General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4258 Views
  • 0 replies
  • 0 Likes

Enable FTP and FTPS for Active/Passive?

Hello Folks, We have a CrushFTP server installed on a server behind our PA 3020 PANOS: 7.1.14, SSL decrypt not enabled.Security Rule: NAT Rule: Trying to figure out why Active and Passive with FTP over TLS (SSL) will not retrieve the directory listing and will not complete connection. Works fine with just FTP (insecure). Do I need to add SSL to...

FTP_rule.jpg
FTP_NAT_rule.jpg
Active_FTP.jpg
Active_FTPS.jpg
OMatlock by L4 Transporter
  • 19515 Views
  • 5 replies
  • 2 Likes

forbidden

Hi,site says forbidden while browsing the site , when I bypass there is no issue .2)When I am uploading files to web site it fails , when by pass it works Any hint to the root cause of the problem Thanks

simsim by L4 Transporter
  • 2159 Views
  • 1 replies
  • 0 Likes

Couldn't access link "www.santander.com.ar" from global protect VPN

Hi Experts, Users couldn't access the link "www.santander.com.ar" from global protect VPN, this is a normal bank related link so everyone can access though outside network, In our office structure Trust-VPN & Trust-Internal both sources zone are allowed to access "www.santander.com.ar" with general policies. As per policy Trust-Internal use...

Resolved! VPN Proxies

I have a VPN tunnel which is up and running. In the tunnel, I have 2 proxyID's which have the same local address but different remote addresses.I can only get 1 proxyid to connect. As an example, I current have proxyID1 connected and I can ping the other side. In the cli, if I type test vpn ipsec-sa tunnel tunnel-name-proxyID2. It does not co...

Resolved! DNS Security service

Hi All.Can any body know if the DNS Security Services have possible to enable and subscribe on Virtual Wire deployment?Thaks

Rojaba by L0 Member
  • 2470 Views
  • 1 replies
  • 0 Likes

IPSec Tunnels BGP Fluctuation Frequently

Hi All, We have 04 IPSec VPN tunnels created on our PA FW with Public Cloud configured with BGP. (All these 04 Tunnels are created over single Internet link). All 04 peering IP of public cloud belongs to same region. Pl note that these tunnels are in pair i.e. 02 tunnels are configured Active-Active (BGP) and redundant to each other to achieve ...

Jimmy20 by L2 Linker
  • 2441 Views
  • 1 replies
  • 0 Likes

iOS Global Protect Always-On VPN ?

We have: MDM: FilewaveiOS: 12+GP: 5+ When an iPad is rebooted, GP doesn't auto reconnect & must manually be opened/connected again. Any ideas how to get it to actually always auto reconnect? We really only care about the user identification being automatic.

Resolved! Global Protect Authentication Local User and AD user to allow both

Hello,I am setting up VPN on the Palo Alto. So far, I was using a local user database and it is working fine. I will need to move to AD authentication and tested ok. However, the issue I am getting if that I can use only one type of authentication at a time by moving the authentication profile type up on the GlobalProtect Portal>Authenticati...

Resolved! User identification in security policy

Hello, I have a problem with configuration of user identification in security policy. What is the target: for some users who login to VPN via GlobalProtect I would like to limit them to some specific subnet. Users login to VPN using their Active Directory accounts (via Radius). I created LDAP profile, group mapping and security policy (with sour...

Resolved! Need to Disable TLS 1.0 & 1.1 for port TCP-3978

Can someone suggest on how can we disable TLS 1.0 & 1.1 for port TCP-3978 Description: The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and s...

Microsoft-Update and activation problem with SSL Decryption

Hello there, Here I have deployed a set of secure rules for Office365 follow the official Paloalto guide. Now we encounter problem with office365 when ssl-decryption is enabled. Some users cannot activate office365, please refer the error as below. So is it safe if we make a not-decrypt policy for O365's URL using Minemeld? Thank you for any a...

BKQT6uZ
tienngo by L2 Linker
  • 4055 Views
  • 2 replies
  • 0 Likes

A statement about using Pinterest in a URL category.

Hello! somewhat new to the community, I used to have a login but didn't login forever...Just something that you might want to know if you are ever forced to add pinterest to a custom URL category, you will also need *.pinimg.com in the category to make it work. Here is what I used in the custom URL category:pinterest.com*.pinterest.com*.pinimg.c...

Burnsy30 by L0 Member
  • 3812 Views
  • 1 replies
  • 2 Likes

MFA Authentication

I need to configure MFA for administrator login, we would prefer second authentication through e-mail or any mobile APP token.I am unable to find exact document to configure , could you please help us to configure MFA in our Paloalto device.

Resolved! Panorama - deleting part of a template?

When i import my HA pair of firewalls into Panorama (9.1.3), the resulting template includes values for HA config. I would like to leave HA config up to the gateways themselves and not include it as part of the template. How would i delete that part of the template? If i set values to their defaults, that part of the config still exists in the ...

  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels