General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

What priviledge need user-id agent user to work with WMI?

Hello,

We need to know the priviledge minimum to the user-id user to work with the WMI probes and it can't look the security log of DC.

The problem is that on the security log appears one user of application siteadvisor that is installed on every PC of

...

jvmartin by Not applicable
  • 3494 Views
  • 5 replies
  • 0 Likes

Data Filtering and File Blocking Not Working

We have File Blocking enabled(mainly to log specified file types) and Data Filtering enabled(to alert/block when it detects a predeterminied string of characters).

 

While uploading a file to a file hosting site(like tinyupload.com) the File Blocking a

...

jambulo by L4 Transporter
  • 1769 Views
  • 0 replies
  • 0 Likes

Resolved! Global Protect some questions

Hi

 

I have PA-3050 Cluster and will configure SSL-VPN for remote users "without licenses installed", so I have a couple of questions on Global Protect;

 

1- How many users can connect through SSL-VPN on this device?

 

2- Can we connect SSL-VPN over mobile

...

myasin by L2 Linker
  • 2386 Views
  • 4 replies
  • 0 Likes

PA App ID Migration

Hi Guys

 

I am in the process of Doing App ID adoption for a environment.

 I have done the following

 

  1. Set Base config and move whatever I need to move to the correct Device
  2. Merge The config 
  3. Go to ap API Output manager
  4. Set settings to Full Config; Sub Attom
...

Generate an e-mail alert from a DENY policy

Hi

Just a quick question, one of my policies on my PA5020 is a "Deny_Any" policy whereby if no application matches the policy base then it gets denied. The only time I see this is when I view the monitor | logs | traffic.

 

Is there any way I could get

...

JulianH by L1 Bithead
  • 2354 Views
  • 3 replies
  • 0 Likes

LDAPS inexplicably working on 2 DCs, not on 3rd

Please suggest a better title, this issue has sent me through the ringer.

 

We have a site with an MPLS connection down.  The PAs use the domain controller in our datacenter for authentication for both admin, and GP users, which is over the MPLS.  LDAP

...

Windows 10 Store update issues: How to avoid

Dear all,

 

I recently had problems with updates from the Windows store and was debugging for a couple of days without much success until someone pointed me to a setting in PA causing the problems:

 

skip-block-http-range

 

In an older thread it is recomme

...

Resolved! Netflow not working

Hello,

 

In the Traffic monitor logs, nothing is showing up for netflow.

Using PAN-OS 7.0.4.

Tried using port 2055 and 9996.

Tried to use default and MGT interface of Netflow and SNMP Trap under Device>Setup>Services>Service Route Configuration.

 

We have s

...

Farzana by L4 Transporter
  • 3871 Views
  • 1 replies
  • 0 Likes

How to SSL Bypass based on application

Hello,

 

I wanted to share a solution I have implemented recntly.

 

Bypassing SSL Decryption based on applications was a request I had from many customers.

I know there is an FR for that. but until then, with PAN-OS 8, it is possible to achieve differentl

...

tag.png
dynamic address group.png
bypass rule.png
log forwarding.png
Ozamir by L2 Linker
  • 5825 Views
  • 2 replies
  • 8 Likes

ERR_SSL_PROTOCOL_ERROR GlobalProtect

Hi All,

 

When I try to open the URL of our portal I get the following error in Chrome:

 

Chrome: ERR_SSL_PROTOCOL_ERROR

Firefox: SSL_ERROR_HANDSHAKE_FAILURE_ALERT 

 

I also imported the wildcard certificate to 'Personal' and 'Trusted Root CA.'

 

Logs:

 

PanGP

...

DocEmre by L0 Member
  • 5527 Views
  • 4 replies
  • 0 Likes

Single Pass Parallel Processing SP3

Hi All,

 

Please can someone explain me the concept of SP3 in simple terms as i dont find any good resource to understand this.

I understand that passing the traffic through different devices will impact throughput and add latency,but how does PA works

...

mahmoodm by L3 Networker
  • 10273 Views
  • 11 replies
  • 0 Likes

Panoram and Clusters

HI

 

Sort of asked this before, but with a couple more months of experienace, I am back again

 

So I have a cluster I want to manage with panorama

 

Object and polices work great... templates not so good.

 

So I have a cluster setup for Global protect, but I

...

  • 24208 Posts
  • 99 Subscriptions
Labels