General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

New to PAN - Traffic log Destination column question

Hello,What information is the Traffic Log's "Destination" column giving me?We are just setting up a pair of PA-500s and I am perusing through the traffic log and noticed that the destination column doesn't seem to reflect the website destination that a user has tried to go to. Instead it seems to only list either the DNS name of the destination...

cnelson by Not applicable
  • 2730 Views
  • 1 replies
  • 0 Likes

Cannot open group_memebers.txt file, casue is 2!

An error like in the subject occurs in the log. The UIA is unable to read group information, nor IP to Username information.Tested with 3.1.1 and 3.1.2 version. Server Windows 2003 R2. Please explain what does "cause 2" mean.Best Regards,Radek

mstawow by Not applicable
  • 2260 Views
  • 1 replies
  • 0 Likes

Resolved! Captive portal port assignment

Is there any way to change the default ports used by a redirected Captive Portal? In my test environment, the users are redirected to the firewall interface, but on port 6082. I'd like to have it redirect back to the std SSL port instead.So instead of:https://<firewall int IP>:6082/xxxjust:http://<firewall int IP>/xxxThanks,Tariq

rahmant by Not applicable
  • 4242 Views
  • 2 replies
  • 0 Likes

User is not in allowlist

Running PAN 2020 v3.1.4 using LDAP authentication with eDirectory. I have a userid that will not authenticate via Captive portal. I am seeing a " User is not in allowlist" error in the System Log. I have verified that the userid in quesiton is in Server group. That Server Group is referenced by a Security policy as the source User. I have ver...

creating custom reports

hi,if i create a cutom reports, does it take time to generate data or it gives the report immediatly from data previously collected ?i mean when i creat a custom report do i have to wait for some time then only i can generate it ot it will be immediate .

u3974 by Not applicable
  • 3025 Views
  • 2 replies
  • 0 Likes

Additional File Types

Hello,In light of the recent email worm that utilized the dowload of a malicious .scr file - is there a reason the .scr extension is not availabe in the current file extention list? Is there a method to create custom extensions? The current list is a bit limited.Cheers,Mike

MGoodnow by L4 Transporter
  • 3925 Views
  • 3 replies
  • 0 Likes

Resolved! Routing question with semi-private (MPLS) connection

Hello all,I currently have the following:e1/1 - untrusted - L3 interface - "Internet_VR"e1/2 - trusted - L3 interface - "Internet_VR"We have an MPLS network handled by our ISP that links remote facilities back to corporate HQ. For the most part the remote facilities can be considered "Trusted," but it would be nice to be able to segregate traff...

bradenmcg by L3 Networker
  • 6329 Views
  • 4 replies
  • 0 Likes

Resolved! Dynamic URL filtering???

What is it exactly - and is it recommended? I've seen some posts here that indicate turning it off solved some poor performance issues. I guess I'm asking whether I should turn this feature on and what will it buy me?Ver 3.1.4 PA 2020

CWillms by L2 Linker
  • 3861 Views
  • 2 replies
  • 0 Likes

Admin users AD authentication HELP

/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Tabla normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin:0cm; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New R...

Configuration of authentication profile via LDAP

Hi to all,we have a PA500 release 3.1.4.We configure an LDAP server that comunicate with a Windows 2003 DC then we create an authentication profile that use that LDAP server; finally we create a vpn profile that use that authentication profile.VPN users can authenticate only if we add the username in the "allow users list" of the authentication ...

u4353 by Not applicable
  • 3508 Views
  • 1 replies
  • 0 Likes

Group Updates

We have just moved a new PAN2020 into production and are slowing starting to move users over to the new system. We are running the following: PAN2020 v3.14 using the LDAP Agent v3.12.The firewall is not updating Group changes. I have the update set to 60 sec in LDAP Server config. I read the note that was posted on this on the 14th and am u...

Connectivity Issues

We are having an odd connectivity issue that randomly shows up on some of our machines. They pull an IP # from the DHCP server, they are able to do nslookups, but when I run a traceroute they time out after the L3 Trust port (10.2.0.1). If you let it sit for a few minutes it will suddenly start working.There is no record in the Traffic Logs of...

Odd SSL-VPN Lock Ups

We are noticing that our SSL-VPN connection, whether using the Windows or Mac client, will just lock up for five minutes at a time. The status window shows that no packets are moving at all. Has anyone else had this problem?We are running PAN OS 3.1.4 and version 1.2.0 of the SSL VPN client.

mharding by L4 Transporter
  • 2871 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels