General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Panorama and active/active configurations

Hi,

 

Recently, we added more PA devices to our infrastructure and we decided to start using Panorma to manage all these devices.

So far, we haven't experienced an improvement in efficiency or user/admin friendliness.

 

Let me (try to) explain:

We have two

...

mvdven by L1 Bithead
  • 1883 Views
  • 1 replies
  • 0 Likes

Certificate attached to non existant security profile

Hello,

 

I've encoutered a problem regarding the deletion of a Certificate. When i try to delete it i get the following error message:

1- Failed to delete certificate - xyz xyz cannot be deleted because of references from: ssl-tls-service-profil...

steven.m by L0 Member
  • 2656 Views
  • 1 replies
  • 0 Likes

Custom extensions for file blocking

I've got our PA setup to block file types that are risky.  But, I've found a problem with Symantec LiveUpdate pulling down the update files it needs.  It uses a couple odd file types that aren't in the list as types that I can allow for a profile.  I

...

Problem with GlobalProtect password.

Hello all!


If we put a sterling pound (£) symbol in a user password, the authentication fails. We are using GlobalProtect 4.1.8 and use a RADIUS server running Microsoft Azure MFA server on the authentication profile of the GP gateway, with just an LD...

Global Protect Client 5.0 for Windows and Mac

I'm looking at the release notes for the Global Protect client for Windows and Macs, now at 5.0.1

 

Am I missing something ?

What is the reason for the 5.0 client?

I don't see that there are any new features, or changes in behavior.

 

Or is it simply that

...

gefuchs by L1 Bithead
  • 1650 Views
  • 1 replies
  • 0 Likes

Limit download file size with specific response message

Hello Guys,

 

I succeed limit the download file size with the following KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhHCAS

 

However currently the user is alerted with the antvirus response page. Is there a way to provi

...

kasito by L1 Bithead
  • 3891 Views
  • 2 replies
  • 0 Likes

Resolved! Receive ping count 0

I've allowed ping traffic from an external source to the outside interface IP.

When they try to ping the firewall, I see allow traffic on the correct rule, but it only shows a send count >0 and the receive count remains 0. Also they report they do not

...

CHKlomp by L2 Linker
  • 3966 Views
  • 5 replies
  • 0 Likes

Resolved! Global Protect Gateway communication

Does anyone have insights into how often the client will talk to the gateway if used only for user-id and not utilizing a tunnel?  I know you can set the portal refresh time, but how often does the client actually talk to the gateway after grabbing c

...

Sec101 by L4 Transporter
  • 2535 Views
  • 1 replies
  • 0 Likes

Redistribution Profiles - Source Types

Hi. I need to redistrubute some routes (loopbacks, and statics) into BGP.

 

Are their any advantages to having the source type as static vs connected under Virtual Router - Redistrubtion Profile - then go into Redistrubution Profile - Source Type.

 

Than

...

Resolved! Query on Brute Force Attack

Hello,

 

Is it possible for the PaloAlto FireWall to stop brute force attacks for inbound SSL sessions without the inbound server certificate being installed on the PaloAlto?

 

Is there any KB for this?

Resolved! Proxy IDs and routing

When having Site-to-Site VPN with Proxy IDs, do we still need to configure static route with next-hop the VPN tunnel interface or will traffic matching the proxy IDs be sent over the tunnel regardless of static routes?

BatD by L4 Transporter
  • 3995 Views
  • 2 replies
  • 0 Likes
  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels