General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Globalprotect 5.2 Cookie Issue

Hello 
We just upgraded our GP from 5.1.7 to 5.2.10

We have a gateway with SAML authentication
We have some connections issue with a message "already logged in" from the Identity Provider

I think this is due to the new feature "Default System Browser for

...

QoS max egress, no effect

Hi there,

 

I'm playing with QoS in our lab. I have a simple setup with two queue, first for SMB traffic, second for RDP traffic.

The max egress value is set, but when I transfer data, then both queues get bandwith values.

 

What I am doing wrong here?

 

 

 

...

PA QoS Monitor.png
PA QoS Profile.png
PA QoS Policies.png
Netzer by L2 Linker
  • 1742 Views
  • 2 replies
  • 0 Likes

site to site VPN on TP-link --- PALO ALTO ---- AWS

 

As of now STORE router/POS1 able to reach the head office(PALO ALTO) via site to site VPN and HeadOffice(PAN) to AWS also working via site to site VPN. But our main goal is that POS1/Store able to reach the AWS network. As of the momment POS1 not ab

...

IPSEC S2S store to HO to AWSrev1 .jpg

global protect connectivity issue (version 5.2.10)

Hi Team,

 

We have facing the connectivity issue on GP Agent 5.2.10.

 

After turning off the windows firewall, it's connecting.

 

Please let us know how we can achieve this without disabling the windows firewall. Because in earlier versions of GP client we

...

VishnuPS by L3 Networker
  • 2116 Views
  • 2 replies
  • 1 Likes

User-ID Agent not mapping users

Hello,

 

Im trying to configure User-ID Agent.

 

Dedicated users is created, with details acroding to: Create a Dedicated Service Account for the User-ID Agent (paloaltonetworks.com)

Agent version: 10.0.4-23

Agent is installed on Windows Server 2019.

DC's a

...

mgwozdz_1-1644489742592.png
mgwozdz_2-1644489787346.png
mgwozdz by L1 Bithead
  • 1896 Views
  • 1 replies
  • 0 Likes

Path Monitoring Static Routes

Hello All,

 

For some locations we have 2xISP setup, since we have no dynamic peering with any of those, we do a default static route via each of those. Having 'ECMP/Source IP hash' enabled it works just fine in a lab. We also do path monitoring for ea

...

Dynamic DNS Bind server updates from DHCP

Curious if the PA-3220 we are looking to use can dynamically send DNS updates to our Bind9 server whenever a DHCP request is granted from our PA DHCP scope we've setup? I know we can get a linux version of DHCP on our Linux server, but would rather l

...

tfleming by L0 Member
  • 1979 Views
  • 2 replies
  • 0 Likes

Decrypted traffic via firewall.

I don't have any decryption policy configured.
But I see port -443 traffic has decrypted flag yes in Traffic logs.
Is it normal for firewall to decrypt 443 traffic even when there is
no decryption policy?

PANOS0-9.1.10 VM-300

API URL Logs Issue

In the below code - I"m using the API to query the URL logs. It works great.

What isn't returning though is the src.user field, if it's mapped. How can I get this value? Do I need to do a separate query?

 

# Build PAN API Connection and get token pan_co...

mehixiyo by L0 Member
  • 1396 Views
  • 1 replies
  • 0 Likes

Apply TS Agent config automatically in FW

Hi,

 

We are expanding our CITRIX platfon in which we have installed a Palo Alto TS agent to monitor. So to avoid introduce manually the TS agent config in Pa (IP, port,etc) each new citrix. Is there any way to send the config to PA to do ir automatica

...

BigPalo by L4 Transporter
  • 1321 Views
  • 1 replies
  • 0 Likes
  • 24010 Posts
  • 102 Subscriptions
Top Liked Authors
Labels