General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 95 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3336 Views
  • 2 replies
  • 14 Likes

Possible to disable SSH CBC cipher and weak MAC hashing?

Hi,

 

May I check if it is possible to disable SSH CBC cipher and weak MAC hashing on Palo Alto Firewall?

If so, may I know how to do it.

 

Had no luck searching for a solution online.

Seems like there is no menu/config file (e.g. /etc/ssh/ssh_config) to e

...

boss82 by L0 Member
  • 12952 Views
  • 3 replies
  • 0 Likes

Move interface to different vsys

Interface ethernet1/1 is currently in vsys1. When I try to change this to vsys2 from Panorama I get the message that the interface is already in use (by vsys1).

 

If I try to remove it from vsys1 in Panorama push is OK, bit it is still in vsys1 on the

...

hncl01 by L0 Member
  • 1278 Views
  • 0 replies
  • 0 Likes

/dev/shm filling up after 10.0.6 firmware

TMPFS partition /dev/shm on the VM series PAN.

 

Typically this is cleared on reboot but after upgrading to 10.0.6 its failed to clear the space on system reboot.

 

We have looked at the other drives on the PAN are there seems to be no capacity issues ot

...

Enable split tunnel for Zoom

Hi

 

We are planning to exclude all zoom traffic from Global protect VPN and currently we are using 4.1.5 GP agent version.

 

I have gone through the zoom documentation and created EDL but not getting option to exclude the EDL (external dynamic list ) in

...

Yusuf_PA by L1 Bithead
  • 4895 Views
  • 3 replies
  • 0 Likes

Resolved! 3250 HA setup

Hello

I am trying to setup HA on a pair of 3250s and am a little confused between what the datasheet says and what's available. Is there an example out there of how to set the ha1-a and ha1-b ports up. I've only done PA-850s and it appears the 850s ha

...

MGMT interface routing questions

When I configure the mgmt interface on its own network and I use the PA for routing, do I need to setup a static route to access the HTTP interface from a different network? Or does a service route take care of this automatically?

 

I have an HA active

...

Restrict Access to WAN Network PANOS9.0.x

Hi,

 

We're looking to restrict access to our network in AWS on the other side of an S2S VPN. From the research i've done it looks like i can set up restrictions on the tunnel using User-ID and Captive Portal. https://docs.paloaltonetworks.com/pan-os/9

...

MP2021 by L1 Bithead
  • 1748 Views
  • 2 replies
  • 0 Likes

PANOS 10.0.6

Hello, team One of my client want to know the stable version of PANOS there current one is 9.1.5 I suggested them with min apps threat Global protect user-id version and suggest the PANOS 10.0.6 After that the client send me the issue below. The PANO

...

Office 365 URL Filter

Hi,

 

New to Palo Alto so might be an easy solution. Im trying to set up URL filtering to allow Office 365. Ive test the object and policy with other websites such as bbc.co.uk and sky.com so i know my policy works, however, when i add the office 365 U

...

Resolved! Block android devices and iphones

Hello Guys,

                I have been through process of blocking a group of devices in VPN and gateway side.

I could block the windows devices usin the Machine-GUID but still unlucky in blocking phones "Android and iphones"

regarding the ANdroid phon

...

  • 24127 Posts
  • 100 Subscriptions
Top Solution Authors
Labels