General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 304 Views
  • 0 replies
  • 2 Likes

Who vets External Dynamic Lists (EDLs)

The Knowledge article on blocking TOR, https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Block-Tor-The-Onion-Router/ta-p/177648, references a list on panwdbl.appspot.com. This website has a number of lists that can be used to filter traff

...

Autofocus Minemeld Advantage vs wildfire?

My understanding is that wildfire autoupdates some URL categories within 5 minutes if you have the correct licensing.  With a current wildfire/URL filtering subscription, and without traps on our network, what is the real advantage to autofocus? My u

...

Sec101 by L4 Transporter
  • 2755 Views
  • 5 replies
  • 0 Likes

RSA AM and PA Configurations

Want to know if anyone has configured a PA to use the RSA Authentication Manager yet?  I have seen an RSA document from 2010 that states it can be done.

Resolved! Inter VLAN routing - best practices/suggestions

Hi guys, I've got about 7 or 8 VLANs that segregate my various departments. I want to inspect the traffic that goes from these VLANs to my server VLAN. What's the best way to do that? The only article I could find suggests creating a zone for each de

...

Current Interface Config.JPG
Konos44 by L1 Bithead
  • 8308 Views
  • 5 replies
  • 0 Likes

Captive Portal - Terms of Service

I would like to configure my PA-200 in such a way that when the user tries to browse a web site, he is presented with the captive portal. On this page I would like to display a "Terms of Service" banner telling him about acceptable use etc. I do NOT

...

u13001 by Not applicable
  • 15234 Views
  • 36 replies
  • 2 Likes

Captive Portal NTLM and responce page

Hello

 

Today I configured for one of my zone insted of default-web-form default-browser-challenge.

When I try to open new session on computer that isnt a Windwos AD machine i got:

and when I clicked Cancel:

 

I'm pretty sure that above message is possible

...

2018-06-20_203000.jpg
2018-06-20_203012.jpg
_slv_ by L4 Transporter
  • 3194 Views
  • 2 replies
  • 0 Likes

limitation when monitoring uptime with snmp

Hello Community.

 

I have an inquiry with which maybe you can help me. This is the situation:

 

In order to know the uptime I´m using the OID 1.3.6.1.2.1.25.1.1.0 to get the value of object hrSystemUptime. This is a counter of 32 bits and considering it´

...

Carracido by L3 Networker
  • 3650 Views
  • 4 replies
  • 0 Likes

panMgmtPanorama2Connected custom poller = Not-Connected

can someone tell me how can we troubleshoot palo alto firewall disconnection from Panorama. I tried to check system logs but there are no enough logs to troubleshoot it. 

 

logs

FW has lost connection to panorama, no log will be forwarded

Disconnected fr

...

SSL Forward Proxy Decryption with ECDSA Cert?

Just wondering if it's possible to use an Elliptical Curve DSA cert with CA and Trusted Root to be the Forward Trust Certificate for the SSL Forward Proxy decryption feature? 

 

Reading about the Perfect Forward Secrecy feature here:

https://www.paloalt

...

jsalmans by L4 Transporter
  • 3409 Views
  • 2 replies
  • 0 Likes

user-ID user mapping problems

Our PA 4.1 has problems mapping entries received from user-ID agent and LDAP queries.

show user ip-user-mapping command produces following output:

192.168.1.1 AD        grybai\vltr12345678

Here grybai is our NetBIOS domain name for domain and  vltr1234

...

SimasK by Not applicable
  • 3155 Views
  • 3 replies
  • 0 Likes
  • 23650 Posts
  • 107 Subscriptions
Top Liked Authors
Labels