General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Regarding EDL domain list which is not working.

Hi Team, I have a query where i need to block domain based malicious domains to be blocked with regards to EDL which we have internally. I have called the EDL over the Application/URL category of the policy which has the EDL name which consist of certain number of malicious domains which need to be denied.For this i had not seen any hit counts t...

GlobalProtect - how to edit the download page

Is it possible to edit the GlobalProtect download page?On the page where users are prompted to download the 32bit, 64bit, or Mac version version of GP, I would like to add some instructions for the not so savvy user on which version to select and how to install the client. If there's a better way of doing this I'm open to it. Setting it up via...

etnerual by L1 Bithead
  • 25485 Views
  • 14 replies
  • 1 Likes

Remedies for block attacks.

Dear Team, One of our faced some attacks from their wan interface IP. The issue is reported by their ISP team, when we checked in the firewall there are no logs. In customer network, huge number of traffic is going at the same time. The device is 3020. Already customer is facing some slowness in the network traffic. Kindly share the Remedies for...

VishnuPS by L3 Networker
  • 2769 Views
  • 2 replies
  • 0 Likes

Not able to connect AD Domain

hey guys one of my clients is not able to connect in the domain some users are connecting while some are not. The users are in Location A in another city and the Domain server is from another site I attached B the image ignore.that is it from the firewall side or domain side issue because some are connected some are not.

Palo Alto Device certs (Default Trusted Certificate Authorities List)

I am dealing with an issue in which the Palo Alto is in proxy mode. The issue is concerning endpoints being able to access a cloud tenant to register (install) a component.. The FQDN of the cloud tenant has been added as an allowance for these endpoints, they are member servers that have exceptions made for Internet access to certain sites. Mu...

Resolved! User's in session table hitting wrong NAT rule

Hi All, I have a client that has several NAT rule's (as per below). The have discovered in the session table 2 IP's from the 10.128.48.0/22 subnet seem to be hitting 'guest_nat' rule below when they should be hitting the 'users_nat' rule below. When testing the NAT policy match with the affected IPs they hit the correct NAT rule (users_nat). The...

BenPrice_0-1628835394873.png
Ben-Price by L4 Transporter
  • 6614 Views
  • 4 replies
  • 0 Likes

Resolved! Certificate Validation for Zoom Recommendation

Hi friend, Can you please all guy , telling me that why zoom is working coz i do not allow policy for this destination Cert address yet?Thank you. There are URL as the below list:crl3.digicert.comcrl4.digicert.comocsp.digicert.comcertificates.godaddy.comcrl.godaddy.comocsp.godaddy.comcertificates.starfieldtech.comcrl.starfieldtech.comocsp.starfi...

sunate_h by L1 Bithead
  • 4540 Views
  • 3 replies
  • 0 Likes

TACACS user authentication on WF-500

Hi Team, The customer has a query about whether if is it possible to configure TACACS user authentication through WF-500. The customer has no panorama setup or anything he was able to successfully configure on Palo Alto NGFW but not on WF-500. I request you to kindly provide some updates on this issue. Awaiting your response. Thanks & Re...

RJ274 by L0 Member
  • 2185 Views
  • 1 replies
  • 0 Likes

Unusual traffic on port 135

Hello, I have been facing an issue where I see lots of traffic toward internal serves on port 135. The source of the traffic is the firewall management IP. Its agentless user-id setup on the firewall. Previously WMI probing is enabled which cause the issue. I can still see the same traffic on port 135 after disabling the WMI probing. In server ...

mshihora by L1 Bithead
  • 5564 Views
  • 3 replies
  • 0 Likes

User id connected but users name not showing in the security policy

Dear Team, I have integrated AD to my PA NGFW. User id is showing connected but when I create any user based policy there is no users. I have tried cleared user is cache, refresh etc. But still same. Please find the below SS for referenceuseridd.log2021-09-06 11:33:322021-09-06 11:33:32.523 +0530 connecting to ldap://[10.1.2.102]:389 ...useridd....

VishnuPS_0-1630913490724.png
VishnuPS by L3 Networker
  • 8222 Views
  • 3 replies
  • 0 Likes

Unknown Users Detected In User-IP Mapping

Hi All,I was checking the User-IP mapping in one of the boxes and noticed something which is a mystery to me. I have attached the picture in this discussion. Some of the entries in the output show as Unknown. Any of you know why and how this happens ? The white boxes that have been cut out are the usernames which i had to remove due to privacy c...

NAble by Not applicable
  • 12268 Views
  • 6 replies
  • 1 Likes

Resolved! Tunnel Monitoring Setup issue

Hello, I need to enable Tunnel Monitoring for S2S VPN between PA and Cisco ISR Router.Since, we need to hide our local network behind one IP address given by client (172.x.x.x/32) so we have used that IP address as loopback interface.There are 2 Tunnels to reach client's remote network and we are using Static route (Primary tunnel with Metric 9 ...

Radius authentication with Clearpass for Firewall Webgui

Followed this KB https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS6CAK The authentication shows successful on the inbound to Clearpass and meets all the policies required for successful login. However the Palo sits at the login then eventually fails after about 5-10 seconds and indicates incorrect login credentials....

Inked15_LI.jpg
16.png
14.png

TACACS user authentication in WF-500

Can we configure TACACS sever profile in WF-500? So that we will provide TACACS user authentication to login into WF-500. If it is possible, please share configuration steps or article for the same.

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels