General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Panorama Certificate Profile Breaks Refresh

Hello Folks, I have a strange scenario and am most likely missing something. I created a CA cert from a new Panorama template. I installed into the MineMeld server and verified the cert is showing up via google chrome. I then created a certificate profile and tied the CA cert to the profile. I then created a new External Dynamic List with the...

Resolved! How to deactivate virtual PA firewall with API

Trying to deactivate a PA-VM firewall with the API. First I add the Licencing API key to the PA with the firewall API: In order to hide my real values, let's use: myfirewall.corp as my firewallcxvzvxvcxvczc as my firewall's API keydgshgdjsgdjsgj as my licensing portal API key. So for the deactivation process, I'm gonna add the licensing portal A...

Panorama/Palo Alto Design Query

Greetings Folks, I have a Design and deployment Question. Our company have 3 Data centers located at three different Geographical Locations. We have a project to deploy Palo Alto 5200 Series Appliance in the environment as IPS appliance, Now we Have the count of 8 appliance in the Environment, So if i am to use the pa...

Resolved! highlight unused rules highlights rules possibly used in the past

HelloI have a query where the highlight unused rules is showing rules as unused, which possibly were used in the past. The security policies were created based on traffic log reports and the same security policies are now showing as unused. I see that the feature says unused since the last reboot, however the device has not been rebooted since t...

List of application where PA skips credential detection

Hello. PA supposedly doesn't check credential submission on some apps. »The firewall automatically skips checking credential submissions for App-IDs associated with sites that have never been observed hosting malware or phishing content to ensure the best performance even if you enable checks in the corresponding category. The list of sites on w...

Native VPN client

The native client on my windows machine does not seem to be authenticating against my radius/otp/ldap server and my globalprotect client is getting through the portal but failing on the gateway. Any ideas why or how to track it down?

jdprovine by L4 Transporter
  • 10160 Views
  • 29 replies
  • 0 Likes

Resolved! SFTP sometimes just hitting SSH app and sometimes Enhanced File Transfer

I have an egress rule that permits port 22 which should include sftp. And for the most part it works. But I had a user go to a particular sftp site useing filezillaand the PAN 5060 identified the traffic as "Enhanced File Transfer" and the traffic didn't hit the egress rule and was blocked. Why would filezilla/winscpwork fine - seen as plain ssh...

heartbeat connection

What is the best way to set up a heartbeat connection between and active and passive pair of firewall. We currently have a PA 5050 pair, in different buidling quite a distance away from one another and the heartbeat connection is through the network via ethernet and a switch. We have had it go into a split brain situation when power is lost on o...

jdprovine by L4 Transporter
  • 6955 Views
  • 12 replies
  • 0 Likes

GlobalProtect for User-Id Without Auth?

Hi All! We're an all-Mac shop, but we use AD for authentication (for now). GlobalProtect "External" is working great for external access, with authentication to AD. Now we'd like to map IP to Users INSIDE our LAN. My primary goal is to link URL Filtering alerts and other threat analysis to a specific user.Perhaps a naive question - When talk...

Palo Alto Layer2 mode and brdige vlan in different subnets

Hi All Can Palo Alto bridge two VLAN like VLAN 10 and VLAN 30 that have different subnets? or both VLAN should have same subnet? Basically what I want, I have VLAN 10 having subnet 10.10.10.0/24 and VLAN 30 having subnet 192.168.1.0/24. Both VLAN have gateway on core switch. How can I use Palo Alto firewall in layer 2 mode to do the firewalling ...

Is it possible by PA

We have a task where users should access to Internet by username and Password.I guess it is PROXY concept but is there any alternative in PA?

Screenshot_4.png
Radmin_85 by L4 Transporter
  • 2358 Views
  • 2 replies
  • 0 Likes

Generating custom reports from system logs

Hi! I need to generate weekly reports from the system logs. We need this for compliance reasons, and we have to filter out events that are logged to the Panorama system log from several firewalls. The custom reports only allow me to choose from specific databases, but not from any of the log sources, is there any way to get this done? Thanks in ...

Prevent admin from acquiring commit lock when another admin has lock

When Automatically Acquire Commit Lock is enabled on Panorama 8.0.10, is there a way to prevent an admin from creating another lock while a different admin already has one? We use shared objects almost exclusively and with four administrators are often in situations where multiple locks are getting created. This leads to reaching out to the othe...

fwmike by L2 Linker
  • 4509 Views
  • 4 replies
  • 0 Likes
  • 24452 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels