General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! PAN User Agent

Hopefully I am wording this in such a way that it is understandable.This is pertaining to how the user-agent software works with a PAN device that has multiple virtual systems. Since I have never worked with multiple virtual systems are the user-agents specific to each virtual system or the physical device.

snormoyle by Not applicable
  • 2455 Views
  • 1 replies
  • 0 Likes

PAN OS Packet Capture

I know where and how to start a packet capture on the device. I would like to know if the capture can be configured to capture only specific parameters (ie src ip, dst ip, src port, dst port). I don't see those options on the web GUI.

snormoyle by Not applicable
  • 2658 Views
  • 2 replies
  • 0 Likes

block by Domain Suffix (.xxx)

Looking for a way to block the domain suffix of .xxx I've created a custom URL catagory with *.xxx (and I also tried *.xxx/) and that works....however It will also block a URL string with.xxx anywhere in the URL (i.e. www.google.com/news/foobar.xxxdsdfsdsld/index.htm). Does anyone know of way to block a specific domain suffix .xxx instead of ju...

mjandin by Not applicable
  • 4329 Views
  • 2 replies
  • 0 Likes

Resolved! HA Active/Active design

Hi all,We would like to deploy 2 PAs on two different sites in an Active/active design. The two sites are 10ms far away from each other.So the first question is : Is 10ms (RTT) acceptable from a PanOS perspective to enable the HA feature ?The IP plan is not the same on each site. Is it an issue to setup HA active/active in this case ? I've read...

bdaussin by L0 Member
  • 4236 Views
  • 3 replies
  • 0 Likes

Resolved! PAN OS Syslogs

Need to find the field identifiers in the syslogs, some of them are pretty obvious while others are not.

snormoyle by Not applicable
  • 2739 Views
  • 1 replies
  • 0 Likes

HTTP Tunneling

Wondering how the Palo Alto detects HTTP tunneling and how would a security policy be configured to detect/prevent this situation.

snormoyle by Not applicable
  • 3350 Views
  • 3 replies
  • 0 Likes

SSL VPN

I just started using PAN 2050 in production and confiuring ssl vpn. Issue is that after client computer connect to vpn, client computer loses all internet access. What makes ssl vpn to work so that client computer doesn't lose internet access locally and still access resources remotely (office reourses behind the PAN)?Thanks

Resolved! add ping as custom service

HiI have a rule with some custom ports in the service tab, but how do I add ping then? - does not work if I dont have "application-default" in the service tab.Thanks

FlexyZ by L3 Networker
  • 4821 Views
  • 1 replies
  • 0 Likes

AD Group PDF Summary Report

HiI configure PDF Summary report for AD group.The way i did , i create the Custom AD group report and attached this custome report to PDF Summary report.But the generated pdf summary report doesnt have any data it shows all the the custom report with any data.If run manually the custom group report i will get the data.Please let me know what wi...

shabeerc by L2 Linker
  • 7261 Views
  • 8 replies
  • 0 Likes

Captive Portal as an option

A few of my rules allow for certain individuals (by way of User-ID) access to download EXE and access most any application. This of course works fine for PCs that are joined to the domain which makes up 99% of our PCs. However, for that 1% that are not on the domain, what's the best way for an individual to optionally supply the proper AD cred...

dshue by L2 Linker
  • 2707 Views
  • 2 replies
  • 0 Likes

Resolved! Clarification on File Blocking and SSL

If a download service uses SSL and PAN has an App and file blocking capability, but under SSL Decryption, it is an exception (ala drobpox), are options are pretty limited, correct?

VPN with fqdn denying ike 500

Hello,I'm trying to setup a ipsec vpn with a fortigate which has dynamic ip as gateway.I have a security policy which allows all packets from the dynamic ip (fqdn) but if i type the command 'show log traffic src in x.x.x.x' i can see that i have an incoming request which Palo Alto denies.The weird thing is that this allow rule contains all other...

cskodras by Not applicable
  • 3913 Views
  • 5 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels