General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Receive an email when an HIP rules not match

Hello, I m going to enable HIP on our global protect so i m testing it and it works very well but i can t find how i can receive an email when a hip profile is not match. I have enabled the log transfer in device -> log settings. So i receive emai even hip match or not but i can find how send eamil on hip not match only Can you help me Thank...

vbe by L0 Member
  • 2657 Views
  • 2 replies
  • 0 Likes

Internet via Mgmt interface

How do you configure the management port to access internet? I have set with default gateway but do I need to had a route to 0.0.0.0 ? I only have the mgmt port connected at this time.

Resolved! GlobalProtect not using AD group

Hi, I am running a PA-VM on AWS. It has two interfaces, one for management, one for data.I have created an LDAP connection to our network and can log into GP using my AD credentials. So far, so good. I need to have separation of users and assigned IPs based on group membership. I have an authentication profile with two sequences. One to match on...

Connect Linux Machine to GlobalProtect

Hi, This is my first post, so please bear with me if this is the wrong forum of if this has been answered somewhere before.. I am having issues connecting a Linux client to Globalprotect. I have tried to follow the following:https://live.paloaltonetworks.com/t5/Management-Articles/Connect-Linux-Machine-to-GlobalProtect/ta-p/77307 But that did no...

Device block on MAC without Global Protect

Hi, Would anybody know if there is a way to block devices on a LAN (without Global Protect)? I know reservations and static IP's can be assigned but asking the question to see if it's a possibility. Many thanks Will

CDS_Will by L0 Member
  • 2251 Views
  • 2 replies
  • 0 Likes

Traffic Flow in SSL VPN

Hi All, Please can someone explain me the traffic flow in SSL VPN as am a bit confuse about it. I might come up with more questions once this discussion starts. Thanks

mahmoodm by L3 Networker
  • 3197 Views
  • 3 replies
  • 0 Likes

What priviledge need user-id agent user to work with WMI?

Hello,We need to know the priviledge minimum to the user-id user to work with the WMI probes and it can't look the security log of DC.The problem is that on the security log appears one user of application siteadvisor that is installed on every PC of domain.Then, when we execute the Get All on User-Id Agent, the 90% of IP addresses are assigned ...

jvmartin by Not applicable
  • 4910 Views
  • 5 replies
  • 0 Likes

port 443 for Minemeld not opened. Cannot log into Web Console

I am brand new into Minemeld. I followed the link https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-on-VMWare-desktop/ta-p/72038 for installation and followed steps. All seemed to work fine. There was a note that to access Minemeld, it would be using 443. Great. I opened my browser up and attempt to reach the DHCP...

scantwell by L4 Transporter
  • 8511 Views
  • 4 replies
  • 0 Likes

Error when trying to renew certificate "Failed to write issuer certificate to disk"

Hello, When trying to renew some certificates (already expired and signed by a internal windows server) we receive the error message below: "Failed to write issuer certificate to disk" This is a VM-100 modelWe have other boxes (PA200 and 3020) with the same scenario (certificates signed by windows server and uploaded to PA box) that can be rene...

2017-02-06.png

Resolved! Global Protect some questions

Hi I have PA-3050 Cluster and will configure SSL-VPN for remote users "without licenses installed", so I have a couple of questions on Global Protect; 1- How many users can connect through SSL-VPN on this device? 2- Can we connect SSL-VPN over mobile phones using the same configuration required for remote users (gateways and portal), or there is...

myasin by L2 Linker
  • 3792 Views
  • 4 replies
  • 0 Likes

Generate an e-mail alert from a DENY policy

HiJust a quick question, one of my policies on my PA5020 is a "Deny_Any" policy whereby if no application matches the policy base then it gets denied. The only time I see this is when I view the monitor | logs | traffic. Is there any way I could get an email sent to me when the DENY policy is matched? Thanks in advance Julian

JulianH by L1 Bithead
  • 3487 Views
  • 3 replies
  • 0 Likes

LDAPS inexplicably working on 2 DCs, not on 3rd

Please suggest a better title, this issue has sent me through the ringer. We have a site with an MPLS connection down. The PAs use the domain controller in our datacenter for authentication for both admin, and GP users, which is over the MPLS. LDAP requests of coures.. fail. We also have a DC in Azure, which the PA has an IPSEC tunnel attache...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels