General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Blocking by AppID don't work as expected

Hi

To block a webpage like Facebook, I have the follow two possibilities.

1) Block it by the Url Filter

2) Block it by the AppID

Since the URL Filter just looks at the URL and no other content. Access to Facebook will only be blocked if I try to access i

...

User_333 by L2 Linker
  • 2053 Views
  • 2 replies
  • 0 Likes

Resolved! Custom URL wildcard

Hi all,

I have a question relating to wildcards in a Custom URL Category on PA-500 - 4.1.0

I have the following entry in my custom URL category

     *.centos.org

and I'm finding that I'm getting a match with the following URL (and many others)

     mirror

...

DavePalo by L4 Transporter
  • 4918 Views
  • 9 replies
  • 1 Likes

Trouble after upgrading to 4.1

I was currently running 4.0.5 on panorama and HA active passive 2050 cluster.

The upgrade ran rather smoothly.

has something changed for service declaration in 4.1?

I define my addresses and custom services on the panorama which I sync to the HA cluster

...

Virtual balancing and PBF

Hi all,

My client need to do Load Balancing in his wan interfaces, I did the next config, in PBF I put four policies, one for the two Internet segments asigned to the first and more faster output (TRUST to (1.0.0.1-126.255.255.254) & (128.0.0.1-192.25

...

p_marquez by Not applicable
  • 1692 Views
  • 1 replies
  • 0 Likes

Resolved! URL Content filtering Question - Netflix

Ok, don't shoot the messenger but I was asked to see if I could unblock the queue management area for Netflix but still block the streaming media part of it...  We're using the URL filtering capabilities of the PA 2050 device and I have a policy defi

...

Emailing of CSV reports?

Currently my reports can only output in the default behavior offered - PDF's are sent automatically - however, some groups within the company that specifically manage risk want to add automation to the mitigation process - and doing that would be muc

...

jsilvia by Not applicable
  • 3109 Views
  • 1 replies
  • 0 Likes

DHCP server -> conflict IP

Hi

I have a DHCP server enabled on one of my interfaces, but clients have problem getting IPs back - after reboot of windows machines it normally works, but this normally not an issue with other DHCP servers.

Here is one message ->

An error occurred whi

...

FlexyZ by L3 Networker
  • 4159 Views
  • 4 replies
  • 0 Likes

Overlapping networks - NAT

Hi!

I have another problem - this time with overlapping networks. Here is a picture:

I'm the administrator of PA1. How can user from PC1 connect with PC2 ? I tried with destination and source nat on PA1 but i had to add routing to the destination trans

...

Resolved! App-ID block the whole category

Hi guys,

i have several distinct classes of users, and whole categories of apps need to be blocked for several of these classes. Is there a way to block a whole application category, similar to the way we can block whole categories using the URL filte

...

bkandola by L0 Member
  • 1715 Views
  • 1 replies
  • 0 Likes

How to report traffic logs for a specific rule ?

Hello,

I have defined several specific policies to allow traffic through my PA device.

I have also created a rule that allow any traffic (at the end) to not impact current traffic.

My idea is to be able to identify all traffic that flows through my devi

...

ldormond by L3 Networker
  • 2646 Views
  • 5 replies
  • 0 Likes

Will SSL VPN work for Apple IPAD (or ios 5 devices)

Hello,

I was told today by PANTAC that  SSL VPN work for IPAD (or ios 5 devices) for PANOS 4.1 but I have not been able to find any documentation supporting this to present interanlly.  Can someone confirm this and also provide any supporting document

...

Eone by Not applicable
  • 2411 Views
  • 1 replies
  • 0 Likes

NetConnect to Global Protect migration issue

Hello to everyone,

I migrate my PAN 500 from 4.0.7 to 4.1.0, with previously configured SSL-VPN which was operational. After migrating to new FW, SSL-VPN migrated to Global Protect portal with all configured settings and with new GP client to end node

...

Tician by L3 Networker
  • 4491 Views
  • 7 replies
  • 0 Likes

Resolved! captive portal and blackberry enterprise server

BES server is a proxy for all users on phones, (they all come from the BES IP address on the LAN) what is the proper way to install captive portal or user identification so that we protect and identify users on the phone client end-points?

kkeeton by L2 Linker
  • 2414 Views
  • 2 replies
  • 0 Likes

terminal server agent and security policies

hi , i installed the terminal server agent on the ts machine and i also configured ldap on palo alto,and create a no-restriciton rule on top of the list.when i try to access to internet technically i must not be blocked,but when i blocked i also dn't

...

  • 24195 Posts
  • 100 Subscriptions
Top Liked Authors
Labels