General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! URL Content filtering Question - Netflix

Ok, don't shoot the messenger but I was asked to see if I could unblock the queue management area for Netflix but still block the streaming media part of it...  We're using the URL filtering capabilities of the PA 2050 device and I have a policy defi

...

Emailing of CSV reports?

Currently my reports can only output in the default behavior offered - PDF's are sent automatically - however, some groups within the company that specifically manage risk want to add automation to the mitigation process - and doing that would be muc

...

jsilvia by Not applicable
  • 3223 Views
  • 1 replies
  • 0 Likes

DHCP server -> conflict IP

Hi

I have a DHCP server enabled on one of my interfaces, but clients have problem getting IPs back - after reboot of windows machines it normally works, but this normally not an issue with other DHCP servers.

Here is one message ->

An error occurred whi

...

FlexyZ by L3 Networker
  • 4396 Views
  • 4 replies
  • 0 Likes

Overlapping networks - NAT

Hi!

I have another problem - this time with overlapping networks. Here is a picture:

I'm the administrator of PA1. How can user from PC1 connect with PC2 ? I tried with destination and source nat on PA1 but i had to add routing to the destination trans

...

Resolved! App-ID block the whole category

Hi guys,

i have several distinct classes of users, and whole categories of apps need to be blocked for several of these classes. Is there a way to block a whole application category, similar to the way we can block whole categories using the URL filte

...

bkandola by L0 Member
  • 1820 Views
  • 1 replies
  • 0 Likes

How to report traffic logs for a specific rule ?

Hello,

I have defined several specific policies to allow traffic through my PA device.

I have also created a rule that allow any traffic (at the end) to not impact current traffic.

My idea is to be able to identify all traffic that flows through my devi

...

ldormond by L3 Networker
  • 2879 Views
  • 5 replies
  • 0 Likes

Will SSL VPN work for Apple IPAD (or ios 5 devices)

Hello,

I was told today by PANTAC that  SSL VPN work for IPAD (or ios 5 devices) for PANOS 4.1 but I have not been able to find any documentation supporting this to present interanlly.  Can someone confirm this and also provide any supporting document

...

Eone by Not applicable
  • 2453 Views
  • 1 replies
  • 0 Likes

NetConnect to Global Protect migration issue

Hello to everyone,

I migrate my PAN 500 from 4.0.7 to 4.1.0, with previously configured SSL-VPN which was operational. After migrating to new FW, SSL-VPN migrated to Global Protect portal with all configured settings and with new GP client to end node

...

Tician by L3 Networker
  • 4629 Views
  • 7 replies
  • 0 Likes

Resolved! captive portal and blackberry enterprise server

BES server is a proxy for all users on phones, (they all come from the BES IP address on the LAN) what is the proper way to install captive portal or user identification so that we protect and identify users on the phone client end-points?

kkeeton by L2 Linker
  • 2486 Views
  • 2 replies
  • 0 Likes

terminal server agent and security policies

hi , i installed the terminal server agent on the ts machine and i also configured ldap on palo alto,and create a no-restriciton rule on top of the list.when i try to access to internet technically i must not be blocked,but when i blocked i also dn't

...

Application-default for dynamic protocol

Hello,

How does the PA device work when we define a rule that allow an application that use dynamic ports and we specifiy the application-default service ?

As an example, I have a rule that allow application "rmi-iiop" (Java remote method invocation (R

...

ldormond by L3 Networker
  • 2546 Views
  • 1 replies
  • 0 Likes

Upgraded to 4.1 Global Protect SSL VPN

Recently upgraded to 4.1 where SSL VPN is now incorporated with the Global Protect client.  Is it possible to not use the Global Protect client and connect via SSL using the Java NetConnect client?

fbrown by Not applicable
  • 1857 Views
  • 1 replies
  • 0 Likes

PBF - Best practices for Target IP Address

Hello all,

When you want to failover between 2 ISP with PBF features, what are the best practices for the choice of the target IP addresses?

If we use the default gw of ISP 1 (for ISP 1 tracking) and ISP2 (for ISP2 tracking), it's sometimes possible th

...

alliance by Not applicable
  • 1807 Views
  • 1 replies
  • 0 Likes

Importing old logs to Panorama

Greetings!

When I upgraded to 4.1, I choose to rebuild my Panorama server from scratch. After I was finished, I decided to try exporting the logs from the old server and import them to the new. Is that possible? Will it leave the new log entries intac

...

cloughr by L2 Linker
  • 2805 Views
  • 1 replies
  • 0 Likes
  • 24128 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors
Labels