General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Edinburgh - pbf + zone lookup snafus

Hi,

I'm seeing the following.

Consider:

- two existing Internet lines, put in zones "I-1" and "I-2"

- there are two L3 interfaces, one in I-1 with address PA-1, one in I-2 with address PA-2

- the default route goes to a router reachable in I-2

- there's a

...

Commit failed due to Application update

After an auto update of application we can't do a commit with out explanation on the commit page.

We discover that when we do a revert of application the commit is ok so we put off the auto update but we want it back.

How could we solve this problem ?

...

support by L1 Bithead
  • 3206 Views
  • 4 replies
  • 0 Likes

SNMP V3 Configuration

I notice that there is no example or detail descriptions for configuration of SNMPv3.  Here is my configuration which works but I never got the include/exclude mask to work.  If someone else have an example or recommendations please upload.

set device

...

blacksan by L1 Bithead
  • 4995 Views
  • 1 replies
  • 0 Likes

CPU

I would like to know that If I observe from Throughput and Session is not exceed the maximum number that box can support. What cause that may make CPU performance overload? Please kindly share idea.

Note. My box is PA2050. Thoughput is around 400Mbps

...

New PA Purchase - Rules question and any tips?

Recently purchased a PA2020 to replace our Cisco PIX 525.  I'm in the process of auditing our cisco config and recreating it in the PA.

I'm looking for suggestions on how to allow applications inside to outside and outside to inside.

I only have two zo

...

SSL VPN users unable to access the internet though Palo

Hi

     I have setup SSL VPN and its been in use for a few weeks without any issue with the exception of one minor annoyance.

I have been unable to get the SSL VPN users to be able to see the internet when connected.

1) The access route is set to 0.0.0

...

IPS functionality testing

We are looking to do a live demo of PAN devices to some leads . Does anybody have tool we can use to demonstrate the IPS functionality in real time .Putting the box through a wide range of attacks .  App ID is pretty easy but Checkpoint now does appl

...

usvi by L3 Networker
  • 1984 Views
  • 1 replies
  • 0 Likes

Resolved! Commit Failed (HA active-passive)

Hi,

Commit on customer PA500 Cluster running in Active-Passive mode on PANOS 3.1.6


Details      device: Client device registered in the middle of a commit. Aborting current commit.
Commit failed

system log:

Receive Time    Type      Severity      Object 

...

Resolved! Block Outbound SSTP (Secure Socket Tunneling Protocol)

Is there a timeline when the ability to block SSTP outbound will become available or is it possible now?

Microsoft's latest and greatest is surely a hole that it would seem most don't want in their environment.

Any insight would be greatly appreciated.

...

micit by L1 Bithead
  • 3062 Views
  • 3 replies
  • 0 Likes

Resolved! User-ID Agent for Active Directory won't transfer mappings

Hello-

I have a new PA500 (running 4.0.4)  that I've set up and am now trying to tie to Active Directory in order to create user-based policies.  I have everything configured to my knowledge, but I'm not getting any user-IP mappings on the firewall.

I

...

Resolved! Data Filtering by Name

In "monitor" --> "Data Filter"  is there a way to filter by name?  The name shows things like zip and rar and filtering by this automatically would be very useful.  Or is this available in a feature-set beyond 4.0.1?

Also, the release notes for 4.0.5

...

SSLVPN/Netconnect Command Line

Hello,

Is there a way to interact with the SSLVPN/Netconnect application via command line arguments? Can you script any portion of the launch of Netconnect?

Thanks,

-Paul

PANOS 4.0.6

Hi - I can see PANOS 4.0.6 in the software section on my Panorama. I can't see it as available when I go onto my PA 4050s though - it's still showing 4.0.5 as the latest available code to download. On the support website - it's mirrored again in the

...

fmd by L3 Networker
  • 1930 Views
  • 2 replies
  • 0 Likes
  • 24290 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors
Labels