General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! session flags

I can't find documentation about connection Flags in command show session all-------------------------------------------------------------------------------ID/vsys application state type flag src[sport]/zone/proto (translated IP[port]) dst[dport]/zone (translated IP[port]I can see nothing, N...

Resolved! Is there a Bug in the URL filtering profiles

Hi everybody,PA-500Software: 3.0.5Threat-Apps: 163-489URL Filter: 3243I have a question to the URL filtering profiles.When we add URLs to the block or allow list,and make a commit the listed URLs were not blocked or allowed.We need a second step, we open the URL profile againand change any category we want, only one is necessary!Then we make ano...

indevis by L2 Linker
  • 4717 Views
  • 1 replies
  • 0 Likes

Resolved! User Agent System Requirements

We're running into issues with the Palo Alto User Agent. It'll run for a few days, then we'll stop getting user information. When I look at the server running the agent, and try to start the agent, I get a message along the lines of "The paging file is too small for this operation to complete." We have a dedicated page file volume that's 4GB,...

Virtual-Wire connectivity during reboot

Hi all,I know some IDS/IPS are able to keep the network connectivity during a reboot. Then it does not stop the trafic.Does the PA able to do the same in Virtual-Wire mode ? Or in other mode ?The aim is to upgrade the appliance in a production environment.Regards,Olivier

olev by Not applicable
  • 4689 Views
  • 2 replies
  • 0 Likes

QoS data in logs

Hello PAN,Is there any way to obtain QoS data from the PAN logs other than doing a "show session id" CLI command in the current release 3.0.5? My customer would like to be able to see how much traffic is hitting the QoS classes and which traffic is hitting the QoS classes.Thanks

jwolach by L4 Transporter
  • 3580 Views
  • 1 replies
  • 0 Likes

Resolved! sample logs of licenses expiration

Hello,Could you give me the sample logs that the PA log before the following licenses expira ? - Support - URL Filtering - VSYS upgradeWe have the log of threat prevention license: - License for feature threat will expire on 2009/12/11Regards,

Defining Policies, Profiles, etc via CLI

Our primary interface with devices and management systems is through the CLI. Essentially, what I need is a guide that explains the syntax and how to create/update/delete policies, security profiles, etc via CLI. (Neither the CLI Reference nor the Administrator's Guide seem to contain the information.)

Troubleshooting PAN-Agent connectivity

Hello, I have PAN OS 3.0.5 installed on a cluster (active passive)The passive device seams to have problem to contact PANAs you can see from ommand below 10.44.36.125 Agent can't be reached (on active is ok) st1\:*{behavior:url(#ieooui) } /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Tabella normale"; mso-tstyle-rowband...

Log files meaning

Hello,With command tail I can read log from PAN FW. ...questions :what's difference between mp-log and dp-log ?what does the mp-log files below contain/mean (i.e ha_agent.log is for ha system) ?appWeb.log.old masterd_manager-infra.logbrdagent.log mgmt_fb.logcaptive_portal.log mp-monitor.logchasd.log ...

Resolved! Pan Agent Expire setting

Hi,I see in the logfile the information :2010 01 04 10:07:25, ########################### Start Pan-Agent #############################2010 01 04 10:07:25, Add Domain: ce2010 01 04 10:07:25, Num. of Threads: 402010 01 04 10:07:25, GroupMemebers cache flag is 1.2010 01 04 10:07:25, Add DNS-style Domain: xxxxx.com2010 01 04 10:07:25, Add NetBIOS D...

u2343 by Not applicable
  • 5808 Views
  • 3 replies
  • 0 Likes

Unable to redirect to desired website after successful authenticated with RADIUS server..

Hi All,I encountered a situation :User in the RADIUS server authenticated successful with CISCO ASA RADIUS Server or Microsoft RADIUS but unable redirected to the desired page such as www.google.com or www.yahoo.com... The page just stay at the captive portal page... The PAN firewall log shows it successful authenticated... There is no policy b...

jeffhooi by Not applicable
  • 5110 Views
  • 1 replies
  • 0 Likes

Secondary interface addresses

I'm trying to add more of the public IP addresses issued by my ISP to the external port on my PA-500. When I try to commit the config, I get this error:routed: In virtual-router Incoming: address 12.x.x.x/27 on interface ethernet1/1 has overlapping subnet with address 12.x.x.x/27 on interface ethernet1/1.Commit failedI have a range of 30 addres...

bwmillslg by Not applicable
  • 15926 Views
  • 4 replies
  • 0 Likes

Can I check if a connection was dropped by the firewall?

I frequently have people coming to me asking if I can check if a connection is dropped on the firewall.Allow me to give you an example:We have a trunk setup between a cisco callmanager and one from Alcatel. All traffic between the 2 systems flows through the Palo Alto's.When someone calls from a phone connected to the Alcatel callmanager and cal...

pieters by Not applicable
  • 6005 Views
  • 1 replies
  • 0 Likes

DHCP - Not setting Subnet, issues with PXE Boot

We are having an issue with our new Palo Alto 2050.We are using the DHCP server on the 2050 in conjunction with a PXE to iSCSI system.Using a different firewall/router with integrated DHCP server - the system works fine.With the 2050 - it doesn't.We took a packet sniff of the failed DHCP 'conversation' and it seems from our packet trace that the...

  • 24450 Posts
  • 125 Subscriptions
Top Solution Authors
Labels