General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 305 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3649 Views
  • 2 replies
  • 14 Likes

Ping log with 0 bytes sent

Hi Guys,

 

I noticed some strange logs on one of our 5200 firewalls.

There is device behind the firewall that is running constant ping to google dns, traffic is allowed and working normally.

I noticed a some logs that bytes sent is zero... I can explain

...

AlexanderAstardzhiev_0-1623937334598.png
AlexanderAstardzhiev_1-1623937505092.png

Deny PSiphon

Black Psiphon

Dear All, Psiphon was blocked for a long time but this week, we detect it has been working again. i have tried to block it again but without any result, it was blocked for 2 hours and working again after that. I have been checking the tr

...

User-ID Connection Security Won't Work

UserID Agent version 9.0.5-8
Firewall 9.0.8

Windows Server 2016 UserID Agent Servers x2

 

I've tried following this guide and numerous others (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGFCA0)

 

Keep getting 'Failed to vali

...

TylerHay by L0 Member
  • 12145 Views
  • 5 replies
  • 0 Likes

Query on MineMeld setup for Azure Sentinel

We would like to add a miner to input nodes in our Minemeld portal.

And we followed the below article to setup as per our requirement but we couldn’t see the “git” icon to add the extensions.

https://live.paloaltonetworks.com/t5/minemeld-articles/send-

...

Multicast, who accessed??

I have tested multicast to be working and is configured as in this diagram. In the logs I see traffic from SERVER zone to Multicast zone. But there is no log on INTERNAL client that accessed the multicast stream.

 

image.png
raji_toor by L4 Transporter
  • 2372 Views
  • 5 replies
  • 0 Likes

Resolved! New install of Minemeld: Timeout errors

I've been beating my head against the wall over the past week trying to get an instance of Minemeld to work on both Ubuntu Server 16.04 as well as within a Docker container running on Ubuntu Server 20.04 LTS.

 

I've followed the below guides verbatim

...

Cisco CAPWAP AP stuck in Discovery

Hi All,

 

Has anyone had problems with CAPWAP AP's separated from the WLC by a PA-220 firewall get stuck in a DISCOVERY OperationState?

 

>show capwap client rcb
AdminState : ADMIN_ENABLED
OperationState : DISCOVERY
Name : ***
SwVer : 8.5.151.0
HwVer : 1.0.0.

...

KevinJB by L1 Bithead
  • 7292 Views
  • 6 replies
  • 0 Likes

NPTv6 seems bugged (PAN-OS 9.1.9)

Hi,

we're running into an issue with IPv6 NPTv6 which we use to route traffic through IPS on PA.

The address isn't translated as expected.

We tried NPTv6 in 2 configurations, both translate the same. We either used:

xxxx:xxxx:xxxx:ffe0::/60 -> xxxx:xxxx:

...

Freaky by L0 Member
  • 1921 Views
  • 3 replies
  • 0 Likes

Knowledge sharing: Palo Alto checking for drops (rejects ,discards), slowness (latency) and counters using captures, global counters, flow basic etc.

Hello To All,

 

 

I will create a short summary about how to do basic checks if the palo alto drops or slows down the traffic.

 

 

1. First the pcap capture on the drop stage will show if the firewall drops the traffic and after that we check why the firew

...

NikolayDimitrov_0-1619596411072.png

HIP check report interval

1. What is the interval for HIP reports that the GP client sends to the gateway? 

2. Is it configurable?

3. What triggers HIP report sending?

ET by L2 Linker
  • 15568 Views
  • 5 replies
  • 0 Likes
  • 24184 Posts
  • 100 Subscriptions
Top Liked Authors
Labels