General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Comparitn two device configs to find missing and inconsistent entries.

we have a head office and disaster site PA3020. It's taken 2 months to get the DR firewall online, originaly it was a clone of the HO one so all settings were the same ( excepet ones that had to be unique) But now after that 2 months we have made a number of changes to the HO which were not reflected in DR. Is there an easy way to take the two c...

Resolved! Query on User-ID Agent

Hello, The issue we are currently facing is we have reached the maximum amount of items 50 in the PA user id agent software and currently have it running on 2 servers and have 100 devices now again we need to install on a third server to allow for more items. Is there another solution? or new version that allows more then 50 items?We are using P...

Farzana by L4 Transporter
  • 3058 Views
  • 3 replies
  • 0 Likes

Resolved! updates.uswest2.gslb.paloaltonetworks.com

Hi Team, Has the update server changed for dynamic updates ? updates.paloaltonetworks.com showing generic communication errors. A ping to updates.paloaltonetworks.com resolves to the address in the title, when ye change it in the config [device>setup>services>update server] connects again fine.. admin@TAC-HomeLab> ping source 10.1...

updateError.GIF
original.GIF
newone.GIF

Antivirus reset-both action for mail protocols

Hi! We enable the blocking email viruses attachement by setting the antivirus profile with an action “reset-both” for SMTP. The virus attachement could be blockded, however the sender’s mail server keep retry until timeout and no undelivered mail message returned to sender. Please advice? Thank you!Device : PA3050, PANOS 7.08

BillKuo by L0 Member
  • 8801 Views
  • 6 replies
  • 0 Likes

Authentication policy

Hello,I'm in proccess of migration from TMG to Palo Alto. One of the rules on TMG whic is used to publish web site to the Internet have AD autehntication enabled. Because I can't change anything on web server and I have to enable some kind of authentication when users are connecting to this site, I was thinking to use PAN Authentication policy f...

Resolved! When to upgade from 7.1.14 to 8.0.6

Hi Everyone,I know this is more of a personal choice rather than a exact science , I am currently running 7.1.14 on a PA 3600 which is very stable for my organisation at the moment, however I do not want to fall to far behind firmware levels , so I am beginning to question when to move to the current F/W My question is , have alot of people up...

Stuck out of management

Hello guys, I have made a stupid mistake on a PA-820. I have changed the Permitted IP in the Interface Management Settings to a single IP (the Panorama server) and now I cannot access the device anymore. Any ideas? I cannot access even in SSH. The Pan-OS versionis 8.0.3 and is peered with another device (that I can access). Thanks

Shye80 by L1 Bithead
  • 3809 Views
  • 2 replies
  • 0 Likes

Resolved! Question regarding VM series HA after a hardware failure

I am new to VM series PAs and looking into how to setup HA. So it is interesting that the license is attached to the host and VM file location. Any change in this needs a re-registration of the license via tech support. Even using VMotion would trigger a need for a support call. I then assumed that I could put one VM on a separate Hypervisor...

Panorama Read Only mode?

Hi all, I cannot modify my Panorama templates (Network, Device), even though I logged in with the admin account. As I attached the screenshots, it says (Read Only) mode and grayed out the check boxes, so I am unable to modify the Interface Management Profile or Services. However, the Device Groups (Policies, Objects) are okay. Does anyone have a...

Panorama_ReadOnly_services.jpg
Panorama_ReadOnly_interfacemgmt_profile.jpg

Multiple DHCP Scope’s on 1 interface

I have a router with 2 VLAN’s. The router is connected to a PaloAlto and behind this PaloAlto I have a server witch serves DHCP. The VLAN interfaces on the router are configured with a helper address to the DHCP server. We would like to remove all servers (and go fully cloud based). I decided I want the PaloAlto to serve the DHCP function. So: I...

Sjoerd by L2 Linker
  • 9299 Views
  • 6 replies
  • 1 Likes

App-id not working on some Apps

I am seeing a number of applications which have definitions, but are not being identified correctly: kaokatalk, league of legends, battle.net and guild wars to name a few. these are showing the correct ports but showing as "unkown-tcp". Is there some way to update these, reset the definitions, etc.?All of my App-ids are up to date.ThanksBob

BobW by L4 Transporter
  • 8244 Views
  • 3 replies
  • 0 Likes

Resolved! GlobalProtect Enforce Connection for Network Access Captive Portal detection

Hi, We are using global protect with the following agent features : GlobalProtect Enforce Connection for Network Access enable and Captive Portal detection enable with timeout of 3600 seconds. Howver we can see many cases at some hotels, and airports where the actual portal detection is not being recognised by Global Protect agent. Hence user ca...

Traps - Permit .exe file with specific certificate

Hi, We would like to add a specific certificate ("Exacq Technologies, Inc") to the TRAPS database so that it recognizes all the ".exe" with this certificate as correct and it is not necessary to upload them to Wildfire, since due to the size limitation of the files to be sent configured in the TRAP console itself, these are not analyzed and ther...

  • 24436 Posts
  • 125 Subscriptions
Top Solution Authors
Labels