General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


PA500 split tunnelling DNS question


Have a PA 500 set up for split tunnelling - so clients access internet locally and all other traffic is passed over VPN tunnel to our office

I have DHCP set up on PA box so clients get primary DNS server (local ISP one) and secondary DNS (office one


sue_town by Not applicable
  • 7 replies

Gaming devices behind PAN firewall

We are using Capitive Portal for students on our campus. All students' devices including gaming devices get DHCP from a PA2050 and these IP ranges require CP. XBox seems to get DHCP and tries to connect to XBox Live servers, but fails. We don't see t


kumara by L0 Member
  • 1 replies

Resolved! Issues with email reports on iOS devices

So interesting issue don't know if others have the same issue.  Email reports that are generated in the firewall and sent via email on schedule.  When I view the PDF on the iPad (newest version of iOS) there is no text in the report it only has the g


kkeeton by L2 Linker
  • 1 replies

uid-gids-cache timeout

Hi there,

we use the pan-agent installed on a DC to read out the users of some AD groups. Works fine so far. The only problem we got is, that if a user is removed from an AD group, I will always have to run the "clear uid-gids-cache" command on the de


Cert issue with Captive Portal

We have installed a Comodo wildcard cert on our 2050 for use with the SSL-VPN and Captive Portal.  IE and Chrome are fine, but Firefox always says the it can't verify the authenticity of the cert.  I remember reading in another post that someone had


bvest by Not applicable
  • 1 replies

Permanently cached user to IP

Did a search, but nothing seems to answer my question:

I would like input from more knowledgable folks on the problem described - the permanent caching of a "good" account on computers that are kiosk mode and logged in with "ignored" accounts.  See ex


jasbeck by Not applicable
  • 8 replies

RDP incomplete session

RDP worked before the installation of PAN 500. Now I'm having an incomplete session on RDP (TCP handshake is dropping). How do I fix this:

760     t.120          DISCARD FLOW  NS[4483]/l3-trust/6  ([2588])


Resolved! Apps vs URL Profile - block application

Hi all,

I tested this strange (imho) behaviour with PAN 2020 4.0.3:

1. create a first security policy with ssl, http-proxy, dns but without web-browsing application (as you can see in 1.jpg) with action ALLOW

2. create a following security policy with f


HA Sync issues with content updates

I am running a pair of PA-4020s in HA mode on PAN OS 3.1.8. For about the last three or four Threat and App Content updates I have had sync issues. I have the active PA downloading and then syncing the content to the passive PA. This worked fine unti


Base64 encoded HTTP traffic.


I was reading the 2011-2012 buyers giude. There is a statement that describes Base64 encoded HTTP messages , used in command and control traffic for malware.

The bot sets the User-Agent header value to “inter easy” and also receives a scrambledBase


AD/LDAP Server authentication

Does anyone have any tips for getting AD/LDAP bind request working at the server.  I have the PaloAlto sending and receiving the bind request to authenticate, but the server reply packet says the credentials are invalid (error code 52e - invalid cred


sajens by L0 Member
  • 1 replies

Simple Policy Question

This is a simple one, but I couldn't find it specifically stated in the manual.

When I define a security policy, are the Zone and Address exclusive of each other?  In other words, if I select a zone,it requires I put in specific IP's or select Any.  I


cmaier by L1 Bithead
  • 3 replies

Resolved! URL Category priority


I am wondering what will happen if one URL is in two different categories. Especially if one is configured to block, the other to pass the request.

I don't know if this can happen within predefined categories (from BrightCloud), but as i am able to


User_333 by L2 Linker
  • 3 replies
  • 23710 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors