General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1952 Views
  • 0 replies
  • 0 Likes

Pre-logon for specific user only

My requirement is that some user should use Pre-logon and other should use User-logon. Currently all users are using only user-logon mode.  

Is it possible to use both mode in global protect, because we have to call client certificate profile on globa

...

gp1.png

Resolved! disable qos

Hi,

 

I have the below configuration for qos   , and there are policies also configured . If I want to disable for sometime ,  Just unchecking  the checkbox under Enabled  will help ?

 

Or even after un checking   the traffic will fall under class 4 ? 

Or

...

Capture.JPG
simsim by L4 Transporter
  • 4198 Views
  • 1 replies
  • 0 Likes

Qos question

Hi,

I have traffic shaping enabled on FG and at the same time PA also.

traffic flow is as below 

client  goes through  FG then PA then go to internet or wan 

traffic shaping  policy running on  fortigate  , and qos policy is there on PA also 

Let's say if

...

PA-DEL-1.png
simsim by L4 Transporter
  • 8314 Views
  • 13 replies
  • 0 Likes

Session created by Syn Cookie

Hello,

 

what process and what is going on if a session (SIP) is created by "Syn Cookie" ?

Is this a valid Session, does this indicate a Problem ?

 

We configured an App-Override Policy to mitigate Problems between Phone-System and SIP ALG.

We see now all

...

rekuhn by L2 Linker
  • 2154 Views
  • 1 replies
  • 0 Likes

GlobalProtect Xauth for iPhone and Android

 

We have setup GlobalProtect Portal and Gateway working perfectly with SAML auth on MacBook Pro and Windows laptop.  

 

The only issue is, GlobalProtect Mobile app is not available in our app stores.  So I'm looking for setting up IPSEC Xauth on PAN so

...

ZhenGuo by L1 Bithead
  • 4176 Views
  • 1 replies
  • 0 Likes

Resolved! Implementing SSL Forward Proxy

I have a problem!!, I'm implementing SSL Forward Proxy, all the guides say I have to install the certificate in all the clients, isn't there an alternative to this? I have a lot of visitors and I shouldn't have to install a certificate.

I used to have

...

Need Help deleting files on PAN /dev/sda8 and /dev/root

Hi All,

Need help on how to free up spaces on the below partitions on my PAN device, support cannot seem to figure this out. Please help..

 

Filesystem Size Used Avail Use% Mounted on
/dev/root 4.0G 3.4G 407M 90% /
none 4.0G 56K 4.0G 1% /dev
/dev/sda5 24G

...

sokonta by L2 Linker
  • 6564 Views
  • 1 replies
  • 0 Likes

install PanHandler on Windows 10 system.

Published install instructions for PanHandler are for MAC and Linux systems.  I run Windows.  Here is how I installed PanHandler on my Windows 10 system.

 

Install Docker for Windows from the Docker Hub -- https://docs.docker.com/docker-for-windows/ins

...

Resolved! Questions about deploying serverfarm FW

Hello,

Currently, every server is behind trust zone, so I can't control traffic from trust user or server to server by FW.

 

I have two options

 1 attach server farm switch to edge firewall

 2 deploy new FW in front of server farm switch

 

Which is more com

...

yhlee1 by L2 Linker
  • 3030 Views
  • 1 replies
  • 0 Likes

Disable Cipher Suite

As of the pen test via SSL LAB  i was observed that less secure ciphers like DES, RC4 were supported by global protect portal ,so that i have disable the all the weak cipher suite and it's successfully done but the when i disable CBC-256 Suite when i

...

Joshan_Lakhani_0-1596646238785.png
  • 24200 Posts
  • 117 Subscriptions
Top Liked Authors
Labels