General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

QOS to a specific webpage/service for admin staff

Greetings I awhile back asked the company that initially setup and installed my palo alto to set up a rule so that my admin staff will not have issues reaching a specific website. but i dont think they did it properly. As a school of about a thousand users balancing the admin staff'ss needs vs the teaching staff's vs the pupils can be quite tric...

Clientless VPN Web Page redirection Issue

Hi all, I published one of web service through clientless vpn (OS 8.0.13). After authentication Its not loding properly. I go through developer tool (F12) its given following screen.please help. Thanks,Lakshitha.

Bird.JPG

Forticlient connecting but no traffic goes through

Hello, I am trying to use Forticlient to connect to a remote network outside our coporate network. The connection is successfully established, it seems that the traffic is sent but no traffic gets received from the Forticlient. Anything needs to be done on the PaloAlto to enable traffic reception? Best regards

Screen Shot 07-22-19 at 02.06 PM.PNG
AGAGroup by L1 Bithead
  • 8131 Views
  • 4 replies
  • 0 Likes

GP switch from 'pre-logon' user to 'logged in' user

Hi, We have got global protect pre-logon set up and pretty much working now after quite a few issues.We still have one issue, although the pre-logon user connects fine when starting the end device prior to logging on (says connected on the windows screen and in remote users in the gateway it shows the pre-logon user), when the user logs on the u...

GP Client on MACs does not always detect internal network

We have an issue that seems to be impacting our MAC users only. They connect to an internal wireless network, but the GP client does not detect that they are on the internal network. (We're using the always-on feature.) We've reduced the timeout to 1 minute, but even then and with a manual refresh, the client still seems to think it's on an e...

ktunkel by L0 Member
  • 3287 Views
  • 1 replies
  • 0 Likes

NAT Configuration to access Remote Desktop

Hi,We need to configure an input rule to authorize an public IP address to access at one of our virtual machine on our subnet.Concretely, I need to authorize public IP address 195.193.194.195 access directly to our virtual machine with the private IP 192.168.1.1 on the port 3389 (Remote Desktop) only via our public IP address (82.83.84.85).I con...

feelgood by L2 Linker
  • 17095 Views
  • 10 replies
  • 0 Likes

SSL Decrypt & Windows Updates

Hello, I've been having a problem with Windows Updates when SSL Decrypt is turned on and I'm wondering if anyone else had to add these "new" Microsoft URL's to the decryption exclusion list. My firewall is on version 8.0.3 and my Windows version is Windows 10 Enterprise 1703 (Build 15063.483). I'm not sure what update package includes SSL Decryp...

kalakai by L2 Linker
  • 10669 Views
  • 3 replies
  • 5 Likes

PA is dropping SYN packet with ECN and CWR

Hi Team, @reaper , @BPry Recently I have come across a scenario that palo alto was dropping TCP SYN packets which have ECN and CWR bits set. upon checking the global counter, i have seen that the drop reason was 'process owner message err, no predict'. anybody have seen this?. PA doesn't support SYN packets with ECN and CWR set ?.. Once I disab...

Resolved! Agentless User-ID - change password

Hi 2 all We have working Agentless User-ID and User-Based and Group-Based PolicySpecial AD-account, "pauser" have necessary permissions. I found, what its login and password is configured in Device > User Identification > User Mapping > WMI AutenticationDevice > Server Profiles > Ldap > "Name of LDAP Profile" I need to change ...

aaobuhov by L2 Linker
  • 3835 Views
  • 1 replies
  • 0 Likes

Anti-Spam list for EDL

Hello. A customer would like to add smo more anti-spam features to a Palo Alto FW setup and is intersted in using EDLs in connection with publicly available anti-spam lists. Anyone knows a good and free anyti-spam list I could use for that? I've checked all the most known ones but they all offer only lookup capabilities (you query an IP/FQDN and...

santonic by L6 Presenter
  • 5238 Views
  • 2 replies
  • 0 Likes

Resolved! Setting up a NAT pool with a PAT address for any spillover

We migrated from Cisco ASAs to PAN-3020 devices and I'm curious whether a feature from my ASAs exists in the PAN world. On our ASAs, we could create a pool of dynamic NAT addresses that would be matched 1-for-1 with inside hosts going to the Internet (we own a large block of public IPs, so we can do this). On the ASAs, once the dynamic NAT pool ...

LorenzoM by L1 Bithead
  • 8231 Views
  • 2 replies
  • 0 Likes

Remote Access on passive node of firewall ha cluster

Hello all, I am currently configuring an HA cluster (active / passive) with the following configuration: Primary (active) box: PA-820ethernet1 / 1: 1.1.1.1/29 (external interface)ethernet1 / 2: 192.168.0.1/24 (internal interface)MGMT: 192.168.50.251/25 (Management interface) Secondary (passive) box: PA-820ethernet1 / 1: No IP address, as this is...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels