General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 309 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3651 Views
  • 2 replies
  • 14 Likes

User-id doesn't work on SSID

I have PAN UID agent mapping IP-to-usernames. It works like a gem for internal users but not on the DMZ which allows company phones with their AD creds. I am not seeing any usernames for these users although they authenticate against AD server. has a

...

NAT + DIPP question

Hi - we have experienced an issue where users in a certain zone were having intermittent problems accessing the internet. We speculated that there could be a NAT issue, and the pool might be full, or translations just werent working. The pool is larg

...

Palo NAT question.png
LukeBr by L1 Bithead
  • 3640 Views
  • 2 replies
  • 0 Likes

POC in AWS - Palo Alto Active/Active under NLB

Working on a POC. 

 

Have two firewalls sitting under an NLB. One of the firewalls routes traffic to database. This appears to be a limitation on the VPC route tables. 

 

With traffic from App server destined for the DB, it goes through AZA palo alto. 

 

W

...

PXE Boot Not Working

Hello everyone,

I have a new issue where a PA3020 has been placed between Client and Server subnets on the network. Since this install, building new PCs using PXE boot and deploying Applications using Windows SCCM no longer works.

The build starts and

...

Bocsa by L3 Networker
  • 8809 Views
  • 4 replies
  • 0 Likes

Resolved! User ID and LDAP configuration

Hi ,

I am a beginner to PA Networks.

Can anyone please provide any document to configure the LDAP tree structure in WIN 2008 sever AD. So that PA user agent fetches the user - ip mapping information.

Thanks

Auto update of trusted root CA

Hello,

 

Our PANs are not updating the list of trusted root CA certificates which is causing issues with services such as Microsoft Skype for Business and other applications as we have SSL decryption enabled. Using PAN-OS 8.0.7

For example, Microsoft us

...

Farzana by L4 Transporter
  • 5451 Views
  • 2 replies
  • 1 Likes

Analysis ransomware

Hi,

 

One of our servers have been infected by any kind of ransomware. We can see several files encripted. So we are seeing any evidence about the infection in the PA. The only trace that we saw in PA is that the infected server sends many dns sessions

...

AV.JPG
BigPalo by L4 Transporter
  • 4049 Views
  • 4 replies
  • 0 Likes

Resolved! MS Updates blocked

It appears as though all of the sudden ms-upate traffic is being picked up as either session-end reason threat or n/a and updates are failing on my MS servers. Regardless of the server they all seem to be hitting the unidentified default rule at the

...

Global Protect HIP Processes

Hello,

 

We are trying to produce a Custom Report of all the Processes (Failed and Successes) that are logged in the HIP Match Log Details.

 

Is there a way to do this?  All we see is HIP and HIP Type, but no way to display the processes in a report.

 

Tha

...

Site to Site VPN cannot use any private network range

Hello,
I have to set up a Site-to-Site VPN so our users can access some resources on a clients network. As we had here a lab firewall, another Palo Alto, I set up a test between our production and lab. This worked and I was able to connect. For the ac

...

cheez by L1 Bithead
  • 10061 Views
  • 9 replies
  • 0 Likes
  • 24185 Posts
  • 100 Subscriptions
Top Liked Authors
Labels