General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Connection Failed: Could not connect to the GlobalProtect Gateway.

Hello, We are facing the following issue with the GlobalProtect client: (client version 5.0.5-28) When the user downloads the client and logs in for the first time, the user is connected successfully. However, when the user disconnects and connects again, the client takes a long time and then displays this error message: "Connection Failed: Coul...

Unable to open a support case

Is anyone else having problems opening a new support case via supportcases.paloaltonetworks.com? Whenever I try to open a new case I am able to complete step 1 just fine however when I get to the section of selecting the asset effected there are no tick boxes next to any of the assets. The filtering drop downs on the columns also appear to be ...

Screenshot 2020-11-18 084201.png

Support license -who own serial number

Hello , We have a customer B who was earlier supported by a Company X Now customer renewed all the Licenses -Threat Prevention , GP , URL filtering etc through our company Y ( We are PA Partner) and also the Support contract with us ;As per customer Company X is/will be supporting them Break and Fix contract . So can i add the serial numbers ...

Best Practices query for Security settings

Hi , I have a customer who has Threat prevention , AV, Wildfire ,licesne The Network is divided into various Security Zones - like Users , Printers, Voip , Front end servers , Backend Servers , there are around 15 zones Now we have the BPA report and a lot in terms of APP ID and Service needs to be fixed Customer wants a kind of matrix as a Indu...

Resolved! Session End Reason auth-policy-redirect

Allowed all http and https traffic to Untrust, still the traffic on port 80 is getting blocked. Any idea why it is So? Rule allowing http and https traffic Traffic log

Rule.jpg
APR.jpg
Bijesh by L1 Bithead
  • 16887 Views
  • 3 replies
  • 0 Likes

LAB'ing PaloAlto

Hi, I have installed a couple of PA-vm firewalls but i am not able to test upgrading PAN-OS or enable multi Vsys support.Am I using the wrong model in the lab? Is there a way I can do the above? Are there any trial licenses without limitations? I look forward to hearing from you. Kind regards,

qasim02 by L2 Linker
  • 3087 Views
  • 2 replies
  • 0 Likes

scheduled policies to affect existing sessions

Dear community, I configured schedule on policies and it seems that as per design the existing sessions are not affected by the schedule:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-schedules.html Meaning that if a session was created before the schedule, the traffic will not hit the scheduled policy un...

Carracido by L4 Transporter
  • 2360 Views
  • 1 replies
  • 0 Likes

LIMIT SERVICES (2000) IN PA 5020 ios 8.1.10

HELLO EVERYB, i there any way to increase de limit of servies? in our case er arrive to 2000 service (ports) in PA 5020 WITH IOS 8.1.10? have i to increase at the hardware level? or sfoftware? thank u so much

JESELITO by L1 Bithead
  • 4614 Views
  • 5 replies
  • 0 Likes

Need a way to move big number of selected policies to the desired location

Dears,As a cleanup to our policies in the firewall, I added a tag "Zero hit" to the policies that never trigger a hit. I have a huge number and I would like to move them all to the bottom.I tried to find a way to move them to the location I want and found it not available.My question:1- Is there a way to (not manually) select a big number of pol...

Resolved! Service Route Source interface not show with VM-300 on AWS

Hello, There is no interface show when i try to change the source interface for specific service (as show as in image).The VM-300 box is on AWS, and both Internal and External interface are set to use DHCP, Layer 3 routing. Anyone has idea how to correct it?Thank you.

Screen Shot 2020-11-16 at 9.45.53 AM.png
Screen Shot 2020-11-16 at 9.46.22 AM.png

Request a Signature for CVE be Mitigated

Is there a proper way to request a CVE be mitigated by the Palo firewall and added to the Threat Vault? I have read the conditions for a signature being added, but it doesn't tell you where to request one. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAOnCAO If it matters, I'm trying to mitigate Oracle WebLogic Ser...

RMaine by L0 Member
  • 3585 Views
  • 3 replies
  • 1 Likes

Error in CEF format for Threat logs

The following guide provides the parsing for CEF-style Log Formats for PAN-OS 9.1:https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cef/pan-os-91-cef-configuration-guide.pdf We have been using this for a while, but because now we have a 2nd source of logs (PRISMA) aside from Panorama, we just found out the parsing suggested for "T...

MarcelST by L3 Networker
  • 4298 Views
  • 1 replies
  • 0 Likes

List all deny rules from cli

I have to list all deny rules (from cli)The following command "show running security-policy | match index " list all security rules by nameFor example:"AllowBrach1IN; index: 1" {....etcWhat I want is:- deny INBOUND traffic rules only but regarding entire subnets (those having CIDR as their destination ...like 192.168.1.0/24..etc)Is there any way...

jls3j999 by L1 Bithead
  • 9833 Views
  • 14 replies
  • 0 Likes

Resolved! PaloAlto 5260 upgrade

Hi, I am upgrading so PA firewalls from 8.1.7 and 8.1.9 to 8.1.13, normally I wouldnt ask these questions but since these firewalls are extremely critical I need to be extra cautious. been looking at the upgrade Matrix and couldnt see a clear answer but based on my experience I believe its a straight upgrade to 8.1.13 without any path, is that c...

qasim02 by L2 Linker
  • 4845 Views
  • 4 replies
  • 0 Likes

User group Mapping

Wndows logon user name is ABC\xyz, and the user id fetched from AD group is ABC.local\xyz, and because of that the traffic is not hitting the configured rule. Any workaround to fix this?

zamiedu by L0 Member
  • 2856 Views
  • 3 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels