General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! How many Terminal Server Agents supports the PAN?

Hi everybody,

I saw in the "TS_agent_install" PDF following sentence "The PAN device currently supports up to 50 TS agents." (page 5)

Now my problem, one of our customers is near by this limit!

So, can anyone tell me if there is an upgrade in the next r

...

indevis by L2 Linker
  • 2907 Views
  • 3 replies
  • 0 Likes

Logging of blocked HTTP traffic

All,

We have a proxy environment where LAN users requesting Internet sites have to go through the proxy. Our proxy is on the LAN side of the PaloAlto so that traffic goes from User->Proxy->PaloAlto->Internet. There is a rule on the PaloAlto that block

...

Exchange 2010 CAS in the DMZ

Aside from being not supported by Microsoft, has anyone placed an Exchange 2010 CAS server in a DMZ? It looks like the reasoning behind it was because you'd have to punch so many holes in the firewall, it wasn't worth it. But since the PAN has a litt

...

mharding by L4 Transporter
  • 2900 Views
  • 3 replies
  • 0 Likes

Result - Stuck in PENDING

Hi,

I have an antivirus download schedule and install job, but it seems PA FW is
stuck in the Download action. Sine 2 days I have the same result as below.


Enqueued          ID             Type    Status Result Completed
---------------------------------

...

ta185020 by Not applicable
  • 3316 Views
  • 2 replies
  • 0 Likes

Safari Security Errors

I have suddenly started getting security certificate errors while using Safari.  I am not using a Captive Portal and have no certificates on the PAN, however the certificate errors always point back to a self-signed certificate by the PAN.  I am atta

...

Resolved! Problem Creating Rule for IKE Traffic

I think it's my phase II re-key traffic being dropped. I tried to set up a rule source untrust with a specific IP, dest untrust with my Firewall's IP, application IPSEC, service application default, Action Allow.

It never gets hit and my udp/500 traff

...

rmagowan by Not applicable
  • 2512 Views
  • 2 replies
  • 0 Likes

Conficker DNS Request Question

So we have some conficker infections here where I work. The problem is that the PA sits at the edge, so all I see are Conficker DNS Requests that get proxied through our internal DNS Server to the Internet. I guess there is no way that PA can see wha

...

jhickey by L3 Networker
  • 2029 Views
  • 2 replies
  • 0 Likes

ipv6 interface

Hi,

  I can't assign an IPv6 address to a L3 interface of a PA-500 in 3.1.

  But I can add IPv6 addresses to the objects DB, and there is a 'IPv6 firewalling' flag in the general device configuration.

  Has anyone played with IPv6 on a PA? Is there any

...

Resolved! Security Rule order

Lets say I have rules set up like this...First rule uses a URL Filtering Profile on just port 80/443, and another rule below it that uses the Antivirus and Spyware profile also on just port 80/443.  If the first rule allows traffic through, will that

...

jambulo by L4 Transporter
  • 4528 Views
  • 7 replies
  • 0 Likes

Resolved! User Agent timeout and expiration timer

Hello,

I have configured Age-out timeout to 720min and configured "<enable-full-expire>1</enable-full-expire>" on config.xml.

There is the way to check the timer for a particular users to check how last for expiration ?

If I restart the PAN-Agent servic

...

Resolved! ARP Question

When logged in via CLI on the PAN 500 and I view the ARP table, it says maximum of 500 entries.  Does this mean that the PAN will only support 500 unique connections at a time?

I'm still trying to track down a problem I've been having with some machin

...

Weird blocking behaviour..

Greetings.

I have a user who is using a specific protocol - FTP with explicit TLS or otherwise known as FTPES (not to be confused with SFTP or SCP), and for some reason my firewall is blocking it.

The PA identifies the transaction as SSL - which I woul

...

dagibbs by L4 Transporter
  • 2756 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama/ Report Creation...

...suitable for presentation. I guess I don't understand what I'm seeing or I don't understand what I should expect from Panorama. Quickly: I have 2 PA-2020's logging to a single Panorama instance where I attempt to create "consolidated" reports. Ver

...

CWillms by L2 Linker
  • 3048 Views
  • 4 replies
  • 0 Likes

Resolved! performance data

Hello team.

can you please tell me where I can have perf data  w/ Smartbits, IXIA or avalance?

I'm in the tender process to some customer, this is required from that customer like..

PA-4020, PA-4050 etc.

64 byte, 128 byte,256byte,512byte,1024byte,1500byt

...

bhlee by Not applicable
  • 2179 Views
  • 2 replies
  • 0 Likes
  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels