General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

ADFS SAML Configuration

Hi all I need help to configure ADFS SAML with global-protect.i have successfully imported the metadata.xml from adfs into palo.But now i can't export the metadata from paloalto. Whats the correct identifiers and endpoints urls for global-contect clientless? I have no idea, what i must configure in adfs. Can anyone help?I use panos 8.0 regards...

Screen Shot 2017-02-25 at 03.50.54.png

Security Policies Not Applied When Client Use Web Proxy on Their Browser

Dear all, I am currently learning the Palo Alto Firewall using Palo Alto VM. I've configured some security policies, for example, file blocking that forbide client to upload a PDF file (including to those website which use SSL). All of the policies are working as expected. Then, I try to set the client web browser to use a web proxy (Squid) loca...

hibagus by L2 Linker
  • 8825 Views
  • 10 replies
  • 0 Likes

Understanding Panorama Backup and Recovery Procedure

Hypothetical Scenario... Through catastrophic failure I have lost my Panorama which also contained device configs. In order to re-build it from scratch which config file should be saved and exported, and then imported?, I note there are few option around 'snapshot' and 'config-bundle'. But to me the documentation is not entirely unamgibuous, tha...

nawaza by L2 Linker
  • 4243 Views
  • 1 replies
  • 0 Likes

Resolved! Query on TS Agent

Hello, We are planing implement TS Sever. Kindly advise if Windows Firewall needs to be disabled on Server for TS Agent implementation. Please provide the reason for the same whether yes/no. Thanks in advance.

Farzana by L4 Transporter
  • 2220 Views
  • 1 replies
  • 0 Likes

Logs export and viewing

Hi,I have a requirement to be able to maintain logs (all url,threat etc) for a period of atleast 6 months, this should be independant of the disk space. I have founf out that from the command line you can export the logbd using scp and back it up, bu the only downside is, correct me if i am wrong, the exported logdb can only be viewed in the Pal...

Resolved! Changing Time Zone

What are the implications of changing the time setting / time zone of a palo alto firewall in an HA setup?Are active sessions affected?

Miner for firehol

This one is fairly straight forward. Based on an ipv4 miner: attributes: confidence: 50 direction: inbound share_level: green type: IPv4ignore_regex: ^#source_name: firehol.blocklist_net_uaurl: https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/blocklist_net_ua.ipsetuser_agent: MineMeld There are a ton of lists just under his ...

chirss by L3 Networker
  • 5499 Views
  • 2 replies
  • 1 Likes

GlobalProtect Client Version Report

When deploying the GlobalProtect client upgrades, is it possible to run a report to see what GP Client version everyone has installed? This will allow us to see how well an upgrade is going to remote computers, and if any computer may not be communicating properly to the portal?

How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)

Dear all, I am looking for a way to get a site2site tunnel working between a Palo Alto with static public ip and a Palo Alto with a "dynamic" endpoint (public ip through dhcp)The tunnel shows as status green in the GUI and also on CLI it shows up, but no traffic is passing. I found a how to through the Palo Alto pages, and I am using the User FQ...

Configuration of Logs PA220 - log database exceeds alarm

Hi, I just can't get a handle on logging. Currently the PA220 reports with PanOS 8.0.5 "Current size (357 MB) of threat log database exceeds alarm threashold value (90%) of total allowed size (368MB"). I have already tried to change the quota % values under Device -> Management -> Logging and Reporting Settings. But how do I get the PA to ...

Resolved! Fail to configure download limitation on my pa firewall

I want to limit download for our subnets. I configured a qos policy and a traffic class profile, next apply on trust zone interface. Then I saw in the statistic, there was runtime bandwidth in class 4, it seemed that all traffic was defined as class 4, there was not runtime in any other class. Could you tell me where I wrongly configured ...

image.png
image.png
image.png

How to add local rules above panorama managed rules, above the pre-rules if Panorama is down

My question would be if Panorama is unavailable and we need to apply a new local rule on a firewall(to block something), how can we create this new local rule and move it above the Panorama managed Pre-Rules? Correct me I am wrong, but any new local rules will be applied below all Pre-Rules and above the Post-Rules.

Resolved! MineMeld hanging after reboot

Dear Luigi, We are having a lot of issues with MineMeld, I hope you can help. We are deploying MineMeld with our customers on their own vmware environment in a DMZ zone with NO DHCP. I know you prefer to use AutoFocus, MineMeld in AWS, MineMeld on Ubuntu or MineMeld with DHCP, but this is not always feasible for our customers. In any case ...

2017-11-09 13_35_21-New notification.png
2017-11-09 14_18_15-Photos.png
2017-11-09 14_24_14-Settings.png
2017-11-09 14_24_37-Settings.png
mr.linus by L4 Transporter
  • 6794 Views
  • 1 replies
  • 0 Likes

Apply policy security on vlan

HelloPlz i need ansewr as soon as possible, can i apply the security policy rule on vlans ? for exepmle let vlan 10 connect to facebook, but bloc facebook for vlan20 ??

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels