General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! URL Filtering vs. Dynamic Block Lists

Does URL Filtering override Dynamic Block Lists?

 

Say an IP address is listed in the Dynamic Block Lists but I want to allow access to a specific URL that resolves to that IP address. Will whitelisting the URL allow access or will it still be blocked

...

Sort ascending or descending in Custom Reports

I am trying to write a Report that shows the least number (e.g. 50) of used rules in my firewall.  The sort feature in the custom report builder only is sorting from largest to smallest.  I can't see how to reverse this.  Anyone know?

merrick by L1 Bithead
  • 1405 Views
  • 1 replies
  • 0 Likes

Can't access management when PA200 is in line

I have a PA200 and when I only have the management port plugged in, I can access the management interface. When I put it inline and have production traffic running through it, I'm no longer able to access the management interface. I have two NAT rule

...

kbreit by L1 Bithead
  • 1583 Views
  • 3 replies
  • 0 Likes

Active Directory group naming scheme

Hi all,

I'd be interested to here is anyone has come up with interesting naming schemes for AD groups used within Palo Alto firewall policies.

I'm looking for inspiration as I'm looking to come up with a logical scheme on our end.

 

Cheers.

Local admin account locked

I have a cluster of two Panorama systems.  When I try the local admin account on the primary-active node the system generates a log entry saying that 'failed authentication for user admin.  Reason: User is in locked users list.  The same account name

...

birish by L0 Member
  • 7045 Views
  • 1 replies
  • 0 Likes

BGP "no enforce neighbor-as" option?

Hi,

 

Is there a configuration avaialble to not enforce the requirement of a BGP peer including their AS in the advertised path?

 

This is required in peering exchanges where there are central route servers which function transperantly by advising of nex

...

CMG by L2 Linker
  • 969 Views
  • 0 replies
  • 0 Likes