General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

how to check list of users of particular group who are connecting Global protect.

We want list of users of particular group who are connecting Global protect.Reason behind this requirement is to get number of users from particular group who are connecting GP. So accordingly we can purchase the licence for 2FA from third party vendor.We have added multiple groups for GP authentication , if 100 users in HOD group and from them ...

Deepak_K by L3 Networker
  • 5547 Views
  • 5 replies
  • 0 Likes

Wildfire behaviour

We can not understand at all how Wildfire works. We realised that WF detects files that have been downloaded and categorized as malware can continue to be downloaded for a long time, this behavior is not the expected, which indicates that once it is categorized as malware, the signatures are automatically updated in a short time and the next tim...

BigPalo by L4 Transporter
  • 3299 Views
  • 2 replies
  • 0 Likes

Resolved! failed panorama migration

hii attempted to migrate an HA pair to Panorama which went bad. I had only pushed to passive and when i tried to make it active, everything went down.had to make the previously active firewall actve again, and load last save on passive to recover the passive firewallnow, after after disabling panorama setting in firewall>device>setup, i ha...

josggf by L2 Linker
  • 14530 Views
  • 14 replies
  • 0 Likes

Resolved! How to see a specific incoming IP

Hello, I am new to Palo Alto Firewalls still learning. I as asked to see a specific IP that is attempting to connect to my FW. Can someone please point me in the direction to see an incoming IP? I see on the GUI "Monitoring" and "ACC" tabs. Is there Training Material or commands that show how?

DNS Security scaling?

Hello, We're looking at replacing some Fortinet and Juniper devices with PA's but can't find any details as to how many entries can be cached with the "DNS Security" feature. I have a lab 220 I'm using but the output of the commands don't seem to show how many entries the cache can hold.debug dataplane show dns-cache statistics Aggregated DNS ...

9_volt by L0 Member
  • 4048 Views
  • 2 replies
  • 1 Likes

Slow ISP bandwidth through PA-3020

We upgraded to a 1gb/s internet connection from a 50mb/s on Friday. For some reason we are only seeing a max of maybe 250-300mb/s but in most cases we are at 175mb/s. We have a PA-3020, with App-ID enabled and Threat. We did our research before upgrading and thought we would see closer to 1gb/s with this firewall. Any ideas on what we can chec...

Resolved! Wildfire actions

Hi ,i have 3 question for wildfire 1)If we define wildfire profile , and call that profile in a security rule , only that particular rule will be effective for wildfire analysis and not all the rules in the policy ? 2)Also , as a starting point , we want to limit sending all the file types to Wildfire , is there any initial level Wildfire catego...

PA 3000 Make users accept TOS before browsing the web

Hello, we use our PA 3000 as a router to distribute our ISP to multiple locations. Is there a way that I can make it so when a user try's to browse to the web either a pop up or a redirect happens so that they have to accept terms of service prior to being allowed to continue?

Jenkins by L0 Member
  • 2634 Views
  • 2 replies
  • 0 Likes

UserID issue when using RDP via GlobalProtect client

Hello,I have the following issue when using RDP via GlobalProtect client.Situation:PaloAlto 820 with PAN-OS 9.0.9, GloablProtect Client 5.2.4, Windows 2016 Active DirectoryFor remote access we use GlobalProtect with Active Directory accounts (RADIUS authentication to AD)User-ID is used utilizing an UserID agent installed on the DCUser-based poli...

Cyber Elite video interview with Brandon Pry !

Just in case you missed it, our very own Cheryl Rasmussen took some time to interview one of our new Cyber Elite Members, Brandon Pry (@BPry) . Take a moment to check out Cheryl's blog and watch the video interview here: https://live.paloaltonetworks.com/t5/blogs/spotlight-interview-with-bpry/ba-p/373666 Super happy to have you on board in t...

Bpry.jpg
kiwi by Community Team Member
  • 4861 Views
  • 3 replies
  • 5 Likes

Resolved! Device certificates for Panorama-managed devices

Hi,The screen below is from support.paloaltonetworks.com in Assets/Device Certificates.I am trying to get the device certificates for the firewalls that are managed by Panorama, without doing it locally on each firewall.In Panorama, where to I go to get the "text/code provided by your Panorama"???That little blue "I" info button provides no info...

ksalustro_0-1610398739744.png
ksalustro by L3 Networker
  • 5161 Views
  • 2 replies
  • 0 Likes

Resolved! Share User-ID among VSYS

How to best share user-id's or ip/User-mapping between different vsys. I want share user to IP-mapping for users connecting through global protect in separate vsys. But i think usecase can be extended to non GP mappings too.

raji_toor by L4 Transporter
  • 3706 Views
  • 2 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels