General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4476 Views
  • 0 replies
  • 0 Likes

Resolved! Recover from Split Brain PAN OS 8.0.6 (PA3020)

Hi Community, i have two PA3020 in an A/P HA deployment.The cluster is virtualized with 2 VSYS - one for comany A and one for company B.Between the companies, the coreswitches are linked with 20GBit. (a kind of dark fibre - 500 meters) The 3020 HA setup manages both companies. VLANs for both companies are configured on both cores to ensure a cle...

Resolved! Global Protect VPN Unique ID's and one user allowed

Hello all, I have a requirement for the following and short of any draconian methods, I'm hoping that the PA GP will be able to answer. These are PAN8.0.7 on 5520's in Active/Passive I have a req to ensure that a user of GP is only allowed one GP session at a time. No sharing sessions or passwords. Options explored inlude a unique ldap group ...

Intrazone default- what gets inspected?

Hi For traffic that matches the intrazone default policy, and assuming there are no security profiles for anti-virus, anti-malware, threat protection. etc, Is there any inspection performed? Reason I ask- I found an article on the Knowledge base about increasing performance for SMB traffic by enabling an application override for the traffic. ...

fmurray by L1 Bithead
  • 3073 Views
  • 2 replies
  • 0 Likes

Resolved! User-ID Agent Ignore a group of users

Hello together, Is it possible to ignore a group of users with the User-ID Agent, and also on the firewall without the agent? I tryed to add a group ( example\Ignore User-ID ) to the ignore_user_list.txt for the Agent. But it seemed not to work. I also tryed:example\Ignore User-IDIgnore User-ID"example\Ignore User-ID""Ignore User-ID"'example\Ign...

Clermont by L2 Linker
  • 9781 Views
  • 14 replies
  • 0 Likes

VNC Access through Global protect

Hi allWe have internal server that must be accessed through VNC and HTTP.Internally it works well but when we try to connect from outside through Global Protect it is blockedAccess Policies from GP to Internal allowed. But not working.

Radmin_85 by L4 Transporter
  • 9418 Views
  • 11 replies
  • 0 Likes

VM-Series Firewall on VMware ESXi - get true link status from host NICs

Hi, I'm in the process of deploying a VM-100 under VMWare ESXi 6.5 as standalone host (not member of a VCenter). Everything has passed smoothly, however I want my V-100 network interface list to display the TRUE link status of each physical NIC port at the VMware host. (I.e. whether or not live cables are plugged in to their respctive host NICs...

SNMP monitoring for Ethernet interfaces

Hello, We are using OPManager to monitor our internal network and we are experiencing some issues with PA-VM 200 when trying to get the traffic of certain interfaces. For all the tunnel interfaces and sub-interfaces, we can see the traffic on the monitor but can't see the traffic for the ethernet interfaces. Using PAN-OS 8.0.21) Downloaded Ente...

Farzana by L4 Transporter
  • 8687 Views
  • 7 replies
  • 0 Likes

SSL Offloading for inbound connection

We have few legacy internal applications listening on a various TCP ports. Now we have a requirement to connect to these applications from a cloud vendor externally. There is no option to setup a site-to-site IPSec VPN tunnel to the cloud so we need to expose this server to internet securly. Can Palo alto act as a proxy for inbound traffic hosti...

ganees by L1 Bithead
  • 12117 Views
  • 4 replies
  • 0 Likes

Resolved! CPU/RAM/Memory Alarms in PAN-OS

Is there a feature in PAN-OS to set CPU/RAM/Memory usage exceeding threshold x% in the same way Device>LogSettings>AlarmSettings has variables to track Log DBs? This could be useful towards spinning up a new instance for the vFW to load balance to if the current vFW instance is being pushed too hard.

timgowan by L0 Member
  • 6145 Views
  • 1 replies
  • 0 Likes

O365 Category Change

Did anyone see outlook.office365.com change category today at about 18:00 GMT? We were seeing logged as computer-and-internet-info and changed to web-based-email? This is when I find out it ws planned and I've missed about a million alerts telling me this was coming....

apackard by L4 Transporter
  • 4051 Views
  • 4 replies
  • 0 Likes

How to block Spotify in Palo Alto

Hello world ! despite spotify being an awesome P2P solution for music, it has been a headache to HR management.So, we were asked to identify an way to block the usage of Spotify in our machines.What´s the way we should use in order to get it done in Palo Alto ?

evsivier by L0 Member
  • 5807 Views
  • 2 replies
  • 0 Likes

Resolved! Admin Roles

Hi I created a 'read only' admin role, simple superuser priviledges, everything set to default. when i login with RO, the HA view for example dissappears, and the commit link is still present desite it being disabled within the Admin Role profile. I'm wondering if this is because we're using ISE...? Many thanksAjaz NawazJNCIE-SEC No.254CCIE-RS N...

nawaza by L2 Linker
  • 3824 Views
  • 3 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels