General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PA-5020 to 5220

we are planning to upgrade ur existing PA-5020 to bigger boxes. our current 5020s are struggling to handle the ssl decryption and it sometimes give ''Dataplane CPU under severe load'' logs on busy days. I heard 5200 series are specfically designed fo

...

Inbound SSL decryption - Digicert

If inbound SSL inspection when using Digicert certificate is not supported, what is the alternative. We have many web-servers using same wildcard cert used for GlobalProtect and wanted use this same certificate but it doesn't work. Is there any other

...

raji_toor by L4 Transporter
  • 8903 Views
  • 15 replies
  • 0 Likes

Resolved! 40031 Threat Exception

What I am wanting to know is if I can add a range of IP addresses to a vulnerability exception.

This would be the entire 1-254 range, rather than 1 IP address at a time.

 

I have already checked the links below and they talk about adding IP addresses on

...

Email Link Analysis - does it look at all emails?

I am curious to know if the organization I work at gets a blast email to 500 employee's from an external B2B marketer does the wildfire analysis get performed on all 500 identical emails or does it simply do it once knowing the email and links are id

...

Resolved! Palo Alto lab in VMware Workstation

Hi guys,

I need some help with configuring network in VMware Workstation and Palo Alto. I tried to build VMware lab using both Udemy and CBT Nuggets video courses:


The problem is that I can't have my Palo Alto to have an access to the Internet. It does

...

4kusnik by L1 Bithead
  • 17263 Views
  • 14 replies
  • 0 Likes

Panorama: cannot use in templates objects from DG

Dear Community,

 

I have a Panorama with several firewalls in a device group under the share one.

I have several templates and I cannot select any shared object from DG into any part of template configuration, for example adding an address object as an

...

Carracido by L3 Networker
  • 2119 Views
  • 1 replies
  • 0 Likes

Pre-logon for specific user only

My requirement is that some user should use Pre-logon and other should use User-logon. Currently all users are using only user-logon mode.  

Is it possible to use both mode in global protect, because we have to call client certificate profile on globa

...

gp1.png

Resolved! disable qos

Hi,

 

I have the below configuration for qos   , and there are policies also configured . If I want to disable for sometime ,  Just unchecking  the checkbox under Enabled  will help ?

 

Or even after un checking   the traffic will fall under class 4 ? 

Or

...

Capture.JPG
simsim by L4 Transporter
  • 3037 Views
  • 1 replies
  • 0 Likes

Qos question

Hi,

I have traffic shaping enabled on FG and at the same time PA also.

traffic flow is as below 

client  goes through  FG then PA then go to internet or wan 

traffic shaping  policy running on  fortigate  , and qos policy is there on PA also 

Let's say if

...

PA-DEL-1.png
simsim by L4 Transporter
  • 6840 Views
  • 13 replies
  • 0 Likes

Session created by Syn Cookie

Hello,

 

what process and what is going on if a session (SIP) is created by "Syn Cookie" ?

Is this a valid Session, does this indicate a Problem ?

 

We configured an App-Override Policy to mitigate Problems between Phone-System and SIP ALG.

We see now all

...

rekuhn by L2 Linker
  • 1767 Views
  • 1 replies
  • 0 Likes

GlobalProtect Xauth for iPhone and Android

 

We have setup GlobalProtect Portal and Gateway working perfectly with SAML auth on MacBook Pro and Windows laptop.  

 

The only issue is, GlobalProtect Mobile app is not available in our app stores.  So I'm looking for setting up IPSEC Xauth on PAN so

...

ZhenGuo by L1 Bithead
  • 3439 Views
  • 1 replies
  • 0 Likes
  • 24011 Posts
  • 102 Subscriptions
Top Liked Authors
Labels