General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Cannot contact update server from public IP address interface

After click "Check Now" in "Dynamic Updates". Show the error popup as below linkhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkuCAC The above KB not apply to my case. As I not allow my management interface to reach internet.So I go to customize "Service Route Configuration", and set the Source Address of Service - "...

jeremylo by L3 Networker
  • 18083 Views
  • 10 replies
  • 0 Likes

IP to User mapping Format

Hi ! We configured Windows User Agent for the IP-to-User Mapping to apply the AD group based policy. User Agent is fine and IP-to-User lookup forwadred to firewall . But the problem in the user format. Some user's mapped in the format of netbios\username ( AD\user1) and some of the user's mapped in the format of dnsdomainname\username ( AD.ex...

gpsriram by L1 Bithead
  • 2952 Views
  • 1 replies
  • 0 Likes

PAN-88671

Hello, In PANOS 8.0.8 release, now can disable or enable the L4 checksum checking. How do I check if my 5200 firewall L4 checksum is enabled or disabled? How do I check if traffic is dropped due the L4 checksum? Thanks, E

Resolved! User Activity Report

Hello, I have generated the User Activity report, just wondering whats the count column in the report? Is that the number of time the user has visited the site? Also some category has 2 counts and browser time 0:00:00 what does that mean? Total time is showing: 7hours and 3 min. Does it mean the user spent that much time in all the categories? H...

Sample.png

Global Protect Client Certificate Issue

Hi teamHow can I implement in the Global Protect confuguration the use of client certificate and LDAP authentication as two factor authentication only for some user (or a user group) ? We had only rolled out private certificates from our PKI for some user that has access to sensitive services and these user should use their certificate as additi...

mtsadmin by L1 Bithead
  • 4907 Views
  • 8 replies
  • 0 Likes

Resolved! How to list all configured values for a template?

Is there a way to list all configured values for a given template? I have searched the tech docs and Community but can't find a good answer for this. Background: I inherited a Template Stack in Panorama, and one of the templates has an oddball naming convention and doesn't SEEM to contain any values at all (browsing manually through the screens ...

lwalcher by L1 Bithead
  • 14803 Views
  • 6 replies
  • 0 Likes

Resolved! Dual Firewall pair-True DMZ design

Hello All, I am looking for any helpful suggestions,recommendations,critics etc for my new firewall design implementation project.currently, we have a pair of 5020s facing the internet and having DMZs,Internet and Internal networks on them. My management would like me to implement a "True DMZ" with new 5220s for greater ssl decryption capabiliti...

Resolved! Two question HA

Good Morning I have two questions regarding the HA Fault conditions When I configure Link Monitoring and Path Monitoring in the Active Firewall Should I also configure these conditions in the same way in the passive Firewall? The "Heartbeats Backup" option must be enabled even if we do not have a backup link configured? Thank you! Regards!

Resolved! O365 URL rewrite

I'm using minemeld to pull the O365 urls into my PAN. I get a list that has entries like*.domain.comsub.domain1.com I need to import those entries and rewrite them so they look like*.domain.com/domain.com/*.sub.domain1.com/sub.domain1.com/ Any pointers would be appreciated.

ckemp by L2 Linker
  • 18130 Views
  • 25 replies
  • 0 Likes

Resolved! Dropbox Client not working

I have a policy rule to allow dropbox. I am performing SSL Decryption. The users are using the dropbox client (not web). I came across this article that mentions this will not work when decrpytion is on https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGaCAK Anyone have recommendations on how to exclude the dropbox cl...

MikeC by L3 Networker
  • 4072 Views
  • 1 replies
  • 0 Likes

Resolved! URL Filter Test A Site page is broken

For about the last week https://urlfiltering.paloaltonetworks.com/ has been broken in way that makes it impossible to submit reclassification requests. I have several sites that I'd like to reclassify, but I have been unable to do so.When will this be resolved? One of the issues is that a JavaScript is being loaded over plain http, so at least t...

arvesynd by L3 Networker
  • 5831 Views
  • 3 replies
  • 0 Likes

PCAP with only source IP Filter and Global counters

Hi Everyone, For certian cloud apps we do not know specific destination IP as users have given is list of urls and multiple subnets.My question is if we do PCAP with only source IP as filter and then do the PCAP and check the global counters for error ordrops will we see right matched traffic as dropped in global counters? or To see right drops ...

MP18 by Cyber Elite
  • 2240 Views
  • 1 replies
  • 0 Likes

expired or resetted password issue with GlobalProtect Agent 4.1.6

An expired password change or a resetted password cannot be changed when using the Global Protect credential provider and PAN agent 4.1.6I re-installed PAN agent 4.1.2 and tested this to verify if it was PAN agent related because this issue was a new feature introduced in PAN agent 4.1.PAN agent 4.1.2 doens't have this issue https://www.paloalto...

GP login expired 2.jpg
GP login expired 1.jpg
DaxVC by L2 Linker
  • 6537 Views
  • 5 replies
  • 0 Likes

Resolved! App-ID Issues with Dropbox traffic

Hello, We've got QoS setup on a PA-220 that classes any traffic marked with the dropbox App-ID. This class is then restricted to 2mbps. However we find that not all traffic generated by the Dropbox Sync client is marked as dropbox. Sometimes it's just ssl, sometimes its unknown-udp. Essentially we just want to restrict any Dropbox traffic to 2mb...

Unable to get multiple global protect working.

PA3020 ,8.0.12.I have working GP with a public ip.I am trying to setup 2nd GP with 2nd public ip.This 2nd ip is used as destination nat for rdp as well.When I configure the loopback interface with 2nd ip and use it in portal and gateway ,rdp gets broken.

  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels