Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

About Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

Discussions

Current method for requesting Application updates?

Hi there, So far, I haven't been able to find the correct method to submit packet captures to Palo Alto Networks for unknown applications. In my case, I'd like to post some captures for updates to the Bloomberg Professional software, but the email address for pro services doesn't accept inbound email from my address.Any pointers?Thanks all,Elvis

Query Palo Alto Firewall PA-5020 using Firemon

Hi I am working on integrating Firemon with Palo Alto and need to query the Palo Alto for zones. Here's what I am trying to do. Problem statement: I want to write a query that would give me the list of firewall rules with ("any" in "Destination zone" AND "Service" AND "Action" = accept ). I am able to generate a query that will give me ("any" in...

Custom APP-ID for SMTP traffic

I have a request to forward all incoming emails attachments to Wildfire cloud, but not for all users. we need to exclude some users. I think this can be achieved with custom SMTP application to match destination email address.

How to search for rules with Security Profiles?

I have a pair of Palo Alto firewalls containing 1500+ rules and running PAN-OS 4.1.9. Both firewalls are running in HA and are managed by Panorama. Some of those rules are having Security Profiles configured and the majority doesn't. Is there a way to search for those rules either from WebUI or CLI without having to go through each and every rule ?

Custom APP-ID

I have deployed a new application on our network and found that this application has some communications that take place on TCP-2000. Noramlly this port is used by cisco-sccp. The data that is being passed is not a normal "cisco-sccp" protocal traffic, and thus my PA-400 is not permitting the traffic to pass through it. I have started writting a...

Deploy custom signature using XML API

I'm trying to deploy custom signatures using the XML API which gives me the following error:<response status="error" code="12"><msg><line>Object cannot be overridden</line></msg></response>This was after I was trying to use action=set which gave the error below which, as specified in the documentation suggeste...

secode by L0 Member
  • 3224 Views
  • 1 replies
  • 0 Likes

Resolved! Adding time attribute to custom vulnerability signature

I have created several custom vulnerability signatures so I am familiar with the general process. I want to create a custom vuln signature based on a string but I also want to add a time signature to time attribute to that signature since it will triggering rather frequently.Unfortunately, it appears that I can only add a time attribute combina...

rsn772 by L0 Member
  • 3399 Views
  • 2 replies
  • 0 Likes

Chromebooks

We are a school district with a growing number of Chromebooks. We are having problems identifying what student is on the Chromebook. We have a work around right now (Captive Portal), but it relies on the student shutting down the Chromebook when they are done using it. If the student does not shut it down that next student would be still usin...

USER-ID Settings: Why is the "User Identification Timeout" a global setting

Hi,i use a syslog collector to receive ip-user-mappings from an Juniper Secure Access Gateway.It works quite fine, i created a custom syslog filter on my paloalto and created the correspondig Server Monitor entry for my Juniper Systems.a simple "show user server-monitor state all" on the commandline shows that the collector receives the correspo...

ottench by L0 Member
  • 4481 Views
  • 2 replies
  • 0 Likes

Unexpected behavior when deleting address-group member using XML API

Hello.We are using XML API to create or delete address and address-group.When I deleted address-group member using XML API, address-group member was deleted even if there is another member. (It had just one address member)As you know, we can't delete address-group member if it has just one members at Web-ui.And commit was successful.So all traff...

ssh1105 by L0 Member
  • 1738 Views
  • 0 replies
  • 0 Likes

When will the msrdp AppID be udpated for UDP 3389?

Hi:MS RDP v8.0+ (comes with Windows 8 & Server 2012) uses UDP 3389 for RDP in addition to TCP. Furthermore, it also tries UDP first (this may be with v8.1 - can't remember).I know I can workaround it - I just want to know when will the AppID itself be updated.I opened a ticket but support told me to post it here as they didn't know.

rest API rule modification with Panorama

Hello, and thanks for whatever help you can provide.I am trying to create a script that will modify one rule from enable to disable and back again via wget. I created a admin user on the panorama box, created a hash based on that user and password. when I run the script I get the following:<response status="error" code="13"><msg><...

DChampine by Not applicable
  • 2988 Views
  • 0 replies
  • 1 Likes

App-Id for Oracle PLM / Weblogic

Hi there,I have a prospect who wants to isolate his critical Oracle PLM / WebLogic application from the rest of the network.Are these applications recognized by Palo Alto Networks?If not, what are my options to create rules that only authorize these two apps / traffic?ThanksGauthier

Gauthier by L0 Member
  • 2545 Views
  • 1 replies
  • 0 Likes

Zarafa App-ID

Hi all,Is there an App-ID for the Open Source Groupware application Zarafa? We got a customer request for this application to be identified by App-ID.Thanks

  • 1031 Posts
  • 68 Subscriptions