General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Not-resolved URL category

Having issues with many urls being categorized as not-resolved - tried failing to passive box and same issue. Also have tried to recatergize a url from within the firewall gui (url logs) and get an error: 'This functionality is unavailable as this device is in passive state or is connected to a private instance of the PAN-DB servers. Please subm...

clewis1 by L3 Networker
  • 6833 Views
  • 2 replies
  • 0 Likes

Filtering Microsoft Exchange Server services [Outlook Anywhere, ActiveSync, OWA]

We are using Exchange 2013 and have the Palo Alto allowing https access to it so our users can use OWA and ActiveSync. We recently discovered that users can also connect an Outlook client to our Exchange server from anywhere (no VPN needed) as long as they have a valid mailbox and password. We do not want this to be allowed but don't want to b...

jrauman by L2 Linker
  • 9712 Views
  • 6 replies
  • 0 Likes

Resolved! How to block Dish Network application

I have a user that is abusing their privileges and would like to block services internally. A user wished to have the Dish Network application installed on their laptop to use while traveling. There has been reports that the use was using the application in the office while on the network. I wish to block services to this application while on th...

ksmith by L0 Member
  • 8116 Views
  • 6 replies
  • 0 Likes

Resolved! When setting Strict Security Profile

Good day everyone need help with verify some information about setting strict security profile. We are wanting to set the all Security profile from default to strict to help contiune doing the best security practices recommend by palo alto. Also not wanting the logging in the threat montior to show traffic we already know is ok. So when we are m...

Resolved! URL Filtering doesn't work with Google-base/quic/google-docs

Hi Everybody I have a customer who whant to block this page "goo.gl/forms/NeclIZETrjUiyFBT2" (seems to be used as malware). We include it in "block list" in the Url Filtering Security Profile but it doesn't block it. In monitor tab, the session doesn't appear in Url Filtering, it appears in Traffic, the paloAlto detects the flow as application ...

SOC_CSG by L4 Transporter
  • 16550 Views
  • 7 replies
  • 0 Likes

App-ID for general internet browsing

This is a question for the Heavy App-ID users. How do you handle the rules for normal internet browsing? My users have access to most of the internet (except for a handfull of URL catagories) I have been trying to figure out something using Application filters, but cant seem to quite hit on the right filters for an allow rule (seems like app-f...

Kaje by L2 Linker
  • 7244 Views
  • 7 replies
  • 0 Likes

Resolved! Advice needed for WiFi network

Hello I have network dedicated for WiFi: 192.168.33.0/24 with DHCP on PA box. Lease time is 30min but even with that there is a lot of commited IP's that are unusable because of lack of Wifi coverage. I'd like to expand it and get more than 250 possible IP's - how to achieve it Sorry for silly questions ...RegardsSlawek

_slv_ by L4 Transporter
  • 3502 Views
  • 3 replies
  • 0 Likes

Setup HA now and update Licenses later?

HI there,Right now we have single PA-3020 as our HQ firewall.We are planning on setting up HA on a pair of PA-3020. Right now we only have been approved for a budget of the secondary hardware. We have been approved to add matching software licenses in December. I was wondering if it is possible to setup an HA with primary firewall having full li...

Create device group to use it on panorama target field

Hello,I use Panorama to deploy some policy rules to my 40 firewalls.Obviously some rules are the same for all firewalls, others are specific to a some of them. Is it possible to create different groups of firewalls and deploy the rules to the groups. So if I have to add/change a FW to a panorama rule, will be sufficient to modify the group and n...

FassaSRL by L1 Bithead
  • 4021 Views
  • 3 replies
  • 0 Likes

Resolved! GlobalProtect Update failure - from 2.0.0 to any higher version

Hi everyone,My current GP Client version is v2.0.2 and we need to update to v4.0.0. Apparently, whenever i tried to download (via Device -> GlobalProtect Client), i always get this error message below, no matter what version of GP Client i try. I checked via CLI to get more details about the failure, but it pretty much gave the same context: ...

GPClientDownloadError.jpg
GPClientDownloadErrorCLI2.jpg

Resolved! authenticate with domain\username in Global Protect

Hi Guys, i have set the authentication Profile (username Modifier) to %USERDOMAIN%\%USERINPUT%because i want all user currently using GP to add thei domain as well not just the username.the Profil has been added to the GP authentication section.but everytime i just get failed authentication from these users.but the second authentication profil i...

big_Gilo by L2 Linker
  • 15878 Views
  • 6 replies
  • 0 Likes

Resolved! How to specify specific users / groups in URL Filtering Policies

Hey guys! We got a couple of 7050s in our Data Center with URL Filtering license, and we are planning to implement the URL Filtering feature. I understand first thing is to create the URL profile with the allowed / denied categories and attach it to the Security Policies that allow outbound Internet access. But my concern is how to enable the u...

Action is Reset-Both in the Detail Log view area

Hello everyone question, I have been seeing this on the Threat montior area. I just need someone to verify what I am seeing is correct. This shows me that action was reset-both, which tells me file never got inside When I look at the Detailed Log View it shows something else. I am thinking that issue was not reset but file did get downloaded. If...

Reset-Both 1.JPG
Reset-Both 2.JPG
Reset-Both 4.JPG
Reset-Both 5.JPG

regarding Content Apps & Threats version

Good day everyone, I look to see what everyone is doing about updates for Content Apps & Threats version on the palo altos. Are you doing the auto-update or are you waiting to install it later to make sure no issues happen? If you are wanting to install it, what is are the security concerns that you came up with ?What are the productions co...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels