General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Automatic email alerts: Sinkhole and security policies

Hi Community,

 

This query is for PAN-OS v8.1.X

 

I am trying to generate an email alert when the firewall sees an (action eq sinkhole) event or when the security policy created to sinkhole an infected host is used. Email Profile(s) have already configur

...

ash83 by L2 Linker
  • 3489 Views
  • 1 replies
  • 0 Likes

BGP Peering Issue

Hi All,

 

I have an issue with maintening a BGP Establish connection. Essentially the setup is the Palo Alto to two peers to allow for resilience if one BGP peer fails. If one peer is established it stays stable. If I enable the path to the second peer

...

a.jones by L3 Networker
  • 10732 Views
  • 3 replies
  • 0 Likes

Custom URL category enforcement in URL column

 

I'm seeing some different behavior from our firewall on 8.0 code.  I've got a few rules setup wtih both security URL profiles, and the URL category column.  I've got a few custom URL categories made that match certain traffic.  What I'm finding is t

...

Sec101 by L4 Transporter
  • 3288 Views
  • 5 replies
  • 0 Likes

Bootstrap Component logs for Palo Alto Firewall instances

Hi

 

 

I am looking to know the best way to troubleshoot bootstrap process on Palo Alto virtual instances on AWS. We have followed the bootstrap package standards as mentioned in https://docs.paloaltonetworks.com/vm-series/8-0/vm-series-deployment/boots

...

jerrygb by L0 Member
  • 2321 Views
  • 0 replies
  • 0 Likes

Is there max concurrent session for GP with one ID?

Hi there,

 

One of my customer says when he establishes multiple GP tunnel from multiple iPad (iOS 12), when 4th tunnel is established, 1st tunnel will be disconnected.

 

His topologies are as below:

-PA is VM-300 with PAN-OS 7.1

-iPads run with iOS 12.2

-G

...

emr_1 by L5 Sessionator
  • 2192 Views
  • 0 replies
  • 0 Likes

Resolved! Server Monitoring Not Connected

Hello,

 

Microsoft AD under Server Monitoring is showing as 'not connected.'

We would like to use the PAN-OS Integrated User-ID Agent

Output from debug commands show UserID Debug Log is enabled but nothing is logging.

 

Anyone encountered similar issue?

 

Cisco ISE and Palo Alto TACACS

Few questions here. 

 

Why do you need user local on the PA devices?

Why do you need those users local on the ISE box rather then allowing access from AD groups via ISE?

If the users are local then password changes are not possible when a user changes th

...

Office 365, 5 minute Session Expiring - Help!

Hi All,

 

New to Palo and wondering if anyone has any input on this issue. Our company has rolled out Office 365, but every ~5 minutes - a Session expiration pop-up comes up while any SharePoint document is open (web-based) - 

 

From my traffic logs, I'm

...

Resolved! URL Filtering & Blocked Countries Response page

I have custom URL filtering response page enabled which works; however, I have noticed that when users get this response page, the URL category is correct and is allowed. When further investigating the issue, we found that the URL/Site is blocked by

...

MikeHamm by L1 Bithead
  • 2327 Views
  • 1 replies
  • 0 Likes

GlobalProtect SSO with Kerberos returns user display name

Hi Community,

 

I'm a bit confused by a internal GlobalProtect installation:

I configured Kerberos SSO and created an aut-sequence with Kerberos SSO and LDAP as fallback.

 

The customer is using a third-party Credential Provider (Windows 10) so we did the

...

Chacko42 by L4 Transporter
  • 2048 Views
  • 0 replies
  • 1 Likes

Panorama Device Removal

I had to rebuild Panorama 7 on ESX as for some reason after a power outage the image could not be restored...

 

New installation completed and licensed but I cannot get the firewall 3020 to connect.

 

I have removed the Panorama settings from firewall an

...

Mick_Ball by L7 Applicator
  • 3072 Views
  • 4 replies
  • 0 Likes
  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels