General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Failed to get CRL http:// ...

Im getting tons of failed to get CRL errors in my logs all of the sudden. Im not sure what I did (if anything) to cause this.

Ive tried to fix it,

  • I tried to enable  "Server CRL"
  • I did a nslookup on crl.verisign.com and I cant see any connections outbou
...

choff123 by L3 Networker
  • 2159 Views
  • 4 replies
  • 0 Likes

Resolved! Security Policy Configuration.

Hi Gents, here is my PA design as active active.

to be clear, the server farm is connected to the Core switches, and the Clients are connected to both Agg switches.

the PA Configuration is in VWire mode.

the question here is, when I create a security po

...

Methods for creating security policies

When creating security policies would it be better to create a separate policy for inbound and outbound traffic, trusted and untrusted, per user group or one policy to manage both ways to minimize number of policies

Resolved! No app ID for for WinRM, port 5985?

I am trying to add WinRM to a allowed policy and I am not finding the app for it. Does PA call it something different? I was thinking there was a way to search the app db by port but nothing is coming up.

jeffm by L0 Member
  • 2756 Views
  • 1 replies
  • 0 Likes

Resolved! GRE protocol traffic

Hello to All,

I noticed some strange behavior regarding GRE protocol, and try to explain what exactly is strange:

Customer has unfortunate GRE VPN tunnel and in one policy "Public_ulaz_GRE" they stated to pass only GRE and NVGRE protocol respectively.

...

Tician by L3 Networker
  • 4661 Views
  • 2 replies
  • 0 Likes