General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4134 Views
  • 0 replies
  • 0 Likes

HTTP Tunneling

Wondering how the Palo Alto detects HTTP tunneling and how would a security policy be configured to detect/prevent this situation.

snormoyle by Not applicable
  • 3369 Views
  • 3 replies
  • 0 Likes

SSL VPN

I just started using PAN 2050 in production and confiuring ssl vpn. Issue is that after client computer connect to vpn, client computer loses all internet access. What makes ssl vpn to work so that client computer doesn't lose internet access locally and still access resources remotely (office reourses behind the PAN)?Thanks

Resolved! add ping as custom service

HiI have a rule with some custom ports in the service tab, but how do I add ping then? - does not work if I dont have "application-default" in the service tab.Thanks

FlexyZ by L3 Networker
  • 4833 Views
  • 1 replies
  • 0 Likes

AD Group PDF Summary Report

HiI configure PDF Summary report for AD group.The way i did , i create the Custom AD group report and attached this custome report to PDF Summary report.But the generated pdf summary report doesnt have any data it shows all the the custom report with any data.If run manually the custom group report i will get the data.Please let me know what wi...

shabeerc by L2 Linker
  • 7306 Views
  • 8 replies
  • 0 Likes

Captive Portal as an option

A few of my rules allow for certain individuals (by way of User-ID) access to download EXE and access most any application. This of course works fine for PCs that are joined to the domain which makes up 99% of our PCs. However, for that 1% that are not on the domain, what's the best way for an individual to optionally supply the proper AD cred...

dshue by L2 Linker
  • 2713 Views
  • 2 replies
  • 0 Likes

Resolved! Clarification on File Blocking and SSL

If a download service uses SSL and PAN has an App and file blocking capability, but under SSL Decryption, it is an exception (ala drobpox), are options are pretty limited, correct?

VPN with fqdn denying ike 500

Hello,I'm trying to setup a ipsec vpn with a fortigate which has dynamic ip as gateway.I have a security policy which allows all packets from the dynamic ip (fqdn) but if i type the command 'show log traffic src in x.x.x.x' i can see that i have an incoming request which Palo Alto denies.The weird thing is that this allow rule contains all other...

cskodras by Not applicable
  • 3918 Views
  • 5 replies
  • 0 Likes

Classify ARD?

Remote Desktop Protocol (RDP) is a multi-channel protocol that allows a user to connect to a networked computer. Clients exist for most versions of Windows (including handheld versions), Linux/Unix, Mac OS X and other modern operating systems. The server listens by default on TCP port 3389. Microsoft refers to the official RDP server software as...

Resolved! Captive Portal Authentication

Hi, I've PA-500 with 4.1.1 and I've configured Captive Portal with AD Authentication. Pan-agenty seems to work fine and I can select the AD groups when I configure Securtiy Policy. I've created an authentication profile only for Captive Portal with Kerberos authentication and my Domain controller as Server profile but I cannot see the groups in ...

ssancho by L2 Linker
  • 6073 Views
  • 3 replies
  • 0 Likes

Installing a router behind PA-500 with Public IP

OK, I have read many discussions about this, but never found the answer. We were provided a /28 range of IP addresses from our ISP. We currently plug the ISP connection straight into port 3 on the PA. I would now like to add a Juniper SRX behind the PA, with a public IP so our VPN routers in the field can connect. Seems straight forward.In t...

Resolved! PANOS 4.0.8 - How to determine cause of DROP

Very basic configuration, an any any rule and a PAT rule for nat... trust and untrust zones and a default route and an internal summary route... what is happening is that from a traffic log perspective its being ALLOWED, from a NAT perspective I can see the session built with two flows for each direction successfully and they go ACTIVE. However,...

joshstout by Not applicable
  • 2558 Views
  • 1 replies
  • 0 Likes

Resolved! URL Categorization

Is there a way outside of making duplicate custom categories to re-categorize a site? (Outside of requesting Brightcloud to change it).If BrightCloud says a site is "Weapons" and I want it to be seen as "Government" how would I do so?Thanks!

mrsold by Not applicable
  • 2830 Views
  • 1 replies
  • 0 Likes

Resolved! syncronize admin roles via panaroma to pa-500

Hi,we are currently running PAN-OS 3.1.8 on our pa-500s and we are using PAN-OS 4.0.2 on our panaroma server.Is there any way to create admin-roles on panorama and push them to the devices or must we create each role on any device separately.Thanks for your help.

Vwire with WCCP

HiI am planing put PAN Device on vwire mode just before traffic reach their Proxy solution. Traffic redirect using WCCP web traffic from Cisoc switch to Cisco Ironport.The Proxy device only has one NIC interface.In this secenario What we will see? Only WCCP traffic, or Web traffic, from Switch to Proxy, and Web responses from Proxy to Switch, w...

shabeerc by L2 Linker
  • 4022 Views
  • 3 replies
  • 0 Likes
  • 24339 Posts
  • 124 Subscriptions
Labels