General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 355 Views
  • 0 replies
  • 0 Likes

SSL-VPN client can't connect

Have a security consultant that is trying to connect to our PAN SSL-VPN and thinks there is a bug and wanted me to report it.  He was using NetConnect SSL VPN client 1.3.1 with win7 and IE9. They could not get connected and got the following error;

j

...

dwgg by L1 Bithead
  • 2522 Views
  • 2 replies
  • 0 Likes

Panorama Logging Traffic Flow

Hi All,

Does anyone have any indicative figures of the amount of data that flows from a PAN apppliance to Panorama?

Say a 4050 running at a consistant 50%, and logging everything = xMB/day of logs?

I'm trying to calculate what will be required to have P

...

KatanaNZ by L3 Networker
  • 3637 Views
  • 3 replies
  • 0 Likes

Resolved! source and destination ports

Under security rules does service refer to source port or destination port and what is the best way to define both source port and destination port in a rule on version 3.1.6

ailfionn by L0 Member
  • 3702 Views
  • 3 replies
  • 0 Likes

Upgrade to 4.0.4 image version failed

Hi to all,


We've two PaloAlto firewalls PA-2020 with 3.1.6 software image version and HA licensed.Both have active gold maintenance support. Last week we tried to update to the last version 4.0.4 and the upgrade process failed.

Step 1

We started with th

...

How to setup multiple SSL-VPN tunnels

I'm hoping I'm missing something obvious here...is there a good way to support SSL-VPN access for different types of users who require different access and use different authentication schemes?

I am trying to setup multiple SSL-VPN tunnel configuratio

...

Resolved! Maximum life-time of SSLVPN

Hi all.

I have 3 questions about SSLVPN session time-out.

1. MAXIMUM LIFE-TIME of SSLVPN session?

2. What are the default values of Login life-time and Inactivity logout if it isn't set.

3. The meaning of "Logout/Expiration" and "TTL" come out by "show s

...

itnsystem by Not applicable
  • 3425 Views
  • 3 replies
  • 0 Likes

bypassed PAN box using free proxies

We are tested PAN 500 NFR in our lab . Did a search for youtube proxy on google and picked the first listed . Used them and bypassed the PAN box and was able to get to facebook and yahoo mail . I couldn't get to these sites through my browser directl

...

usvi by L3 Networker
  • 3224 Views
  • 4 replies
  • 0 Likes

PA500 split tunnelling DNS question

Hi

Have a PA 500 set up for split tunnelling - so clients access internet locally and all other traffic is passed over VPN tunnel to our office

I have DHCP set up on PA box so clients get primary DNS server (local ISP one) and secondary DNS (office one

...

sue_town by Not applicable
  • 3442 Views
  • 7 replies
  • 0 Likes

Gaming devices behind PAN firewall

We are using Capitive Portal for students on our campus. All students' devices including gaming devices get DHCP from a PA2050 and these IP ranges require CP. XBox seems to get DHCP and tries to connect to XBox Live servers, but fails. We don't see t

...

kumara by L0 Member
  • 1988 Views
  • 1 replies
  • 0 Likes

Resolved! Issues with email reports on iOS devices

So interesting issue don't know if others have the same issue.  Email reports that are generated in the firewall and sent via email on schedule.  When I view the PDF on the iPad (newest version of iOS) there is no text in the report it only has the g

...

kkeeton by L2 Linker
  • 2460 Views
  • 1 replies
  • 1 Likes

uid-gids-cache timeout

Hi there,

we use the pan-agent installed on a DC to read out the users of some AD groups. Works fine so far. The only problem we got is, that if a user is removed from an AD group, I will always have to run the "clear uid-gids-cache" command on the de

...

Cert issue with Captive Portal

We have installed a Comodo wildcard cert on our 2050 for use with the SSL-VPN and Captive Portal.  IE and Chrome are fine, but Firefox always says the it can't verify the authenticity of the cert.  I remember reading in another post that someone had

...

bvest by Not applicable
  • 2006 Views
  • 1 replies
  • 0 Likes

Permanently cached user to IP

Did a search, but nothing seems to answer my question:

I would like input from more knowledgable folks on the problem described - the permanent caching of a "good" account on computers that are kiosk mode and logged in with "ignored" accounts.  See ex

...

jasbeck by Not applicable
  • 4568 Views
  • 8 replies
  • 0 Likes

RDP incomplete session

RDP worked before the installation of PAN 500. Now I'm having an incomplete session on RDP (TCP handshake is dropping). How do I fix this:

760     t.120          DISCARD FLOW  NS   172.21.196.181[4483]/l3-trust/6  (70.159.69.130[2588])
vsys1           

...

  • 24057 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels