General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

Resolved! Blocking Categorys Vs ACC reporting

Question, we are blocking the category online-personal-storage but my ACC report shows that some may have been using it. I see this a lot in the Sharepoint (live.com) and Gmail/Yahoo cloud sites but this 4shared is new. Can you please explain to me if this is blocked why does the report under the Bytes column shows data. Please see the image ...

Routing by source address

Hi at all.Actually I am migrating from a Juniper to a PAN 500, the juniper firewall has some routes based in the source address. The reason for this routes is the following, The HQ has running an ERP (SAP) in 3 servers and the conection from the remote sites to this servers is made trough a MPLS, the other traffic between the HQ and the remote s...

HA interfaces

Hi,On PA-4000 series, is it possible to dedicate interfaces other than HA1 & HA2 to HA, for example fibre ports ? Thanks.David

dramey by Not applicable
  • 2177 Views
  • 1 replies
  • 0 Likes

sslvpn installation not working on Windows 7

Hi,I have some clients having issues installing the sslvpn client on windows 7 pcs.We are using version 1.2.0.When i try to install manually, i get the error installing service.I get the netconnect icon but the connection stays on connecting.....Please advise.Vinesh

vinesh by L2 Linker
  • 2458 Views
  • 1 replies
  • 0 Likes

Streaming Media –Best Practice?

We implemented PAN few months ago in our network. We implanted some URL category policy; blocking A&P, online games, gambling and few other URL categories.We are thinking of blocking URL category and Application Category for Streaming media. We use You-tube in our organization for training purpose and we would like to keep some audio/video s...

judy_ulm by Not applicable
  • 4546 Views
  • 4 replies
  • 1 Likes

Port Forward and system real time dump

HelloI'm a novice and I have maybe stupid two questions.How can I dump and display (real time) incoming and outgoing traffic on the interface (or all interfaces) ?.For example: typical view from tcpdump.~# tcpdump -n host 193.165.XXX.XXX and port 80tcpdump: verbose output suppressed, use -v or -vv for full protocol decodelistening on eth0, link-...

u6804 by Not applicable
  • 2734 Views
  • 2 replies
  • 0 Likes

Feature request: Replace the hard disk with solid state storage

Hi Palo AltoOne thing we asked of our var is instead of hard disks in the boxes, can we have solid state disks.I am informed this is something you do not offer at the moment.The reason for the feature request, we had our shipment of 2 x 2050's and a 2020 yesterday. Of the three firewalls, one of the 2050's was DOA with a failed hard disk. Obviou...

thesa by L1 Bithead
  • 4112 Views
  • 3 replies
  • 0 Likes

Resolved! PA2020 Proxy ID Limitations

Hi,I am configuring a VPN Tunnel between a PA2020 and a Cisco ASA. The PA is running version 3.1.5.The PA is obviously route based VPN's... The Cisco ASA uses policies or encryption domains/ACL's to define what traffic is allowed down the VPN.So in order to get this working we have used Proxy ID's to define the traffic that is allowed down the t...

harsh01 by Not applicable
  • 3161 Views
  • 2 replies
  • 0 Likes

ssl-vpn unable to login

Hello,I have a Problem with my PA-500 (4.0.2). I'm unable to see the Webserver Login Page for the SSL-VPN. I get the SSL Certificate Security Warning and then the Browser hungs up on loading (Waiting for IP-ADDRESS) and nothing happens.I already disabled the Clientcertificate, Changes the Server-Certificate and changed the Authentication Profile...

computop by L1 Bithead
  • 5735 Views
  • 6 replies
  • 0 Likes

Resolved! Disk Quotas

Does anyone know if it is possible to change the disk quotas in Panorama?

Exclude URL

Is there a way to exlude URLs from the log? In other words if there are websites, like our company website, that I don't want to see when I view the URL Filtering log, can I exclude the URL from being logged?Thanks.

Klein_it by Not applicable
  • 3768 Views
  • 2 replies
  • 0 Likes

Resolved! Link Aggregation

Does anyone know if the Palo Alto has or will have (in a future release) the abilty to aggregate WAN links?

tmallen by Not applicable
  • 4354 Views
  • 4 replies
  • 0 Likes

Resolved! Global protected user

Dear Friends!I have one pa2020 device. So i configure global protected feature. but configuration continue problem. rasmgr: No valid GlobalProtect gateway license! device: Warning: No valid GlobalProtect gateway license!Warning: No valid GlobalProtect portal license!Configuration committed successfullyThis one error message.Must I license buy Gl...

batmunkh by Not applicable
  • 3165 Views
  • 1 replies
  • 0 Likes

HA Active/Active with Floating IP issue (PAN4.0.2)

The configuration is HA Active/Active with the following: - “Session Owner Selection” set to primary-device; - Floating IP configured on several L3 interfaces, and on each interface the Active-Primary node has lower Floating IP priority (is the preferred node); - The Link Monitoring is disabled, however on each Floating IP group ‘Failover on ...

darkfibre by Not applicable
  • 2977 Views
  • 1 replies
  • 0 Likes

CREATE CUSTOM REPORT FOR UNKNOW USERS?

Hello,I want create a custom reports for identify all User there are not identified by the PALO-ALTOI can do that with the traffic log with the fitler : not (user.src neq '') ( I do a negate on user is present)I can see the unknow users in real time, in cli with : show user ip-user-mapping | match unknowbut with the custom report filter is not p...

alle by L3 Networker
  • 2430 Views
  • 1 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels