General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Apps vs URL Profile - block application

Hi all,I tested this strange (imho) behaviour with PAN 2020 4.0.3:1. create a first security policy with ssl, http-proxy, dns but without web-browsing application (as you can see in 1.jpg) with action ALLOW2. create a following security policy with facebook application and action DENY3. create a final security policy for all other outbound traff...

panagent user identification problem with working groups on the active directory

Hi,i tried ad user identification with pan agent on the pa2050 box and windows2008R2.But i have some problemsfor example;i created one group which called MSN_DENY and added it 5 users like test 1,test 2,test3,test4,test5(whatever) .later i was write two security rule.firstly deny msn traffic for MSN_DENY group(rule1),secondly permit msn traffic ...

lildeniz by L3 Networker
  • 7582 Views
  • 11 replies
  • 0 Likes

HA Sync issues with content updates

I am running a pair of PA-4020s in HA mode on PAN OS 3.1.8. For about the last three or four Threat and App Content updates I have had sync issues. I have the active PA downloading and then syncing the content to the passive PA. This worked fine until now and we have had the 4020s in place since April. Anyone else having this issue or have any s...

Base64 encoded HTTP traffic.

Hi,I was reading the 2011-2012 buyers giude. There is a statement that describes Base64 encoded HTTP messages , used in command and control traffic for malware.The bot sets the User-Agent header value to “inter easy” and also receives a scrambledBase64 encoded command which means “sleep”: <!-- 2upczxAX.3Most network security controls would pa...

AD/LDAP Server authentication

Does anyone have any tips for getting AD/LDAP bind request working at the server. I have the PaloAlto sending and receiving the bind request to authenticate, but the server reply packet says the credentials are invalid (error code 52e - invalid credential). My AD server administrator says the requests aren't making it to the server, but I have...

sajens by L0 Member
  • 3968 Views
  • 1 replies
  • 0 Likes

Simple Policy Question

This is a simple one, but I couldn't find it specifically stated in the manual.When I define a security policy, are the Zone and Address exclusive of each other? In other words, if I select a zone,it requires I put in specific IP's or select Any. If I leave the IP's as any, but select a specific zone, will it only allow IP's from within that z...

cmaier by L1 Bithead
  • 3493 Views
  • 3 replies
  • 0 Likes

Resolved! URL Category priority

HiI am wondering what will happen if one URL is in two different categories. Especially if one is configured to block, the other to pass the request.I don't know if this can happen within predefined categories (from BrightCloud), but as i am able to define new ones, its possible to add a already categorized URL in my own category.Our goal is, to...

User_333 by L2 Linker
  • 8609 Views
  • 3 replies
  • 0 Likes

Resolved! Trunk / Link Agg Recommendation

I have a 5060 I'd like to carve up and use one of the vsys's on it for a back-end firewall. My plan was to take two of the 10Gb ports and LAG them together, sending all 4 of my vlans in and out on that one trunk. Will that work, or is there a better way to architect this setup?I'm a little lost in setting this up and creating the vlans to resi...

cmaier by L1 Bithead
  • 4221 Views
  • 3 replies
  • 0 Likes

Problems with PAN

We are a PAN partner and have some issues with the boxes . We have a PA 500 installed for testing as we are looking to do some live demo for clients . I have a laptop connected to the lab running logme in, skype . The unit has been on live traffic for about 4 hrs and it can't detect neither the Skype nor the logme in . incomplete or insufficient...

usvi by L3 Networker
  • 3081 Views
  • 2 replies
  • 0 Likes

Resolved! Session Browser?

Just looked at Monitor->Session Browser. This is cool! Why is it not documented anywhere? Is it new and I just missed something?

Panorama SSL Decryption Rules

Hi all,I have some problem during commiting decryption policy (Forward Proxy) to devices from Panorama. Panorama tells me only one things: "commit all failed" :smileymischief:I suppose something related to decryption certificates that are device dependent. For this reason I tried to import the certificate generated from the PAN device inside the...

SSL decryption in 4.0

Hi,Is there an article describing how SSL decryption is to be configured in the current version 4.0 ? I can see there has been some changes in the way certificates are being used.Regards,Sunil

  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels