Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

About Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

Discussions

Can't import policy from firewall to Panorama using panxapi

I've already imported all objects successfully with panxapi (part of PAN-Perl), and have manually created all zones referenced in security policy. But for some reason I keep getting error code 12 when I try to import policy. I've tried the xpath syntax from the Panorama-Device-Migration guide and also variations on the xpath based off what I see...

kmurphy by L3 Networker
  • 4685 Views
  • 4 replies
  • 0 Likes

Custom APPid based on user login

I am working with a client in an interesting situation..We are basically needing to limit sections of the network where certain users and login to a web server. For example, only admins can login from zone1 and only users can login from zone2. The application on the web server is not a custom one built by the client but there is no current ID fo...

SDorsey by L4 Transporter
  • 1980 Views
  • 0 replies
  • 0 Likes

Want to allow specific YouTube videos and block all other content

Hello,I am trying to block all YouTube content with the exception of the company videos that we post. I had this working at one point, but then it stopped working and now all content is being allowed. I can't block it now unless I can only allow the company videos. Associated ticket is 148560.

Change custom report parameter via a REST API call

All,I use a customise report in order to query all threats related to one particular IP over a specific timeframe (e.g. 7 days, 30 days, etc.). The report is fairly basic and list the threat names, source and destination IP and also the severity.Is there a way to change the IP address parameter in the report using the REST API? Obviously I'm not...

SGaniere by L0 Member
  • 1783 Views
  • 0 replies
  • 0 Likes

Resolved! tcpdump: no such file or directory

Hi all,I have some problems with the tcpdump command/option.When I start an tcpdump at the GUI nothing will happen. I didn't see any pcap files being created.When I stop de capture and start an new capture via the CLI, I still didn't see any files being created.When I use the command "debug dataplane packet-diag show setting" I see the capture i...

ppater by Not applicable
  • 8754 Views
  • 2 replies
  • 0 Likes

custom report

I am trying to make a custom report that will give me a weekly overview of the total usage ( in time ) of the Global protect Client per user. Is this possible and does anyone have an example.greetings

Is it possible to create custom App-ID objects that call out to custom-developed code for signature recognition?

We have a PAN 2020 in our lab which we are using to explore recognition, detection, and selective authorization of obscure, legacy application protocols that are not natively supported by the PAN 2020. We have successfully created custom App-ID objects that recognize some of our application protocols using the built-in regular expression support...

IATDlab by Not applicable
  • 1884 Views
  • 0 replies
  • 0 Likes

Zabbix template

HiI sow topic with Cacti templates for PA devices.Could someone share a template for Zabbix?With regardsSLawek

_slv_ by L4 Transporter
  • 9214 Views
  • 5 replies
  • 0 Likes

Highest Risk User

The highest risk user on the predefined report doesn't have additional information under the URL Categories/Applications/Threats?What are the details of an IP address becoming the "Highest Risk User"?

API user login error

I am trying to get user id information from our Aerohive wireless to our PA-3020 (5.0.4 OS) device. I am using a custom agent that gets snmp traps from our aerhive AP's for the user infor and then forwards them to the PA through the api. I created a user on our firewall and gave it full admin rights (just for testing). I got the API key for the ...

bberes by L0 Member
  • 1820 Views
  • 0 replies
  • 0 Likes

pan-python - How to add an address group to a policy

I would like to add/change the destination address group in a policy. xpath=/config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='testDG']/pre-rulebase/security/rules/entry[@name='Allow_FTP']/destinationelement=<destination><member>test_addr</member></destination>Can you please show me how to ach...

ksomu by L4 Transporter
  • 2744 Views
  • 1 replies
  • 0 Likes

HTTP application override

I need a method to allow all HTTP traffic from a group of source addresses to any destination, regardless of port or other application definition. I thought of using the application override with a custom applicaiton but not sure how to write the custom app to identify only HTTP. Would I use the custom app parent app of with a predefined app o...

MarioR by Not applicable
  • 2791 Views
  • 3 replies
  • 0 Likes

PAN-0S 4.1 Cacti template host template

Hello,i have updated this cacti template:https://live.paloaltonetworks.com/message/13477#13477to be able to graph in the right way the PA-50XX firewalls running PAN-OS 4.1 witch cacti.This host template monitor this variables:Traffic the firewall is passing through each selected interface(s)Data Plane cpu usageControl Plane cpu usageThe number o...

Colt by L1 Bithead
  • 7712 Views
  • 4 replies
  • 0 Likes
  • 1031 Posts
  • 68 Subscriptions