General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Access into the panorama database

Hi All,What access is there, if any, into the database within panorama, for a prospect that is using an automated response/ticketing system?We would want to be able to periodically query the database, for example to extract out infected workstations, and notify the appropriate people within the organisation.

KatanaNZ by L3 Networker
  • 3969 Views
  • 2 replies
  • 0 Likes

DNS Zone Tranfers not working through PA

Hello,I have a PA in front of a DNS server and since the date we installed the PA, the DNS zone Transfers to the remote site is not working.The remote DNS admin stated that there are timeouts and that the firewall should allow fragmented packets to pass through.Any idea on what could be the issue on PAN side?thanksVinesh

vinesh by L2 Linker
  • 3546 Views
  • 1 replies
  • 0 Likes

Custom Reports - Incorrect Dates

Hello,We are currently running 3.1.1 Panorama code. Are there any known issues with creating custom reports and the output shows dates in the future? For instance if we create a report and choose a custom date selection (last 2 weeks for example). The report will come back with data showing dates several days in the future (as well as the orgi...

MGoodnow by L4 Transporter
  • 5100 Views
  • 4 replies
  • 0 Likes

RADIUS (not Active Directory) and Allow List

Hi, I'm configuring a RADIUS different than Active Directory, I use Radius users for SSL-VPN and GUI and all works fine but always I've to add manually the Radius user to Allow List in Authentication Profile, is there any way to avoid this. If I've to add users in Palo ALto then I don't need Radius.Thank you in advanceSamuel

internet load balancing

Hi,Our customer has existing Sonic wall TZ210 , they confiugred Load balaning between internet links. 90% of traffics are going through the primary link & 10% ie, defined traffic from few computers are going through the secondary link.Now we want to configure the similar load balancing or load sharing stuffs in PA500 box.we tried it but we c...

Block msn-file-transfer security rule in VWire mode

Hi All,I configured my PA2020 to block msn-file-transfer from any any but it doesn't work. I checked Monitor traffic log already show "Deny" on msn-file-transfer. However, it is successful to transfer a file in msn in my test lab. Below is my rule set of firewall in simple1. any any msn-file-transfer deny2. any any any allowThanks a lot!Johnny

Resolved! 3.1.1 and captive portal

Hi,I upgraded my pan to 3.1.1 version and I never find these commands:"debug captive-portal"tail mp-log captive-portalAfter the upgrade the radius authentication doesn't functionany suggestions?thanks

Resolved! BrightCloud - are they having issues?

Seems lots of URLs are being flagged up that appear to be in totally the wrong categories.These are URLs that all have no link/commonality whatsoever and that worked perfectly yesterday but today are in categories such as spam-url and cult and occult when they clearly aren't.

Terminal Server Agent RoadMap

Hi All.I'm really interested into know what is the evolution of Terminal Server Agent. I mean, now only Windows Server 2003 and XenApp 4.5 version are supported for the moment, but new environments are installed on XenApp 5 or new XenApp 6 in o couple or months when new relases was tested.Is there any news about XenApp 5 /XenApp 6 support??? Is ...

Resolved! URL Filtering Process Order

we've run some tests on both at client side and in our office lab.the process for handling url fitlering will start with BLOCK list --> ALLOW list --> URL Categorythe logic of it is quite understandable, however, the problem lies with BrightCloud DB. Is it good enough to filter out all the web sites if we were going to "block" all web surf...

Vlan information in logs

Device: PA-2050OS: PANOS-3.0.6HiI have a question about Vlan. In the different logs you cant find "source vlan" anywhere. I belive this is cause Palo Alto is a zone based firewall and you should use zones to separate different network types rather than interfaces and vlans.However...When doing troubleshooting, vlan information would be really go...

u2521 by Not applicable
  • 7812 Views
  • 6 replies
  • 0 Likes

Resolved! Address Issue [20191]

Hi, support team.There is the following note on the release note of PANOS3.1.2:- Address Issue : [20191]System instability may occur in deployments using the Terminal Services Agent toidentify users.I would like to know that more specific.Thank you,Tomoyuki Komure

Resolved! PanAgent - Ignore specific users?

I believe its possible to ignore specific usernames with the AD PanAgent? How can this be done? I have machines that are running AV agents and rebuild agents that login and logout at various points this overriding the actual user details.

djmac by Not applicable
  • 4497 Views
  • 2 replies
  • 0 Likes

PAN-agent 3.1.0 problems

I'am using pan agent 3.1.0 and PAN-OS 3.0.9. I have some issue that are not affecting traffic, but i want an explanation for it. First, the agent status indicate that it cannot read security logs on a DC, even if it has the rights to read it, and there is no log messages in the pan agent log file indicating the issue, is it a folse positif? and ...

asia by L3 Networker
  • 3460 Views
  • 1 replies
  • 0 Likes

maint password for 3.1.1

Since rebooting one of our firewalls it has gone into maintenance mode. We are trying to SSH to the management port using the maint username and MA1NT as password as specified in the doco. We are getting access denied. Has the password changed for the later version or is access restricted via SSH?login as: maintThe system is in maintenance mode....

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels