General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4257 Views
  • 0 replies
  • 0 Likes

Classify ARD?

Remote Desktop Protocol (RDP) is a multi-channel protocol that allows a user to connect to a networked computer. Clients exist for most versions of Windows (including handheld versions), Linux/Unix, Mac OS X and other modern operating systems. The server listens by default on TCP port 3389. Microsoft refers to the official RDP server software as...

Resolved! Captive Portal Authentication

Hi, I've PA-500 with 4.1.1 and I've configured Captive Portal with AD Authentication. Pan-agenty seems to work fine and I can select the AD groups when I configure Securtiy Policy. I've created an authentication profile only for Captive Portal with Kerberos authentication and my Domain controller as Server profile but I cannot see the groups in ...

ssancho by L2 Linker
  • 6138 Views
  • 3 replies
  • 0 Likes

Installing a router behind PA-500 with Public IP

OK, I have read many discussions about this, but never found the answer. We were provided a /28 range of IP addresses from our ISP. We currently plug the ISP connection straight into port 3 on the PA. I would now like to add a Juniper SRX behind the PA, with a public IP so our VPN routers in the field can connect. Seems straight forward.In t...

Resolved! PANOS 4.0.8 - How to determine cause of DROP

Very basic configuration, an any any rule and a PAT rule for nat... trust and untrust zones and a default route and an internal summary route... what is happening is that from a traffic log perspective its being ALLOWED, from a NAT perspective I can see the session built with two flows for each direction successfully and they go ACTIVE. However,...

joshstout by Not applicable
  • 2606 Views
  • 1 replies
  • 0 Likes

Resolved! URL Categorization

Is there a way outside of making duplicate custom categories to re-categorize a site? (Outside of requesting Brightcloud to change it).If BrightCloud says a site is "Weapons" and I want it to be seen as "Government" how would I do so?Thanks!

mrsold by Not applicable
  • 2864 Views
  • 1 replies
  • 0 Likes

Resolved! syncronize admin roles via panaroma to pa-500

Hi,we are currently running PAN-OS 3.1.8 on our pa-500s and we are using PAN-OS 4.0.2 on our panaroma server.Is there any way to create admin-roles on panorama and push them to the devices or must we create each role on any device separately.Thanks for your help.

Vwire with WCCP

HiI am planing put PAN Device on vwire mode just before traffic reach their Proxy solution. Traffic redirect using WCCP web traffic from Cisoc switch to Cisco Ironport.The Proxy device only has one NIC interface.In this secenario What we will see? Only WCCP traffic, or Web traffic, from Switch to Proxy, and Web responses from Proxy to Switch, w...

shabeerc by L2 Linker
  • 4064 Views
  • 3 replies
  • 0 Likes

Inbound server failover between two ISP's

Hi All,I have a PA-2050 setup with two IPS's. One is primary, and if that goes down, the secondary takes over. This has been tested and it works great.There are three servers that recieve incoming traffic. They have been setup to use the primary ISP IP addresses for access. All works fine there also.What I would like to do is to addtionally ...

jgrabows by L0 Member
  • 2315 Views
  • 1 replies
  • 0 Likes

Global Protect Portals/Gateways HA sync

Hi,I wonder if portals/gateways config are automatically synchronized in a HA environment or do the have to be created manually on each devce?On our passive HA unit, there are no portals/gateways shown under global protect (only on the active unit).thx

PAN OS 4.1.1. How to delete user-group mapping

Hi, I'm using PAN OS 4.1.1 and I'm testing pan-agent and user-id agent. Actually I don't know how to delete my old user-group mappings. In CLI I type show user user-IDs and I see all the users, what I had with pan-agent and an old Active Directory and the new ones with User-IDs and new Active Directory.How could I delete the old ones??Thank you ...

ssancho by L2 Linker
  • 3619 Views
  • 1 replies
  • 0 Likes

Traffic Between DCs after User Agent Install

I installed the PAN user agent on a customers core DC and we are now having some issues. The traffic between the DC with the user agent and the firewall is pretty minimal and everything is working correctly. However we are seeing a lot of additional traffic ( consistent 1Mbps+) between their core DC (where the agent is installed), and their edge...

Panorama

I have multiply firewalls but all the 3 firewalls holding different set of rules, in this case how panorama will help to manage centralzied.

dpgowe by Not applicable
  • 2081 Views
  • 1 replies
  • 0 Likes

VPN peer with dynamic IP

Hello,I tried to make a VPN between a Palo Alto (static IP) and a Netscreen 5 (dynamic IP).I succeeded when I declared Netscreen's IP as static, so phase I and phase II, proxies and so are correct.When I change peer address to dynamic, VPN doesn't work. I tried declaring peer id, local id, every combination, but no success.I always get this log...

nevot by Not applicable
  • 4591 Views
  • 3 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels