General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

VTC NAT problem

I'm having a problem getting a standalone VTC box working. We're replacing Cisco ASAs with PA-500s at our sites, so there are existing rules that should be working when translated to Palo Alto. I'm fairly confident I have the requirements down:tcp/1720 (h323)tcp/5060 (sip)tcp/5061 (sip-tls)udp/5060 (sip-udp)tcp/60000-64999 (media-tcp)udp/60000...

nwallette by Not applicable
  • 6280 Views
  • 6 replies
  • 0 Likes

Size limit for URL block list

Is there a size limit for a URL block list, anad if so, what is it? (I understand that there is a size limit on each URL...I am referring to the size of the entire list of URLs)

jstiling by Not applicable
  • 6171 Views
  • 6 replies
  • 0 Likes

Resolved! Unable to download Dynamic Updates/

So, has anyone run into an issue with downloading Dynamic Updates? We are curently running a pair of PA-4060's in active/passive mode, with PAN-OS Software version 3.1.9. I have configured the firewalls to download only and sync to peer both the Application and Threat signatures everyday at 1800 and the Antivirus signatures every hour on the hou...

UAMSITSEC by Not applicable
  • 17812 Views
  • 9 replies
  • 0 Likes

URL filtering not active

Hello,I have NFR PA-2050 device. Software is 3.1.1. Licence is valid (see screenshot).Url filtering is not active. There is no activation button to activate it too (see screenshot)request url-filtering upgrade/revert/install doesn't work. request url-filtering download statusError installing last databaseany idea ?RegardsMichal

Resolved! PA-5020 NAT Limitations ?

All,We're in the process of doing a Checkpoing to PA conversion and we think we've found a possible show stopping issue. On our Checkpoints we have a large number of NATs that we need to port over. Our vendor runs through the conversion tool and generates a config for us, when we Commit it to the 5020's we get the following error:Error: Number o...

steveo by L3 Networker
  • 4637 Views
  • 5 replies
  • 0 Likes

Panorama Logging with NFS

I'm currently making a log concept for our new PaloAlto firewall environment for our new internet perimeter. I have a few questions about that.Here is what we want to build:- a two stage firewall concept- outer firewall is a PA-5050 cluster with Threat and URL- inner firewall is a PA-5020 cluster with just firewalling- inbetween of the two clust...

ssl gateway not working after upgrade to 4.1.2

HiAfter upgrading to 4.1.2 from 4.1.1 the ssl gateway and protal is not working.When accessing the portal the client certificate is presented but when pressing continue, the login page never appears.I had to revert to 4.1.1 to get it running again.Any clues?Thanks

FlexyZ by L3 Networker
  • 7181 Views
  • 9 replies
  • 0 Likes

User-ID Group Include List Error

On PanOS 4.1.2 I am trying to perform an LDAP lookup for the 'Group Include List' element of the User Identification setup i.e. to populate the 'User' field in policies.When I do this I get an "bind-dn is invalid" error. I know the account configured is fine, as it is a shared object set in Panorama and pushed to multiple boxes, and it works fi...

apackard by L4 Transporter
  • 7674 Views
  • 11 replies
  • 0 Likes

NetConnect on Linux under Wine

Has anyone managed to get NetConnect to run under wine on linux?I Use Firefox 9 for Windows under Wine, and managed to do an offline Java install by downloading from here: http://www.java.com/en/download/manual.jspI authenticate in the portal. The NetConnect client seem to be starting, the correct msi and exe files are apparently downloading,...

aseem by Not applicable
  • 2400 Views
  • 1 replies
  • 0 Likes

How many PAN support Admin account?

Hello.I want to know about PAN admin account performance.First. How many PAN support Admin account? Is it different from each PAN model?Second. How many PAN support concurrrent logged Admin user?Please let me know above question.Thanks in advance.Regards.Roh.

ttongfly by L3 Networker
  • 2122 Views
  • 1 replies
  • 0 Likes

Resolved! Blocked traffic after Content Upgrade 289

World of Palo,We have just seen an increase in blocked traffic (thus broken apps) after upgrading app content from V288 to V289. The funy thing is its all low risk Microsoft LAN stuff. Does anyone know if PAN have changed the action and not the signiture for 30858 - Windows Local Security Architect LsarQueryInformationPolicy from alert to drop...

djmac by Not applicable
  • 8732 Views
  • 1 replies
  • 0 Likes

When does a rule go unused

I have a number of rules that are showing unused. I've read the threads on the counter resets etc. but I'm still looking for a definitive answer - hence my post. When does a rule become marked as unsed? Is it after a month, 2 months, a year, since boot? Is there a setting I can adjust to say a rule is unused after X amount of time?Thanks,Bart

Blocked Applications cause Reset, not Block Page

On our firewall users are getting 'Connection Reset' errors in their web browsers rather than the 'Blocked Application' page.While the end result is the same, it makes debugging connection issues a lot harder! Am I doing anything wrong - an application that matches a 'Drop' rule should display a Block page if it's a browser based app?Rgds

apackard by L4 Transporter
  • 3582 Views
  • 1 replies
  • 1 Likes

VPN and client proxy

Hi Does anyone know how to force PC clients that have authenticated to the PA using Global Protect (non licenced version) to use a particular proxy server. ThanksRod

djrodb by L3 Networker
  • 2381 Views
  • 1 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels