General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SNMP OID for Management Plane Load

Hi,Has the MIB OID for the Management Plane loading changed in PANOS4.x?I'm trying to poll my PA's and I'm pulling back Data PLane loading but getting an error on the DP OID (25.3.3.1.2.1)Ta!

apackard by L4 Transporter
  • 4733 Views
  • 3 replies
  • 0 Likes

A commit is pending. Please try again later.

HiI upgraded a few things, and all looks like they are completed, but I can't commit changes now - where can I see what the box is doing and progress?URL filtering database was upgraded from version 3734 to version 3735 by the auto-update agent11/09 09:55:35RASMGR daemon configuration load phase-1 succeeded.11/09 09:54:44IKE daemon configuration...

FlexyZ by L3 Networker
  • 7172 Views
  • 4 replies
  • 1 Likes

Configuring Virtual Route in 4.1 default gateway

I was trying to enter default gateway in Virtual Route when I commit it , it is asking to enter canont find interface.I use to configure this in 3.1 same no problem.Can anybody help tell me why ?Thanks,

BPA by L0 Member
  • 2651 Views
  • 1 replies
  • 0 Likes

Exchange 2010 NLB Cluster

I have a NLB Cluster configured for our Exchange 2010 environment. I have manually added the ARP entry for the Cluster to the interface of the PA. Everything works fine, until you make any change to the PA and commit it. Once you commit it, the PA can no longer ping the Exchange cluster and the entry in the ARP table is not present. All traffic ...

Steven by L1 Bithead
  • 11830 Views
  • 19 replies
  • 0 Likes

Natting Internal Hosts to a differente ISP`s

I'm trying to find documentation and/or any help to see if PAN firewalls are capable of NATing Two external ISP`s to a differents hosts IP.My scenario:My default gateway is 187.x.x.xWhen i try to make a NAT with the seconde ISP 189.x.x.x , i don`t know but don`t work.When i send a netstat at my HOST on NAT , the server don`t receive the SYN to s...

Thiago by L3 Networker
  • 3752 Views
  • 5 replies
  • 0 Likes

Resolved! How to monitor bandwidth on Internet interface

I'm looking to monitor the bandwidth of the Internet facing interface (ethernet 1/8) of our PA-500 through SNMP (using Solarwind IPMonitor), but am unable to find what OID to use.I've found several documents and lists, MIB's etc with various OID entries, but cannot find the right one for bandwidth.The reason I want to monitor it, is that the fir...

lhank by L0 Member
  • 18185 Views
  • 7 replies
  • 0 Likes

Problems with PA-2050

hello friends....I have a PA-20-50 configured as content filtering and is synchronized with a pan-agent, the problem I have is that the device is completely disconnected after 10 minutes and only restarting again operate.Know if any physical detail or firmware version, because neither the administration interface responds.Device:PA-2050Firmware:...

ljuarez by Not applicable
  • 3062 Views
  • 4 replies
  • 0 Likes

Monitoring PA4020 with Cacti

Hi,Has anyone managed to set up Cacti to manage the system resources, Mem, CPU, Sessions, Connections and so on?I have tried the Netcreen tips as per https://live.paloaltonetworks.com/message/2968#2968But this didnt help...Any other tips?Or can anyone suggest a monitoring tool thats better than Cacti?Richard

onesj by Not applicable
  • 4592 Views
  • 2 replies
  • 0 Likes

AIM-MAIL dependency

After a recent APP-ID update, AIM-MAIL is sqwauking about not having imap, smtp and pop3 dependencies enabled. Users still get access to their webmail, but I'd like not to continue getting the below warnings. Ideally, I'd like PA to re-address this APPs dependencies. Anyone else dealing/dealt with this?- <response status="success">- <r...

AD/LDAP admin authentication in 4.1

Hi all,does anybody have an exmple of howto authenticate a user based on it's group membership against active directory?We have 3 kind of groups in AD which should represent the access level.Could someone please post a small summary how to achieve this.I tried alreday to setup LDAP Server Profile and the Authentication Profile but in the authent...

muellerm by Not applicable
  • 6989 Views
  • 7 replies
  • 0 Likes

Object Reports or comapre groups option

Is there a way to print the details of a URL filter group or an Application Filter group? How about the ability to comapre 2 URL filtering groups or 2 Application groups?We have 8 different URL filtering groups and 8 different Application filtering groups.For example, recently I was asked "What URL filtering categories are blocked in the "All Te...

Captive Portal for AD Users

Hello, I'm seeing an issue currently where a handful of my hundreds of AD users are being directed to the CP landing page despite their workstations being on our domain, and with valid AD user accounts. They are all on Macs and have the same configuration as every other mac. If I check our DCs for the user security log entries I can see the nece...

Conde01 by L1 Bithead
  • 4686 Views
  • 5 replies
  • 0 Likes

PA-500 throughputs?

I realize that is a difficult question to answer. What kind of maximum throughputs are people seeing with their PA-500s?For example: I monitor our firewall (not a PA) using PRTG via SNMP and see a fairly constant 20 Mbps with some 30-45 minute spikes up to 35 Mbps. Nights I see 30+ constantly (we are a boarding school and their is a lot of str...

XML Interface to PAN Agent

HiWe are having a lot of issues with using the PAN Agent scraping the wrong user / ip information from our AD logs as we also have a mixture of local user logins and remote desktop RDP connections which change the user's login / ip address association which I'm sure you are all aware of.I'm aware that the UID Agent that is used for E-Directory L...

ERIKS by L1 Bithead
  • 3906 Views
  • 2 replies
  • 0 Likes

Skybox unable to add Palo device due to (Host without primary interface) error

Have this error appearing only on Palo's with multiple Vsys. Devices without singular Vsys will import in to Skybox without any issue.Anyone using Skybox and seeing similar or know if there is a particular configuration point on the Vsys we may have missed ? We are in the process of deploying the Palo's in to a live environment so are quite ne...

gawainuk by Not applicable
  • 4065 Views
  • 2 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels