General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1694 Views
  • 0 replies
  • 0 Likes

CRL revocation traffic identified as ms-update

Is this an expected behaviour? We where somewhat surprised that the application included this traffic. It includes all SSL CRL traffic (like establishing remote desktop or visiting websites), independent if its related to Windows Update.

Resolved! PA220 as a router?

Hi,

We are planning to have paloalto PA220 firewall in our new sites and instead of purchasing new cisco routers (ISR 4000 series), we will just use the PA220 as a router.

Our link is via ipvpn (not IPSec) with GRE tunneling. And we will be using EIGRP

...

bentot by L0 Member
  • 3783 Views
  • 2 replies
  • 0 Likes

IPSEC VPN IKE Phase 1 Goes down after couple of hours

Hi Guys,

 

Got a quick query. We have implemetmented new pa 3050 firewall in our perimeter. Two IPSEC vpns configured and working fine. We notice, after couple of hours, the Status of first led goes red. but, the second status led stays green. During t

...

irshad.n by L1 Bithead
  • 5319 Views
  • 3 replies
  • 0 Likes

Decryption with Wildcard SSL-certificate?

Does Palo Alto support decryption with Wildcard SSL-cert?

Ref.:
In order to determine if a connection needs to be decrypted or not, the firewall relies on the (CN) common name configured within the certificate and compares that to the security policy.

...

pivvre by L2 Linker
  • 10915 Views
  • 12 replies
  • 0 Likes

Global Protect Auto Start

We are looking into adding Global Protect as part of our deployment of newly reimaged computers. Within my company's work environment, we want Global Protect to start up only when the user clicks on the shortcut icon for the application. We do not wa

...

Resolved! Security Policy - with Service\URL category configuration

 I have a Security policy rule configured as below

1.source and destination any

2. User - any

3. Application - Any

4. Service ports open for http

5. Url category allowing access to custom created URL category in which only search engines google and bing's

...

krdeepu by L0 Member
  • 4757 Views
  • 1 replies
  • 0 Likes

name that security profile

I am looking for a more descriptive name for my security profile ? I have vulnerablity protection, anit-virus, anti-spyware and wildfire included on the profile that I have added to a majority of my rule. currently it is name All PE alert

jdprovine by L4 Transporter
  • 4532 Views
  • 13 replies
  • 0 Likes

Force what Global Protect Portal to use

Hello,

 

Our users will have 2 Global Protect Portals to choose from.

 

 

The users sometimes log in to windows with a smart-card and sometimes with a normal AD-account (Username and password).

 

Not sure if it's possible but can we force what portal they c

...

xen-pv by L1 Bithead
  • 2843 Views
  • 4 replies
  • 0 Likes

Resolved! Captive Portal errors

Hello

 

Early today the captive portal stopped working and UserID didn't get any user mappings. Users couldn't be able to login by SSO or captive portal. After some investigation, we restarted the l3-service and it come back working.

 

The l3svc_ngx_erro

...

Monitor multiple IPs in a PBF rule?

Running 8.0.x on our PA-3020 and PA-220 systems. 

 

In our virtual routers, we can path monitor with multiple IP addresses and take action on AND or OR conditions, but PBF still seems to be limited to a single IP. I'd love to be able to monitor multipl

...

uvdes by L2 Linker
  • 2841 Views
  • 2 replies
  • 0 Likes
  • 24216 Posts
  • 117 Subscriptions
Top Liked Authors
Labels