General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 436 Views
  • 0 replies
  • 2 Likes

Panorama Logging Traffic Flow

Hi All,

Does anyone have any indicative figures of the amount of data that flows from a PAN apppliance to Panorama?

Say a 4050 running at a consistant 50%, and logging everything = xMB/day of logs?

I'm trying to calculate what will be required to have P

...

KatanaNZ by L3 Networker
  • 3343 Views
  • 3 replies
  • 0 Likes

Resolved! source and destination ports

Under security rules does service refer to source port or destination port and what is the best way to define both source port and destination port in a rule on version 3.1.6

ailfionn by L0 Member
  • 3277 Views
  • 3 replies
  • 0 Likes

Upgrade to 4.0.4 image version failed

Hi to all,


We've two PaloAlto firewalls PA-2020 with 3.1.6 software image version and HA licensed.Both have active gold maintenance support. Last week we tried to update to the last version 4.0.4 and the upgrade process failed.

Step 1

We started with th

...

How to setup multiple SSL-VPN tunnels

I'm hoping I'm missing something obvious here...is there a good way to support SSL-VPN access for different types of users who require different access and use different authentication schemes?

I am trying to setup multiple SSL-VPN tunnel configuratio

...

Resolved! Maximum life-time of SSLVPN

Hi all.

I have 3 questions about SSLVPN session time-out.

1. MAXIMUM LIFE-TIME of SSLVPN session?

2. What are the default values of Login life-time and Inactivity logout if it isn't set.

3. The meaning of "Logout/Expiration" and "TTL" come out by "show s

...

itnsystem by Not applicable
  • 3103 Views
  • 3 replies
  • 0 Likes

bypassed PAN box using free proxies

We are tested PAN 500 NFR in our lab . Did a search for youtube proxy on google and picked the first listed . Used them and bypassed the PAN box and was able to get to facebook and yahoo mail . I couldn't get to these sites through my browser directl

...

usvi by L3 Networker
  • 2932 Views
  • 4 replies
  • 0 Likes

PA500 split tunnelling DNS question

Hi

Have a PA 500 set up for split tunnelling - so clients access internet locally and all other traffic is passed over VPN tunnel to our office

I have DHCP set up on PA box so clients get primary DNS server (local ISP one) and secondary DNS (office one

...

sue_town by Not applicable
  • 3109 Views
  • 7 replies
  • 0 Likes

Gaming devices behind PAN firewall

We are using Capitive Portal for students on our campus. All students' devices including gaming devices get DHCP from a PA2050 and these IP ranges require CP. XBox seems to get DHCP and tries to connect to XBox Live servers, but fails. We don't see t

...

kumara by L0 Member
  • 1879 Views
  • 1 replies
  • 0 Likes

Resolved! Issues with email reports on iOS devices

So interesting issue don't know if others have the same issue.  Email reports that are generated in the firewall and sent via email on schedule.  When I view the PDF on the iPad (newest version of iOS) there is no text in the report it only has the g

...

kkeeton by L2 Linker
  • 2292 Views
  • 1 replies
  • 1 Likes

uid-gids-cache timeout

Hi there,

we use the pan-agent installed on a DC to read out the users of some AD groups. Works fine so far. The only problem we got is, that if a user is removed from an AD group, I will always have to run the "clear uid-gids-cache" command on the de

...

Cert issue with Captive Portal

We have installed a Comodo wildcard cert on our 2050 for use with the SSL-VPN and Captive Portal.  IE and Chrome are fine, but Firefox always says the it can't verify the authenticity of the cert.  I remember reading in another post that someone had

...

bvest by Not applicable
  • 1874 Views
  • 1 replies
  • 0 Likes

Permanently cached user to IP

Did a search, but nothing seems to answer my question:

I would like input from more knowledgable folks on the problem described - the permanent caching of a "good" account on computers that are kiosk mode and logged in with "ignored" accounts.  See ex

...

jasbeck by Not applicable
  • 4179 Views
  • 8 replies
  • 0 Likes

RDP incomplete session

RDP worked before the installation of PAN 500. Now I'm having an incomplete session on RDP (TCP handshake is dropping). How do I fix this:

760     t.120          DISCARD FLOW  NS   172.21.196.181[4483]/l3-trust/6  (70.159.69.130[2588])
vsys1           

...

Resolved! Apps vs URL Profile - block application

Hi all,

I tested this strange (imho) behaviour with PAN 2020 4.0.3:

1. create a first security policy with ssl, http-proxy, dns but without web-browsing application (as you can see in 1.jpg) with action ALLOW

2. create a following security policy with f

...

  • 23699 Posts
  • 110 Subscriptions
Top Solution Authors
Labels