General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Testing Sinkhole DNS

Hello, all I am testing Anti-Spyware DNS sinkhole. I set: I make policy with this profile. For most DNS-names in category “Malware” и “Command and Control” (https://threatvault.paloaltonetworks.com/) i see nslookup answer, for example: Addresses: ::1127.0.0.1And it is good. But for two DNS-names: namecha.in, 4cdf1kuvlgl5zpb9.pmr.cc (Malware cate...

Sinkhole.png
aaobuhov by L2 Linker
  • 3147 Views
  • 2 replies
  • 0 Likes

Pan-OS Upgrade path question

I know this is a frequent question, but I've not seen one particular aspect of it. I need to upgrade from 7.0.1 to 7.1.x (the latest). Am I correct that I would do the following: Download and install 7.0.19 <- this is my main question- can I go directly from 7.0.1 to 7.0.19 or is there an interim version needed? rebootDownload and install 7....

bwade by L0 Member
  • 2327 Views
  • 1 replies
  • 0 Likes

Resolved! 'proxy decrypt failure' in session detail even though no ssl decryption

CLI shows Session 33880958c2s flow:source: 10.29.32.146 [_DMZ]dst: 65.55.163.76proto: 6sport: 59760 dport: 443state: INIT type: FLOWsrc user: unknowndst user: unknowns2c flow:source: 65.55.163.76 [_EXT]dst: 198.160.191.5proto: 6sport: 443 dport: 32999state: INIT type: FLOWsrc user: unknowndst user: unknownqos node: ae1.3741, qos member N/A Qid ...

MP18 by Cyber Elite
  • 5991 Views
  • 4 replies
  • 0 Likes

GlobalProtect with MFA Dual Authentication

We have set up a GP slit tunnel we allow SSO using LDAP and Certificate based authentication this allows access to everything in the corporate network. However for applications we have specifically listed by service and destination we have created additional authentication rules that force the user to authenticate using a MFA (Entrust) method th...

Resolved! No expiration set for collector group on Panorama m100

Hello everybody, I would like to know what happen if I don't configure the Expiration Period in my Collector Group. By default, blank field means that my logs will never expire but if it reachs the maximum capacity what happen ? Does my panorama take in consideration my Quota and override the oldest logs ? Regards,David

GlobalProtect portal user authentication failed

For globalprotect I have a radius server profile with two servers in it. I have noticed that all authentication goes to the first server in the list all the time. And that works. However, in testing, I have shut off the first server and the firewall never tries to send authentcation to the second server. If I use the "test authentication" co...

Hangout as ms-lync

Hello everyone, the users in our company use Google Hangouts / Meet. We allowed google-hangouts and google-meet and all the dependent applications with Service Any.However the connection is recognized as ms-lync!! Anyone else facing similar issue? Best Regards,RJ

Configure Firewall HA through Panorama

Hi ! How we can configure the HA between Firewall through Panorama. I have added the both devices in to single device groups. So whenever i did the HA configuration parameters it's getting applied to both devices . What are the steps need to be followed for this ? Thanks in Advance...

gpsriram by L1 Bithead
  • 2638 Views
  • 2 replies
  • 0 Likes

Panorama snmp trap

My idea was first to setup panorama to monitor the logs for critical and then send snmp trap.But from what i can see from the PA mibs, there are no way for panorama to send info in the trap about the device? So all i see in the trap is the panorama ip. Is there any way around this? Or is maybe best practise to trap from the individual device?

hbalzac by L3 Networker
  • 4139 Views
  • 2 replies
  • 0 Likes

qos rule allowed application is http-video but stats and cli also shows unknown-tcp

I have configured qos on application http-video only and category is any.Running OS 8.0.9 On qos stats graph it also shows application as unknown-tcpfrom cli when i run command > show session all filter qos-class 1 it shows application as undecided need to understand qos rule only applies application http-video why we see applications unkno...

MP18 by Cyber Elite
  • 2606 Views
  • 3 replies
  • 0 Likes

Resolved! Authentication via LDAP server

We have a PA-3050, I have setup LDAP auth and it is working fine, however I have a question/concern. Yesterday we had a user offsite who needed VPN access, he was not in the AD group initially, so I added him to the AD group and sent him instructions on how to download the agent, when he tried to sign in, it would not allow him, ten or so mins ...

GlobalProtect concurrent Gateway conections

Hi i have two separate PA-220 clusters in separate sites and i can connect to each one independtelly via global protect, but i have to choose one site or the other. is there a way to setup the Global protect to connect to both sites at the same time without the use of a VPN satellite setup? the networks are not overlapping.. thanks,Jonathan

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels