General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1950 Views
  • 0 replies
  • 0 Likes

Resolved! Agentless or User-ID Agent?

Hi,

In my environment, we have several domain controllers around the world across MPLS. In order for users to go out to the internet, they must have an AD account in a certain AD group. This seems to work just fine....but recently we've had a few issu

...

PA 5050

I heard that the PA 5050's are going end of life in 2020 so why did they sell me premium support to July 2020? Do  I loose what I bought or do they honor it till the expiration?

jdprovine by L4 Transporter
  • 3328 Views
  • 5 replies
  • 0 Likes

Resolved! How to block Geo IPs for some services?

Hi,

i have a ssh Service connected via the internet.

But i would like to filter a bit, because there comes often automatical scans from china IPs and so on.

The devices who connect to the port 22 have a dynamic ip so i cant set a static source.

But i kno

...

Resolved! Recover from Split Brain PAN OS 8.0.6 (PA3020)

Hi Community,

 

i have two PA3020 in an A/P HA deployment.

The cluster is virtualized with 2 VSYS - one for comany A and one for company B.

Between the companies, the coreswitches are linked with 20GBit. (a kind of dark fibre - 500 meters)

 

The 3020 HA se

...

Resolved! Global Protect VPN Unique ID's and one user allowed

Hello all,

 

I have a requirement for the following and short of any draconian methods, I'm hoping that the PA GP will be able to answer.  

These are PAN8.0.7 on 5520's in Active/Passive

 

I have a req to ensure that a user of GP is only allowed one GP se

...

Intrazone default- what gets inspected?

Hi

 

For traffic that matches the intrazone default policy,  and assuming there are no security profiles for anti-virus, anti-malware, threat protection. etc,  Is there any inspection performed? 

 

Reason I ask- I found an article on the Knowledge base a

...

fmurray by L1 Bithead
  • 2828 Views
  • 2 replies
  • 0 Likes

Resolved! User-ID Agent Ignore a group of users

Hello together,

 

Is it possible to ignore a group of users with the User-ID Agent, and also on the firewall without the agent?

 

I tryed to add a group ( example\Ignore User-ID ) to the ignore_user_list.txt for the Agent. But it seemed not to work.

 

I al

...

Clermont by L2 Linker
  • 8553 Views
  • 14 replies
  • 0 Likes

VNC Access through Global protect

Hi all

We have internal server that must be accessed through VNC and HTTP.

Internally it works well but when we try to connect from outside through Global Protect it is blocked

Access  Policies  from GP to Internal allowed. But  not  working. 

Radmin_85 by L4 Transporter
  • 8391 Views
  • 11 replies
  • 0 Likes

SNMP monitoring for Ethernet interfaces

Hello,

 

 

We are using OPManager to monitor our internal network and we are experiencing some issues with PA-VM 200 when trying to get the traffic of certain interfaces. For all the tunnel interfaces and sub-interfaces, we can see the traffic on the mo

...

Farzana by L4 Transporter
  • 7289 Views
  • 7 replies
  • 0 Likes

SSL Offloading for inbound connection

We have few legacy internal applications listening on a various TCP ports. Now we have a requirement to connect to these applications from a cloud vendor externally. There is no option to setup a site-to-site IPSec VPN tunnel to the cloud so we need

...

ganees by L1 Bithead
  • 11046 Views
  • 4 replies
  • 0 Likes

Resolved! CPU/RAM/Memory Alarms in PAN-OS

Is there a feature in PAN-OS to set CPU/RAM/Memory usage exceeding threshold x% in the same way Device>LogSettings>AlarmSettings has variables to track Log DBs?

 

This could be useful towards spinning up a new instance for the vFW to load balance to if

...

timgowan by L0 Member
  • 5720 Views
  • 1 replies
  • 0 Likes
  • 24199 Posts
  • 117 Subscriptions
Top Liked Authors
Labels