General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4445 Views
  • 0 replies
  • 0 Likes

Anybody try to block Invidious yet?

The students in our school district have discovered that Invidious sites (https://invidious.io ) are able to circumvent the Youtube content blocking we had in place with our Google Chromebooks. Has anybody else experienced this yet and/or discovered a solution for 'blocking' Invidious?Thanks,

Resolved! SMTP port 25

We are progressing to moving show services to the cloud and I'm been told that port 25 is not opened or being blocked in Palo Alto. So where do I check to find out if this is being allowed or being blocked?Sorry this is a really basic question but I've been asked to resolve this because the regular guy has left the company..

Port to Port latency stats

I am trying to find out what the typical port to port latency is of the 800 and 3200 devices. I appreciate that this probably changes depending on what inspections are running, and configuration, but I am after a ball park figure for standard L2/L3 interfaces with a simple rule set, and how much extra IPSec adds.

Rich.H by L2 Linker
  • 2356 Views
  • 1 replies
  • 0 Likes

Resolved! Mobile Hotspot - Can I force SSL?

I'm working using a mobile hotspot (T-Mobile 5G), but I have chronic failures until it finally falls back to SSL. Then I run fine for many hours until I need to reconnect. Question: Can I force it connect in SSL? I'd be happy to help improve the product by diagnosing the issues, if anybody wants to reach out to me. My IT department j...

Security Report

I would like to create and export a security report giving me a simple count on the number of times an attack was attempted.The definition of an "attack" could range anywhere from a network discovery to a tentative of password brute-force, as many vectors as possible.I am using a PA-3020 on version 9.1.9 but the report won't be limited to this v...

Resolved! With GlobalProtect on Windows is it possible to exclude Chrome but include Firefox from routing through the VPN?

I have to use Global Protect on my home Windows machine purely for accessing certain work-related websites that aren't accessible without it. Ideally I'd like the rest of my browsing (e.g. Youtube) to not have to go through it. My idea for achieving this is to use Chrome (unproxied) for all my non-work browsing and Firefox for accessing work sit...

dee4006 by L1 Bithead
  • 6803 Views
  • 5 replies
  • 0 Likes

How to apply security policy over more than 200k public IP? (EDL? API?,...)

Helo, we have started a plan for a new project. I have created a picture, so you can see, what I acutally mean :). User will via some customer portal setup a new broadband link. He will be able to choose if the broadband should be secured and by several levels - TP, URL, DNS, WF,...If he choose the security level and confirm it, the customer por...

pict.png
LukasB by L2 Linker
  • 4942 Views
  • 7 replies
  • 0 Likes

Question about Global protect Pre-Logon Issue

Hi, I configured GP pre-logon method, But it’s only working in administrator mode even though the user is part of administrator group, it’ not working for normal users. I followed below KB article,https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 In global protect client installed laptops, we are able to connect g...

GlobalProtect.jpeg

No ICMP hitting Palo Interface but ICMP is allowed

I have a greenfield Palo with a fresh ISP.Have confirmed from the Palo I can source from my interface and ping outbound to anywhere in the world.Interface mgmt has been set to allow ICMP, I've left the allowed IP's blank and also set my specific IP, neither allow ICMP traffic to the interface. The more frustrating thing is that nothing is hittin...

VPN IPSEC secondary peer

Hello,I have a vpn ipsec in production, now I have to add a secondary remote peer.It's my first time I have to configure a 2nd peer.If I understood well I can't simply add a seocndary peer to the VPN but I have to configure a new psec but the difference is the static route related the remote network.Example I should have:Remote net: 10.1.0.0/24R...

5450 - Included cards in base bundle

It seems odd that the base bundle (PAN-PA-5450-AC-SYS) includes a NC and not a DPC. Can someone from Palo, or someone that has received a 5450, confirm that a DPC is *not* included and the base bundle (it will not function on its own)?

  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels