General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Trouble decrypting Google traffic

Hi,

we have some trouble with a lot of Google sites when we enable SSL decryption and also enable CRL and OCSP checks. We either get no response at all, or error messages like the one in the attached screenshot. If we disable the CRL/OCSP checks (whic

...

Update 377-1826 breaks youtube-safemode

Just a heads up - it appears that update 377 has broken the detection of youtube-safemode, with everything being detected as youtube-base  ; revert to 376-1817 appears to resolve the issue.

SimmSimm by L2 Linker
  • 4275 Views
  • 9 replies
  • 0 Likes

policy and security profiles

heyy

i tried to troubleshoot some traffic behaviuor, an i created a rull without any security profile and with application overide.

when i run those commands to look at the traffic i found this.

admin@PA-500> show session all filter destination 147.235.

...

minow by L4 Transporter
  • 2894 Views
  • 6 replies
  • 0 Likes

dependency warning - how to force it?

Hi

I'm bit confused about dependency ...

During commit i have:

    vsys1: Rule 'XXXXXXXXXXX' application dependency warning:

     Application 'gmail-base' requires 'imap' be allowed, but 'imap' is denied in Rule 'Scholastycy - deny rest'

     Application

...

_slv_ by L4 Transporter
  • 3148 Views
  • 4 replies
  • 0 Likes

Resolved! Security Policies - Terminology

I am coming from a Checkpoint environment and I am struggling with some of the terminology. I see a number of references in the Getting Started and the Administrator's guides to "Security Policies". To me this implies that I can create a number of po

...

jmayne by Not applicable
  • 3206 Views
  • 8 replies
  • 0 Likes

Resolved! Global Protect and two gateway

Hello

I have PA200 without licence for second GP Portal.

I did a second gateway because I thought that this should solve my problem.

I need to let access to some website to my users but with my IP address. Thease people has accounts on radius server. I

...

_slv_ by L4 Transporter
  • 3960 Views
  • 7 replies
  • 0 Likes

ICMP reply size in 4.1

Is it possible in 4.1 to limit the size of icmp replies or strip any payload in order to discourage tunneling via ICMP ?

mbecker by Not applicable
  • 2349 Views
  • 5 replies
  • 0 Likes

Resolved! OCSP on SSL decrypt with self signed certificate

When enabling OCSP and having a self signed certificate for SSL decryption

(we push the certificate to all our domain clients)

will OCSP check my self signed certificate against the OCSP responder (and fail because it is unknown)?

Or will it only check

...

mr.linus by L4 Transporter
  • 5864 Views
  • 10 replies
  • 0 Likes

Resolved! Problem VPN Split-Tunneling

Hi everybody.

I've got a strange problem related to split tunneling in PAN configuration. The situation is:

- Portal and Gateway configuration in PAN-2050 with PANOS 4.1.7 (same results with 4.1.6 and 4.1.5).

- VPN client Cisco compatible (Windows and L

...

Packet capture of specific Security Rule?

I need to confirm what traffic data (specific DNS Request strings inside the packet) is hitting two specific Security rules, so would like to capture just the traffic that is hitting these rules. Is there any way to do this?

I have run the Packet Capt

...

Netconnect File Extension

When I try to download the latest netconnect install file from the Software Updates web page it downloads without a valid file extension. When I download the file PanVPN-1.3.4 shouldnt it be PanVPN-1.3.4.msi ? I've tried renaming the file...

awdinfra by L0 Member
  • 2965 Views
  • 3 replies
  • 0 Likes

Resolved! Antivirus Compatibility Mismatch

Hi, i just realised that my two PA (active/passive) have an alert of HA Antivirus Compatibility. I have checked the version in Dynamic Updates and its the same in bot devices. CAn you tell me why this mismatch happens???

I attached an screenshot with

...

  • 24215 Posts
  • 99 Subscriptions
Top Liked Authors
Labels