General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4228 Views
  • 0 replies
  • 0 Likes

Why are new units shipped so out-of-date?

We have purchased eight units (2020s and 4020s) in the past two months and they all shipped with PANOS v3.1.4, no updates of any kind, and an incorrect setting for the URL filering (surfcontrol vs. brightcloud) which requires a full reboot to fix. It has been very time consuming to get all these units up-to-date before we can use them.I realize ...

KGC by L3 Networker
  • 3402 Views
  • 2 replies
  • 0 Likes

LDAP Authentication questions

Hi everyone,when I configure LDAP for authentication,then I'm getting the groups in the distinguished name (dn) format.I can choose them in policies and in the authentication profile.Now my questions,is the pan-agent then needed for policy authentication, too? Please explain why!when I add a group in the dn format to the allow listof an authenti...

indevis by L2 Linker
  • 5430 Views
  • 4 replies
  • 0 Likes

How to disable threatID for defined IP addresses

Hello!I would like to disable one threatID for specific sources/destinations (e.g. when source or destination is file sharing server), but I would like to enable it for all other users and/or addresses. Is it possible to do that?Thank you and best regards,Maja

mkopcic by L2 Linker
  • 3129 Views
  • 1 replies
  • 0 Likes

How to handle if control link/data link failure in HA

Hi All,I would like to know if our environment using 2 x PAN and formed HA. The control link and data link connected to switches as our office over 3 floors in the same building. If the switch failure, how did the PAN response? Will they are not able to fail over?Thanks!J

johnnyw by Not applicable
  • 5185 Views
  • 3 replies
  • 0 Likes

Resolved! blocking files based on size ..

hi,i was looking for a way on how to block files based on size like to block files which is greator than 3mb for exmaple.i thought it could be created in custom vulnerability but i cant find.. so is it possible ?

Any documents with Logging and Splunk

I got as far as sending all the logs to our Splunk server, but am having problems with generating simple reports or using the Splunk for Palo Alto networks App. Any tips in getting that to work?I found one PDF from a while back, but doesn't quite seem to work.

Resolved! Paloalto to Firebox

Any know issues with an ipsec VPN connection between a PA-500 to a Watchguard Firebox?

twhite by L1 Bithead
  • 6567 Views
  • 4 replies
  • 1 Likes

Resolved! IP to user mapping issues with Pan Agent

We run McAfee which does some user authentication on AD for group policies. The problem is that when this happens, the ip to user mapping shows this service account as the user instead of the actual user that is logged in. The actual user is then unable to match on a specific rule and therefore gets the incorerct access.Not sure if changing some...

hallk by Not applicable
  • 3745 Views
  • 3 replies
  • 0 Likes

Resolved! insufficient-data/incomplete application in logs but still permitted

I am currently only allowing ssl and web-browsing applications to a specific server. If I do a "telnet x.x.x.x 3389" it connects even though the rule should not allow this. I would think that the application filter is unable to block this due to the application coming up as insufficient-data or incomplete.How do I block this??

hallk by Not applicable
  • 11159 Views
  • 12 replies
  • 0 Likes

Errors with Cosutm Reports

Hi Guys,Since I have upgrade to 3.1.6 (December 2010), the PA-500 is unable to run Costum Reports longer than 1 week or last 7 days, I downgraded to 3.1.5 but this does not work. Right now I have version 3.1.6, an every time I try to run a Custom Report longer than "Last 7 days" It shows me "Communication %20 fail". Is this a bug on the PANOS or...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels