General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

GlobalProtect Use Connect Before Logon is not compatible with Pre-logon(Always On) ?

Hello to All, We are use globalprotect with Always-on and "Enforce GlobalProtectfor Network Access" and blocking the users to delete or disable the globalprotect app. This way we are forcing them to always use the VPN. We are planning to test "Connect Before Logon" but the strange thing is ''Pre-logon(Always On)'' is not mentioned as to not be ...

Resolved! Certificate Validation not working

Hi all,hope you are doing well!I've a little probelm with the certificate validation.I've changed the DDNS provider to a custom one bit certifiate validation dows not work.PAN OS: 10.0.5First what I've done on CLI:set network interface ethernet ethernet1/1 layer3 ddns-config ddns-vendor-config dyn-api-host value updates.dnsomatic.com set network...

Image 4.png
Image 5.png
Image 3.png
Image 2.png

Is PANOS 9.1.6 is vulnerable for wreck security vulnerability?

Hi guys, Im having a query whether any of the PAN OS has the vulnerability as wreck in Palo alto network firewall. If so kindly update me here.I have searched with the PAN Advisory as well as other portals. like these https://www.cvedetails.com/vulnerability-list/vendor_id-12836/product_id-26167/Paloaltonetworks-Pan-os.html but no luck. So incas...

Resolved! About DNS security

Hello Bros, I my network and my firewall 3220 setup I have a question regarding the DNS security feature.If you go through creating an anti-spyware profile, and exactly in the DNS signature what is the difference between DNS signature source "Palo Alto networks content DNS signature sinkhole as an action" and " Palo Alto network D...

Hybrid model (where some exchange mailboxes are hosted in Microsoft 365) (using DNAT) Palo Alto inspect the traffic be regarded secure enough?

We have clients who want a Hybrid model (where some exchange mailboxes are hosted in Microsoft 365) rather than full blown integration. Would the proposed solution (using DNAT) with the sources constrained to the Microsoft approved IP/URL list and having the Palo Alto inspect the traffic be regarded secure enough?

NavidAlam by L3 Networker
  • 3541 Views
  • 2 replies
  • 0 Likes

Error Palo Alto Global Protect on MacBook

Hi Guys, I am facing an error when i want to use global protect on my mac. Every time i want to log on, It shows Gateway SSL VPN GW: The server certificate is invalid. Last two weeks i just use this and no problem. Please help me to solve this issue because it was very urgent. Appreciate if you could help me to solve this. Btw: my MacBook OS...

Kevin234 by L0 Member
  • 2641 Views
  • 1 replies
  • 0 Likes

Commit Error Messsge for Application being used

We noticed last month that a core firewall PA-3060 has started reporting the same error message as in this link. Application being already in use. We have provided tech support files to PAN support but they are still unable to determine the reason that we keep getting these error messages when we commit to the firewall.https://live.paloaltonetwo...

bambox by L1 Bithead
  • 2513 Views
  • 1 replies
  • 0 Likes

Data Filtering logs not in Panorama

Hi All, we are running 9.0.12. I've got data filtering with the patterns etc all set up. The logs appear fine on the firewall. And logging profile is set to forward all to Panorama, but none appear in Panorama. It's empty. Logging profiles is set to forward log type Data to Panorama.Any help would be appreciated. Panorama is forwarding all event...

igs1917 by L1 Bithead
  • 4386 Views
  • 4 replies
  • 0 Likes

SSH to Management interface (RADIUS Auth) PAN OS 10.0.4

Working on an HA Pair of PA-820 firewalls and just finished configuring auth for management interfaces. Went to test, and found that the firewall said auth succeeds, but the SSH connection immediately drops. Config:Auth profile is RADIUS (Windows NPS server)PAN OS 10.0.4Tests:Authentication to web interface works for user via RADIUS profileAuthe...

D_Baerry by L1 Bithead
  • 4679 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect - Use Machince Certificates for Authentication

Hi everyone, at the moment our GlobalProtect Infrastructure is only using LDAP for authentication, which is a problem since users should only be allowed to connect to GlobalProtect via a corporate Windows notebook.As a second factor we would now like to use machine certificates. We have already rolled out machine certs to every machine by an int...

Enabling multi vsys on a prod firewall.

I’m planning to create multi vsys on my palo alto. I just wanted to know if my existing configuration (interfaces, aggregate interfaces and rulebase) will be moved as it is to vsys1 or they need to be mived manually? I have aggregate interfaces layer 2 in my environment so I need to assign vlan interfaces to vsys and keep parent port in no vsys ...

HA1/HA2 speed recommendations for a PA5200 series setup (A/P)

I'm not sure if this documentation exists somewhere but I can't seem to find it.we have a customer with palo alto 5200 series firewall.due to covid-19 (as is the case with so many companies they are currently production stress testing the firewall with extra load due to teleworking, etc)the firewall handles it fine. however the ha1 and ha2 inter...

Resolved! Authenticating a PC based application

We have an old vertical application that can connect to a web server via https and that populates the datain the desktop application (thick client). Mgt Team would like there to be two factor authentication. But if the thick app does not support two factor I think that's a non-starter. Or could there be some way that a legacy app not designed fo...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels