General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

server load balancing on PA-4020?

I'm working on a Data Center redesign. One design we are considering will require replacing a core switch which currently gives us the ability to load balance a few sets of systems (within a set, not across) by defining an outwardly facing IP that balances traffic to N "inside" servers. This balancing also allows for a weighted balance (ie Ser...

bhelman by L2 Linker
  • 2566 Views
  • 1 replies
  • 0 Likes

Windows EXE Data filter

Howdy,Quick question: Does anyone know how to filter on just Windows Executable (EXE) in the data filtering log? Thanks in advance!Ebowd

ebowd by Not applicable
  • 2636 Views
  • 1 replies
  • 0 Likes

Resolved! Brute force and scanning signatures

Box: PA-2020 (probably all)OS Version: PANOS-3.0.6 Hi! I have some questions and suggestions for the threat-ips part of the box. 1. Ability to view settings for scanning and brute force signatures. - What are the settings for these signatures? I cant find for instance how many attempts/ips/ports is needed for the signature to trigger. 2. Ability...

u2521 by Not applicable
  • 878932 Views
  • 13 replies
  • 1 Likes

PDF Summary Schedule

Hello,Could you provide details on how the Summary Schedule works. The reports work properly and email properly. They are sent at 4:00AM - and there seems to be no ability to modify that. Also I am unclear what time frame I am seeing in the report. For instance the custom PDF summary that is emailed to me this morning at 4:00AM has today's d...

MGoodnow by L4 Transporter
  • 4844 Views
  • 4 replies
  • 0 Likes

Missing Objects defined with Panorama in NAT Policy on device

Hello,I miss objects, which are defined with Panorama in NAT Policy configuration on the device.The Objects itself are there (marked green) and available in Security Policy but not in NAT Policy configuraton.Is there a way to get this working or do I have to create Objects twice (one time Panorama - other time on device)?Installed SW Version: ...

ttwict by L0 Member
  • 2738 Views
  • 1 replies
  • 0 Likes

APP vs URL

Despite the fact that I've blocked *.logmein.com and the logmein application, I'm still seeing traffic permitted to logmein.com. On inspecting the traffic log details, I can see that the traffic is being identified in 2 ways:06/21 13:07:59 THREAT url ssl block-url URL Default Severity: informational Category: Blocked sites URL: *.app03-10....

robert.b by L1 Bithead
  • 2881 Views
  • 1 replies
  • 0 Likes

Resolved! Spyware Download Tab

Setting up new PA2020. Have upgraded to 3.1.2. In looking at SpyWare profiles, I am not seeing a Download Tab. I only see a PhoneHome Protection and an Exception Tab. What am I missing?

Allowing a subnet complete internet access but logging their traffic

Hi ya'll,Background: We have a seperate Vlan that we call "Raw Internet" with no filtering. This is used by our helpdesk staff. Which means they have open access to Internet and nothing is being blocked.Currently we purchased Palo Alto and I was wondering what would be the best way to do this. Meaning, giving them full access to internet yet...

casdc1pa by Not applicable
  • 4100 Views
  • 2 replies
  • 0 Likes

VLAN and Routing

Hi Guys,I have an issue.I have a PAN-500, I am using 3 interfaces: et1/4 is L3-Untrust, et1/3 is L3-Trust and et1/2 is L3-Trust.ET1/4 has the public IP.ET1/3 = 192.168.0.254/22ET1/2 has 8 sub interfaces, each subinterface has its own IP addressing and belongs to differnet VLANs.et1/2.1 192.168.9.0/26 TAG 30et1/2.2 192.168.9.64/26 TAG 31et1/2.3 1...

Resolved! Getting SSL-VPN clients to see internal servers

I am fairly new to configuring VPN's. I configured SSL-VPN using the wonderful guides found on this site and was able to log in with no problems. With the VPN active all of my traffic was routing out through my PaloAlto device perfectly I could surf the net all day with my traffic through the company IP address. When I try to talk to the servers...

Packet Capture Question

Hey folks,I'd like capture a particular traffic stream for analysis. I see how you can capure a packet trace as part of a Vulnerability Protection profile, but this particular traffic is not seen as a vulnerability or threat (i.e. it's not showing up in the threat log).Is there a way to create policy, defining the stream, and capturing a packet...

User Activity Report

Hey folks,Just installed my first PAN firewall - after running an eval unit for about a month. Loving it so far, but still learning...First question for this board - hope it's not a dumb one.We're running 3.0.9 and pan-agent and that seems to be working fine. In Traffic log and URL Filtering log user ID seems to be working fine. The problem I'...

Resolved! Vsystems With HA( Active/Passive)

Question :Please refer the attached Diagram. /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-ma...

roshithw by Not applicable
  • 4336 Views
  • 2 replies
  • 0 Likes
  • 24380 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels