General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4123 Views
  • 0 replies
  • 0 Likes

user group mapping

Using PanOS 4.1.2 on 5020listing group mapping:show user group name "<DOMAIN>\<GROUP NAME>"we get something like this[1 ] <DOMAIN>\<name>.<surname>....though in "user id identification->group mapping settings" under "user objects"we discretely choose"Object Class: person""User Name: sAMAccountName"and browsin...

mpaskevic by Not applicable
  • 4401 Views
  • 1 replies
  • 0 Likes

Captive Portal not working in V-Wire mode on version 4.1.2

Hi Guys,Scenario: Palo Alto installed in Virtual Wire mode between HP 5412 L3 switch and Threat Management Gateway (TMG) simliar to ISA which is also a Proxy Server with port 8081. Traffic passes through Palo Alto for content filtering and works fine (10.0.0.0/8). Captive Portal was configured for wireless users on 172.16.0.0/16 network with ...

Intercept DNS requests

Hi all,I've read in an article that it's possible to intercept DNS requests with DNS proxy without setting PA IP address as the computer DNS Server.Following this article, I've enabled DNS proxy in a PA interface (inside), redirecting DNS request to a public DNS server; I've set up a DNS proxy rule to try to intercept the requests (for example, ...

SYSTEM ALERT : high : SSL connect error

Have any body got such error message as below:domain: 1receive_time: 2012/02/13 19:10:00serial: 0002C123456seqno: 0actionflags: 0x0type: SYSTEMsubtype: generalconfig_ver: 0time_generated: 2012/02/13 19:10:00vsys: eventid: generalobject: fmt: 0id: 0module: generalseverity: highopaque: SSL connect error(10.2.1.1): 5, source: 10.3.1.250We got ...

Apostrophe in user name breaks query builder

Hi all,I have a username in my organisation that is domain\john.o'neill and I'm finding that when I try to do a query such as (user.src eq 'domain\john.doe') it's fine, but when I put in (user.src eq 'domain\john.o'neill'). I appreciate that this is because I'm esentially saying (user.src eq 'domain\john.o' ) but with neill' on the end.Is there ...

UKRB by L3 Networker
  • 2431 Views
  • 1 replies
  • 0 Likes

Is there a way to eliminate the need for SSL-VPN users authenticating via AD to enter the Domain field before the username ?

I am using a PA-2050 and OS 4.0.5 (plans to upgrade shortly to 4.0.8) with NetConnect. We recently started using AD for authentication and it's working very well with one exception: the users must enter the AD domain name in with their username. Ex: domain\usernameIs there a way to remove the need to enter the domain name if you are only u...

dcowan by Not applicable
  • 3573 Views
  • 3 replies
  • 0 Likes

PAN 500 - 4.1.2 - Bypass Mgmt Interface

Hi,I am pretty new to PAN Firewalls, and my question is really basic.I would like to use only two interfaces on my Firewall : ethernet1/7 as my Lan and ethernet1/8 as my Internet Acess.I would like to avoid using Mgmt Interface port.I have found a thread which explains how to enable management on any interface through CLI. And it did worked well...

Resolved! Qos Guaranteed

Hi, all we would like to better understand the QoS for setting "guaranteed"The question is: the "guaranteed" is pre-allocated or it's dynamic configuration?Suppose to have:5 Mbps of total bandwidth available; if we set guaranteed to 3 Mbps for calss 1 this means that default class(4) has automatically 2 M? Or the default calss (4) has a bandwidt...

helpdesk by L1 Bithead
  • 4408 Views
  • 2 replies
  • 0 Likes

Resolved! g.ceipmsn.com

Has anyone dealt with this url before? It seems like it's trying to call home as soon as my machine login and it's reating some issue with some of my user. Wonder if Palo can recognize it for now it just saying web-browsing app.thanks.

friento by L3 Networker
  • 3825 Views
  • 2 replies
  • 0 Likes

URL Filtering - DNS Proxy

Hi,I have the PAN devices in the main datacentres that do DNS lookups for all clients globally. What I am trying to figureout is how to have those servers forward to the PAN and the PAN proxy off to external servers then filter the returns based on a URL filtering policy. Thus not having to use a service like Open DNS. The standard URL filtering...

bcsgroup by L2 Linker
  • 5304 Views
  • 5 replies
  • 0 Likes

Multiple Remote Access VPNs, same gateway IP?

Hey all,I'm coming over from the Cisco world and trying to setup two separate remote access VPNs but using the same gateway IP. My understanding is that normally with the PA you can use the security policies to differentiate users and provide access restrictions to different users that way.Say though you wanted two different remote access VPNs e...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels