  • 0 Likes

Vulnerability understanding

I'd like to figure out the meaning of a vulnerability alertlet say that I have an alert like:Severity Name ID Directioncritical Adobe Flash Player Bounds Checking Remote Code Execution Vu...

Resolved! Comments when exiting GP client

When users disable/exit the Global protect client on their computers. They are forced to whrite a comment/reason. Where are thoese comments logged? Can i read them somewhere? //Karl

Captive Portal with Applications

Hi!When not logged in with Captive Portal, it seems like all other Applications are allowed to pass through except http traffic. Is it possible to setup Captive Portal so that it actually blocks ALL traffic before being authenticated with Captive Portal?Thx!

gebis_it by Not applicable
  • 2682 Views
  • 2 replies
  • 0 Likes

Problem with AD authentication - username change

Hi, We had to change the username of one of our colleagues in the Active Directory. Now our appliance (PA-500 running 4.1.4) can see the changes but only in a strange way. When I try to create a rule with this user and I try to list the users with [domain]\ I can see only the old username (ana.cvetkovska), but when I try to list the users with [...

Captive portal

HelloI am new to the administration of a PA 500. I would make a captive portalfor my users. The documentation of the manual I have no very clear. I do not look very complex, something functional and easy. I wonder if there is atutorial about it. The AP 500 is VWire mode.Thank you very much

Configuring VPN with redundant ISP

Hi guys,I want to know it`s possible to configure a VPN with redundant ISP.I configure the VPN to use a 1 ISP , when this 1 ISP fail , my vpn go to my 2 ISP.It`s possible to do it ?Best Regards.Thiago Lima.

Thiago by L3 Networker
  • 4117 Views
  • 5 replies
  • 0 Likes

SSL-Gateway

I'm using a PA-500 to connect our network to 2 ISP's. I'm using policy based forwarding which works great but if I add a static entry for ISP-2 it breaks SSL-VPN access. I have a public IP assigned to a loopback which is in the untrust zone. It works if I remove the static route for ISP-2 and replace it with a static route for ISP-1 which is ...

Content-ID Container Pages

Has anyone done anything with the Content-ID container pages to control the URL logging? Are you using a Custom 'URL Content Types' list? What are the supported URL Content Types? The documentation is sorely lacking .Thanks, Jeff K

Jeff_K by L2 Linker
  • 5844 Views
  • 3 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels