General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4121 Views
  • 0 replies
  • 0 Likes

Application "Mode Shift" Behavior

From what I understand, "mode shift" is the term for when an application's identification changes during inspection. For example, a flow may be initially identified as "web-browsing", and then further identified as "facebook". I can't find any documentation about how the "mode-shifted" flow is analyzed again in the security policy. Does the f...

mgentile by L2 Linker
  • 5197 Views
  • 2 replies
  • 0 Likes

URL Filtering Exception...

Hi all, Here's what I need help with. .I have a general URL Filter setup on my outbound internet rule.I am filtering Job Seeker sites (Monster, etc.) per management requests.My question is, how do I setup a rule that will allow my HR dept to be able to access those sites, but not compromise the rest of the filter list.Thanks!Greg

smfwadmin by Not applicable
  • 2911 Views
  • 2 replies
  • 0 Likes

SSL-VPN and HA Cluster A/P

Hi,I have two 5050 in A/P mode running version 4.0.5. My question is if I connected via ssl-vpn to my environment and the primary PA is going down, do I need automatically flip over to the stand by firewall or I need to reconnect manually? BTW I’m using RSA OTP for authentication. Thank in advanceilyia

iliafr by L0 Member
  • 2456 Views
  • 1 replies
  • 0 Likes

SSL-VPN dhcp dynamic ad integrated dns

We have a problem with clients (winXP) connecting with the ssl-vpn and registering the vpn supplied ip into dns. When they login onsite, their host a record does NOT get updated. It stays at the ip given to to the ssl-vpn. Our internal dhcp server registers all dns records using a service account. This account doesn't have authority to modify th...

VSYS

i have PA 4020 in a production enviroment , and i need to create a new Vsys(2) , would that by any means delete my current (vsys1) confeguration. , i mean is it safe to do that now.

High CPU and Lag using ACC

We have PA-4020 running 3.1.9 in HAEvery time I need to use ACC to run traffic report for week/30 days or so …. It just freezes up for several minutes with up to 98% CPU that remains long after I cancel the report. The more granular I get with my report (filter on app) the more lag I get. Usually if I chose only one filter after the initial repo...

is it safe to raise "action" to block?

hii noticed that in some "critical", "high" and "medium" severity vulnerabilities, the default action is just "alert"... especially those brute-force attempts. at the moment, our system is set for default to take care of these. however, i remember a thread here advising to set the action to "block" for medium severity on the server side vulnera...

RonaldGo by L2 Linker
  • 15002 Views
  • 7 replies
  • 0 Likes

Resolved! Next-hop Resilience (Shared IP) options for L3 Interfaces

Hi all,We're preparing a migration from Nokia IP boxes to a pair of PA4050s in an active/passive HA setup. We currently use VRRP on the Nokias for next-hop redundancy but I couldn't find an equivalent option on the Palos.What options are available to us? Are we going to have to use HSRP from the switch side or can we do something with virtual ro...

Global Protect Client is crashing on Windows 7 x64

Hi!Does anybody has had problems with Windows 7 X64 that Global protect Client crashes all the time? I have reinstalled the program serveral time and still it does that. I tested it also with windows 7 32, and it works great there.. Any idea?

How many router which is supported IPSec of PAN?

Hi all,I need to do IPSec from Head Quater to branches.I am looking for a new router which will be placed in some branch(since each branch has a few clients).But I don't know a router which is supported by PAN IPSec.Does anyone know? or has an experience about this, please give me a list or some kind of example router.Big thanks

Millenium-lis app in 4.0.5

Dear Support Team I have issue in OS 4.0.5 with 4050 box the application is Millenium-lis it cannot be use from untrust to access this apps (server is in trust zone). the log show it work fine, but the access is cannot, please give me any recomendation.thank youBest Regard

CLI commands logfile ?

Hi,Is there a logfile that stores all commands that have been issue through CLI ( with username and timestamp)I'm sure this must exist, but I can't find it....Tx !

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels