General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Query on Split tunneling

Hello, We are trying to exclude one IP from including routing in split tunneling.VPN is working, however, I found that when going to 192.168.16.22, still through VPN rather than local LAN.What we need to setup is ONLY this range, 192.168.0.0/16, will be accessed via VPN except one particular IP shown below.Looks like we need to use include and ...

Config.png

Resolved! Can Wildfire be integrated with Traps?

Hi; If Wildcard declares a file to be melisious after having been downloaded by one user, then what? Can Wildfire inform End Point Protection Traps management to quarantine that particular user device? KindlyWasfi

Resolved! What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

Hi; My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or pr...

Many to many dynamic NAT (/24 to /24)

Is there a way to make a dynamic NAT rule that translates one /24 subnet to another /24 subnet work in both directions and map last octet to last octet? There's a way to do it in Sonicwall so if your natting a subnet to another it will make .20 on the real local subnet map to .20 on the natted subnet and do that for all IP's. The reason why I as...

Problem with user mapping and GlobalProtect connection

Hello! The access to GlobalProtect is done using certificates, it works alright, users are authenticated and identified by sAMAccountName. Sometimes happens that the firewall re-maps the already identified user substituting the sAMAccountName with name.surname, for example. john.smith. I don't understand why. Sometimes it works perfectly, then j...

Resolved! recommended versions

Hi, I'd like to know which PAN-OS is currently recommended? And this in combination with GlobalProtect? Thanks,wkr,Luc

Resolved! 7000 Series processing speeds

Hi All, Hoping someone can clear up some confusion I have with the processing speed fothe 7050 firewall. The literature states that each NPC adds 20 Gbps of processing to the chassis. You can scale out your deployment and speed by adding NPC's, the first packet processor will do the job of distributing the load accross the NPC. Picture this sc...

Integrate a DMZ with virtual F5 to the PA FW

I would like to add a virtual F5 as a proxy to our exsiting 5220 PA FW. As I have never done a DMZ to a virtual device, I am jsut wondering there a sample scenario or configuration. If my F5 was a physical device, I will just assign an IP address to my FW interface with zone as DMZ. But if my DMZ device is virtual (setup in the datacenter in the...

Capture.JPG
jac101 by L2 Linker
  • 9607 Views
  • 8 replies
  • 0 Likes

XML User ID

One of our engineer setup XML to pull the user id and ipaddr mapping, which works with no problem. The problem is he left the organisation and we are not able to determine the source from where the input is coming into the firewall. The log on the PAN does not tell you exact source ipaddr.irtual Systemvsys1Timeout2700Data Sourcexml-apiSource Nam...

Policy rules based on hostname or windows hostname

Hi I can create a policy based around the username, what about linking to a hostname . windows hostname - verify in MS AD. I have a management VM, I would like to move, but it has some policied based around location - specific network. It would be nice to allow it access based around windows name as long as named is in MS AD.

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels