General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PAN Firewall LDAP Authentication user handling

Hello Community, so i've got a small "issue"/question regarding PAN Firewalls and LDAP User-Authentication handling.I configured it like it is documented hereMy issue now is that when i add an Administrator, then delete the user from the Active-Directory group, the user is still able to log on even after the firewall refreshes the connection.Am ...

Website getting blocked

Hi Team We have PA 220 firewall with 8.1.5 PAN os version. We have tried to reach one particular website but its not reachable. When we checked the traffic logs that application was shown as "incomplete" and the end session reason was aged-out. Note : Same website can be reached by external network. For testing purpose, we have created one secur...

Sec policy.PNG

Resolved! migrating config from 7.0.12 to 8.x.x

hello.we have a replacement of a palo alto coming up. the actual migration is I believe from a 3050 model running pan-os 7.0.12 and the config needs to be migrated to a pa 5220 (whic I believe can't run pan-os 7.x but comes with 8.0.0 minimum.due to security reasons I'm not able to take teh existing config. install it on a lab devic, upgrade tha...

ipsec site to site vpn

Hi,Do I need a tunnel interface for site to site vpn ? If yes How can I do that and what is the benefit Thanks

simsim by L4 Transporter
  • 3316 Views
  • 1 replies
  • 0 Likes

firewall using wrong LDAP attribute to find user in active directory

Hello Community, I´d like to check with you the following issue:created a LDAP authentication profile which is not working, when using the "test.... " command I get an authentication failed with "Received empty DN for user User12345" I made a traffic capture and saw that the firewall is using the wrong attribute to find the user on the active di...

Carracido by L4 Transporter
  • 5557 Views
  • 1 replies
  • 0 Likes

Resolved! update from pan-os 4.1?

is it possible to update an old box for lab purposes that is currenlty running 4.1.6 pan-os? It can't be updated to 6.x without being at 5.0, but 5.0 is not available for download. Is a fresh install (skipping upgrade paths) of 8.1 not possible? Is their a way to download old EOL software version?

Orange attack on GP

https://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html?m=1 Any word from PA on this ?

GP client fedora certificate

HI, We are trying to go up a VPN using Global protect client in fedora device. We have read that global protect 4.x requires that the certificate be signed by a trusted CA. Our certificate is self-signed. So we have GP client version 3.1.x because we whitnk its not neccessary a certificate signed by CA. Is this true? whats are the requisites for...

BigPalo by L4 Transporter
  • 4444 Views
  • 3 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels