General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4469 Views
  • 0 replies
  • 0 Likes

SSL Inbound Decryption with a web proxy doing SSL Forward Proxy!

Hey girls/guys. My clients on the internal network, talk to a web proxy on the internet that performs SSL forway proxy. This traffic traverses the Palo Alto firewall - we would like the Palo Alto to see inside this traffic for threats,etc. Note: The web proxy must stay - we cannot move this function to the Palo Alto firewall. Is it possible to i...

Looking for a keyword report

Hi Everyone,I would like to create a report that sends me a email either straaight away or on a schedule, that when a user performs a search for a keyword i.e suicide I am alerted. I workout how to create a report if the url contains a keyword, however that is not what I am after. Many thanks in advance for any suggestions. RegardsPaul

packet size

Hi,How the packet size impact throughput .Why do we require higher throughput when the packet size is small. How do we identify the packet size during the poc time ?which service will be using the smaller packet size ? Thanks

simsim by L4 Transporter
  • 5571 Views
  • 3 replies
  • 0 Likes

Internal Gateway not working

I'm trying to create an internal gateway to be able to capture User ID fully and start creating User ID based rules. I created the dns records and put the gateway on a loopback interface on the firewall that is in the internal trusted zone. I have done the cert work and confirmed that the name resolution is working. When looking at the logs it...

Authentication with LDAP server failed because received empty DN for user

Hello community, I have an issue and maybe you know the reason. Here the situation:Trying to create an authentication profile to authenticate with active directory but it´s not working.When testing the profile with "test authentication ... " command I get the following error:Authentication to LDAP server at X.Y.Z.E for user "......"Egress: X.X.X...

Carracido by L4 Transporter
  • 6637 Views
  • 1 replies
  • 0 Likes

Resolved! Source User ID being replaced by service account for SCCM

We have a service account for SCCM (Microsoft's System Center Configuration Manager) which will log onto our user PCs to run a scan to identify what is on the device. At times this account will log on after the user and will make it so the firewall sees the service account instead of the actual source user's ID. I have asked and we are not abl...

Recommended Version

Good Morning: What is the recommended version for the Palo Alto 3050 series firewalls? We are currently running 8.1.8 What are your thoughts on 9.0.2-h4? Are there any problems with it, or should we more likely than not be good to go?

birkhojk by L2 Linker
  • 4327 Views
  • 2 replies
  • 0 Likes

Custom URL Category and SSL Decryption

Hello all, We have a custom URL category created to exclude sites from SSL decyption. We have the category set to no decrypt on the firewall but recently we encountered an issue where URLs that we add to the custom object were not getting categorized as such. We talked to PAN TAC and they recommended adding a "/" to the end of the URLs. We teste...

BGP sessions not exporting

Hi folks/ I'm trying to use BGP to synchronise routing across two ISPec tunnels to a Palo Alto HA cluster. I have BGP connectivity established - the remote end is exporting the routes I want, and they're being seen (and managed correctly) by the Palo Alto as far as I can tell. However, I can't seem to get the Palo Alto to export routes BACK to t...

darren_g by L4 Transporter
  • 19564 Views
  • 11 replies
  • 0 Likes

Force BGP Peering over a certain interface/path

I have many paths through my network and my palo altos are choosing to peer iBGP with each other over the Northbound paths to the next level of of switches. I want them to use the links south bound to my datacenter core to peer BGP. They are peering with loopbacks. how do you weight routes or set costing within ospf on the palo?

USER-ID and problems with runas /netonly in combination with MMC modules

Hello, as a safety measure i placed my workstation in a different vlan and from there i'm managing our network and servers which are located in the designated dedicated vlans. On the firewall we have a rule which makes it possible for our 'admin' accounts to access most vlans for management tasks. Now when i use runas for certain management t...

hmcadmin by L0 Member
  • 4289 Views
  • 2 replies
  • 0 Likes

PAN DB URL filtering issue.

Dear all, One of my customer PAN DB License expired and we try to block all Youtube videos excluding some the vidoes links in Youtube. My query here is, whether if the device without a valid PAN DB Licence we will be able to acheive the above requirement to be configured. Please let me know if you have any questions. And eagerly waiting for a ...

Resolved! Policy details

Hi , Is there way to pull the details of all policies using same address/address group in Panorama via cli . I can check from gui , but it will need lot of manul work . Example: address group -" Test" is part of policy for 10 firewall managed by Panorama . How i can pull details which are the policy name along with respective device group nam...

deepak12 by L3 Networker
  • 5205 Views
  • 3 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels