General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Certificate-based Authentication for the WebUI

Hi,

I read about "Certificate-based Authentication for the WebUI" article. I am not sure if we can use it in our enviroment:

- We have our enterprise CA and each admin has a CA Certificate. We are using those certificates for other purposes like admi

...

ENAGAS by L0 Member
  • 1768 Views
  • 1 replies
  • 0 Likes

Proper Cisco Network Configuration With Palo Alto's?


Please forgive my ignorance, when it comes to Palo Alto's.  This is the first time I've dealt with them.  We have a need to secure a localized VLAN behind the Palo Alto's.  I'm including a diagram to show a simulation of what we're looking to do.  We

...

degreek21 by Not applicable
  • 1635 Views
  • 0 replies
  • 0 Likes

Email Notification when a user logs into the PA Box.

Hi team,

I am working on case: 00188973 where the customer want to get a real time email notification when a any user logs in to the firewall via GUI or CLI.

Do we have any such feature available now on PA Box.

If not, DO we need to raise a feature requ

...

Resolved! acc risk factor

Hello Support Team,

I'd like to know a mathematical formula of acc risk factor.

It doesn't seem a session-based average value.

Regards,

Tomoyuki Komure

Tomoyuki by Not applicable
  • 11246 Views
  • 7 replies
  • 1 Likes

Application block page - not enabled by default

I've noticed in PAN OS 5.x that the application block page is not enabled by default. Obviously it can be manually enabled.. but was this done for a specific reason to address some common problems experienced by customers?

I could surmise that perhaps

...

CMG by L2 Linker
  • 2663 Views
  • 3 replies
  • 0 Likes

Convert from vwire to layer 3 for globalprotect.

I'm trying to put together a plan of action to get globalprotect to work for us. I have a work ticket open with PA. Our PA firewall is currently deployed in a VWire setup, on the lan side of our router. Here are my big questions for getting this acco

...

Netwerx by L2 Linker
  • 3479 Views
  • 3 replies
  • 0 Likes

Resolved! SYN-Flood packets dropped by unknown rule

Hi everybody,

we got a lot of syn-packets which were dropped  by the rule any-allow. But we haven't this rule, so is it a inbuilt rule and

why do i need a DoS-Rule to be protected against Syn-Floods if there is a builtin rule.

Cheers klaus

kdd by L4 Transporter
  • 5145 Views
  • 14 replies
  • 0 Likes

Response Page Operation

All,

So, just a possible silly question about the order if you will of response page activation - specifically around the Application Block and the URL Block.  Per the documentation:

Application Block Page:  Activated when application access not allowe

...

mrsold by Not applicable
  • 1704 Views
  • 0 replies
  • 0 Likes

Resolved! Decryption policy Issue

Hi All,

I'm just trying to configure decryption. because I'm facing Issue while blocking applications(not all the applications got blocked as the policy supposed to do).

First of all, I'm using Trusted CA, and here you are the steps I followed To gener

...

Resolved! GlobalProtect with NATet interface

I have a PA200, and is using eth1 for outside (internet) and eth2 for inside. I'm NATing from eth2 to eth1, as normal.

Now i want to have the management https address on the eth1 for several reasons.

At home its just for testing, but at my office i hav

...

Dropbox (again)

Hello,

We have a requirement to do the following

Block dropbox for some users

Allow dropbox web for some users but block app - use ssl decryption to control uploads

Allow ALL for 2 VIP's - no decryption required

Is this at all possible?

depps by L1 Bithead
  • 3562 Views
  • 4 replies
  • 0 Likes
  • 24208 Posts
  • 99 Subscriptions
Labels