General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Intrazone default- what gets inspected?

Hi For traffic that matches the intrazone default policy, and assuming there are no security profiles for anti-virus, anti-malware, threat protection. etc, Is there any inspection performed? Reason I ask- I found an article on the Knowledge base about increasing performance for SMB traffic by enabling an application override for the traffic. ...

fmurray by L1 Bithead
  • 3169 Views
  • 2 replies
  • 0 Likes

Resolved! User-ID Agent Ignore a group of users

Hello together, Is it possible to ignore a group of users with the User-ID Agent, and also on the firewall without the agent? I tryed to add a group ( example\Ignore User-ID ) to the ignore_user_list.txt for the Agent. But it seemed not to work. I also tryed:example\Ignore User-IDIgnore User-ID"example\Ignore User-ID""Ignore User-ID"'example\Ign...

Clermont by L2 Linker
  • 10126 Views
  • 14 replies
  • 0 Likes

VNC Access through Global protect

Hi allWe have internal server that must be accessed through VNC and HTTP.Internally it works well but when we try to connect from outside through Global Protect it is blockedAccess Policies from GP to Internal allowed. But not working.

Radmin_85 by L4 Transporter
  • 9767 Views
  • 11 replies
  • 0 Likes

VM-Series Firewall on VMware ESXi - get true link status from host NICs

Hi, I'm in the process of deploying a VM-100 under VMWare ESXi 6.5 as standalone host (not member of a VCenter). Everything has passed smoothly, however I want my V-100 network interface list to display the TRUE link status of each physical NIC port at the VMware host. (I.e. whether or not live cables are plugged in to their respctive host NICs...

SNMP monitoring for Ethernet interfaces

Hello, We are using OPManager to monitor our internal network and we are experiencing some issues with PA-VM 200 when trying to get the traffic of certain interfaces. For all the tunnel interfaces and sub-interfaces, we can see the traffic on the monitor but can't see the traffic for the ethernet interfaces. Using PAN-OS 8.0.21) Downloaded Ente...

Farzana by L4 Transporter
  • 9002 Views
  • 7 replies
  • 0 Likes

SSL Offloading for inbound connection

We have few legacy internal applications listening on a various TCP ports. Now we have a requirement to connect to these applications from a cloud vendor externally. There is no option to setup a site-to-site IPSec VPN tunnel to the cloud so we need to expose this server to internet securly. Can Palo alto act as a proxy for inbound traffic hosti...

ganees by L1 Bithead
  • 12374 Views
  • 4 replies
  • 0 Likes

Resolved! CPU/RAM/Memory Alarms in PAN-OS

Is there a feature in PAN-OS to set CPU/RAM/Memory usage exceeding threshold x% in the same way Device>LogSettings>AlarmSettings has variables to track Log DBs? This could be useful towards spinning up a new instance for the vFW to load balance to if the current vFW instance is being pushed too hard.

timgowan by L0 Member
  • 6261 Views
  • 1 replies
  • 0 Likes

O365 Category Change

Did anyone see outlook.office365.com change category today at about 18:00 GMT? We were seeing logged as computer-and-internet-info and changed to web-based-email? This is when I find out it ws planned and I've missed about a million alerts telling me this was coming....

apackard by L4 Transporter
  • 4182 Views
  • 4 replies
  • 0 Likes

How to block Spotify in Palo Alto

Hello world ! despite spotify being an awesome P2P solution for music, it has been a headache to HR management.So, we were asked to identify an way to block the usage of Spotify in our machines.What´s the way we should use in order to get it done in Palo Alto ?

evsivier by L0 Member
  • 5920 Views
  • 2 replies
  • 0 Likes

Resolved! Admin Roles

Hi I created a 'read only' admin role, simple superuser priviledges, everything set to default. when i login with RO, the HA view for example dissappears, and the commit link is still present desite it being disabled within the Admin Role profile. I'm wondering if this is because we're using ISE...? Many thanksAjaz NawazJNCIE-SEC No.254CCIE-RS N...

nawaza by L2 Linker
  • 3962 Views
  • 3 replies
  • 0 Likes
  • 24450 Posts
  • 125 Subscriptions
Top Solution Authors
Labels