General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 310 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3653 Views
  • 2 replies
  • 14 Likes

Resolved! Test Mail getting failed

Dear Team,

 

We have tried to create a email scheduler, We don't have a local SMTP server. We getting the below error,

 

 

Please find the packet flow below.

 

c2s flow:
                source:      10.1.1.5 [LAN]
                dst:         172.217.194.109
 

...

VishnuPS_0-1630582731903.jpeg
VishnuPS by L3 Networker
  • 6022 Views
  • 2 replies
  • 0 Likes

Disable Weak cipher suite

Has anyone had success getting past a B on ssllabs for the globalprotect web portal

 

# TLS 1.2 (suites in server-preferred order)
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)   ECDH secp256r1 (eq. 3072 bits RSA)   FS   WEAK256

TLS_DHE_RSA_WITH_AES_256_CB

...

Joshan_Lakhani_2-1597424067542.png

GlobalProtect Portal SSL in PANOS 8

Hello all,

 

I have noticed an important difference in PANOS v8.0 in comparison with PANOS 7.x.x concerning the SSL settings for the GlobalProtect portal.

 

More specific, the famous site for SSL Server tests, Qualys SSL Labs presents PANOS 7.0.x with Gr

...

ggoudr by L2 Linker
  • 4805 Views
  • 4 replies
  • 1 Likes

GlobalProtect Split tunneling support on Chrome OS

We have implemented split tunneling in GP configuration for operating systems including Windows, iOS, and ChromeOS. It is working on all devices except Chromebooks. Doing further research, we are not very clear whether split tunneling is supported on

...

JatinSingh_1-1630476320899.png
JatinSingh_0-1630476280089.png

Resolved! FQDN with 80 characters not resolving in Address object

Hi All,

 

I have a client running PAN OS 8.1.3 Panorama 9.1.3, that is trying to implement an Address object with an FQDN that is 80 characters long. When clicking the resolve button in the Address object GUI it does not resolve. When running the comma

...

Ben-Price by L4 Transporter
  • 2593 Views
  • 2 replies
  • 0 Likes

How to connect MineMeld to MISP

I tried following the steps at GitHub - PaloAltoNetworks/minemeld-misp: MineMeld nodes for MISP but to no avail.  My searches for other sites or resources have not proven successful.  Can someone point me in the right direction so I can integrate our

...

Gmail, Me email not being allowed through on Mac Mail

Hi,

I use gmail.com and me.com for email.

when I used the web interface, no problem at all.

But when I use my Mac (OS X 10.6.6) Mail client 4.4, however I for some reason or another the client cannot access these two email accounts it just times out.

...

djbisbey by Not applicable
  • 3284 Views
  • 3 replies
  • 0 Likes

Resolved! Exclude all Zoom traffic from GlobalProtect VPN

We have been trying to exclude all Zoom-related traffic from the GlobalProtect VPN tunnel.

 

So far we have tried with: "*.zoom.us" exclusion configured directly on the GP gateway as a domain in:

Network --> GlobalProtect --> Gateways --> GW NAME --> Ag

...

MarcelST by L3 Networker
  • 54054 Views
  • 59 replies
  • 0 Likes

User-id agent secure connection using enterprise CA

We are using one user-id agent for four locations and want to use enterprise CA cert to resolve vulnerability detected on port 5007.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGFCA0

 

Have below queries :

1. Can we genera

...

Deepak25 by L3 Networker
  • 2078 Views
  • 2 replies
  • 0 Likes

U-turn Nat between isolated networks

Hey Guys and Gals

 

I am having an issue getting u-turn nat to work between two isolated networks on the same Palo.  I am basically tiring to allow Interanal clients to access a webcam server in a IoT network.  I think might issue might be that I need

...

u-turn Nat.jpg
trees by L1 Bithead
  • 4169 Views
  • 3 replies
  • 1 Likes

Palo Alto multiple configuration for log forwarding

Hello,

I am in the process of setting up a server for syslog relay to Azure Sentinel. Currently my Palo Alto systems forward their CEF logs to LogRythm. I am looking for a way to set up my Palo Alto to forward the same logs to the new syslog relay se

...

Ematek by L0 Member
  • 1447 Views
  • 1 replies
  • 0 Likes

Spotify and URL Filtering

Hello

 

Spotify, besides being detected as a application, connects to certain URLs for information.

 

What URLs are these? Id like to making a URL Filtering category so I can allow this traffic to pass.

 

Thank you.

riahc3 by L1 Bithead
  • 1974 Views
  • 2 replies
  • 0 Likes

Anyone else have a ton of these?

URL filtering I keep seeing lots of clients for this URL:

 

play.google.com/log?format=json&authuser=0

 

Anyone know what application can be causing this request from the client PC?

 

Block domains using EDL

Hi,

 

We are doing test in order to block the domains using EDL but its not working. We are doing test with this domain: unrealengine.com

This is the config:

 

The domain is added to the EDL domain list:

 

The antispyware profile is created with the list:

 

T

...

Minemeld1.JPG
Minemeld2.JPG
Minemeld3.JPG
Minemeld4.JPG
BigPalo by L4 Transporter
  • 2914 Views
  • 2 replies
  • 0 Likes

use of binaries in Global Protect

Hello

 

I want to know if the binaries  wa_3rd_party_host_32.exe and wa_3rd_party_host_64.exe are essential for use in Globlal Protect, and what service of Global Protect are use these.

I see this articule:

https://knowledgebase.paloaltonetworks.com/KCSA

...

BigPalo by L4 Transporter
  • 3253 Views
  • 1 replies
  • 0 Likes
  • 24185 Posts
  • 100 Subscriptions
Top Liked Authors
Labels