General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Traffic forwarding based on security policy?

We have been trying to troubleshoot an issue for a couple weeks now. We seem to have found the issue, but it doesn't make sense. I'm hoping someone can shed some light on this:First off, we have a pair of PAN-4020's in HA @ 3.1.9.I'm going to oversimplify the situation, but I think the logic will hold:Segments A, B and CSegment A is a user seg...

bhelman by L2 Linker
  • 4189 Views
  • 4 replies
  • 0 Likes

Cannot browse nat webpage internally in lan

Hello All,We have some internet facing servers who has NAT public address.1) Externally we can access the public address of the server.2) Internally on our LAN, we cannot access the public address of the server, it timed out. However the appliance monitor tab shows accept, nothing was denied.The policy rules i set wasAny to Any - Server_...

mmxong by Not applicable
  • 2975 Views
  • 2 replies
  • 0 Likes

Resolved! System Log monitoring via email?

Is there a way to have notifications sent on system log events, either via SNMP or email, in 3.1.8?Perhaps I am just not seeing it in the config, my apologies.Thanks.

KGC by L3 Networker
  • 4532 Views
  • 2 replies
  • 1 Likes

Antivirus job failed

Dear Sir,I am getting above error message in my logs even though the Av update has taken palce. Ths is 2nd time i saw the messgae in the log.And also I can see some unusual logs in the logs. pleasee see the attched log file.Regards,Asanka

Asanka by L2 Linker
  • 8108 Views
  • 7 replies
  • 0 Likes

Resolved! URL Catagories Report

I have several URL filtering policies defined on the objects tab with my PA-2050 and would like to be able to dump that information into a report / spreadsheet for my manager etc. Is there a way to do this? It would also be benificial to me so that I can check my policies against each other. If there's a command line way to dump that config o...

SSL Renegotiation Denial of Service Vulnerability

Hi All,I have received an Alert for SSL Renegotiation Denial of Service Vulnerability.I have visited the website, and for some reason, Palo Alto thinks i am the attacker,and the website i am visiting is the victim.I have attached screen shots of this issue, please help me in understanding this issue/threat.I am not sure how to treat it and why P...

Resolved! Multiple DNS Names SSL Certificate

Hi All,Hope this is an easy one to answer.I have a customer that requires that the SSL-VPN have 2 fqdn names associated with iti.e.https://vpn.company-A.com = 196.1.1.1https://vpn.company-B.com = 196.1.1.1How would i over come this as I can only allocate a single certificate to the VPN portal ?CheersMarc

File transfer Issue - PA5050 (PAN 4.0.2)

PA5050 device with PANOS 4.0.2 in L3 mode: - There is created a single interface AE1 (6x physical interface in LAG); - There is createsd 100 L3 subinterface with VLANS tag on interface AE1; - The device has a one rule "allow all" (test environment) with profiles SPYWARE, AV, VULER, URL, DATAFILTER - all in logging mode.The device works fine with...

darkfibre by Not applicable
  • 5004 Views
  • 4 replies
  • 0 Likes

Dynamic URL database updates failing.

Folks.I haven't been able to connect to the URL database update server for nigh on two days now - all other updates are working fine.Does anyone know if there's an issue, or is anyone else experiencing a similar issue?Cheers

dagibbs by L4 Transporter
  • 4101 Views
  • 2 replies
  • 0 Likes

RADIUS authenticated SSL VPN users in policy

Is is possible to define a "source user" in a security/QoS policy as a username/group that was authenticated by RADIUS? Basically, the need is for users coming in via SSL VPN to have specific security policies assigned to them based on username or RADIUS group membership.

pflanagan by Not applicable
  • 3820 Views
  • 2 replies
  • 0 Likes

Report on Rule Usage?

Hi,How can I run a report to understand the last use of a loaded policy/security rule? For example, if I have 100 security rules in the firewall policy, how can I identify which rules are actively being used, and which ones are not being used often, or at all? I realize that this information is contained within the traffic log, but for an enviro...

apc050 by Not applicable
  • 3930 Views
  • 3 replies
  • 0 Likes

Resolved! Upgrade from 4.01 to 4.03 Url filter issue

After we did an upgrade from 4.01 to 4.03 when proceeding to do a commit we get the following error:rulebase -> security -> rules -> X X Policies 'X X Policies ' is invalidThis worked with 4.01...Any thoughts?

almay by L2 Linker
  • 3701 Views
  • 2 replies
  • 0 Likes

Captive Portal SSL Problem

I tried to configure my PaloAlto with a captive portal, but something seems to be wrong, as i don't get any login form.As I use the captive portal in redirect-mode, the firewall forwards my browser request to something like https://publicWLAN:6082. This seems to work right. I also got a "allow" Log entry on my traffic log.I tried to analyze the ...

User_333 by L2 Linker
  • 5052 Views
  • 3 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels