General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

url-filtering


Hi,

In url filtering adult-and-pornography blocked . But la-xxx.com can accesible
xxx.com not blocked

 

1)
test url la-xxx.com

la-xxx.com adult-and-pornography (Dynamic db)

2)
test url xxx.com

xxx.com adult-and-pornography (Base db)


other info
----------

show ur

...

sib2017 by L4 Transporter
  • 3955 Views
  • 8 replies
  • 0 Likes

Two L3 interfaces on One Zone

 

 

 Hi,

 

 

in the setup of the above diagram , I need to run OSPF on Paloalto between two Core-SWs, so I have to create two L3 interfaces  Point to Point with the two SWs.

 

the two core-SW is considered as inside for me , so from the prespective of routi

...

Question.jpg

Resolved! Create threat signature

Hi Guys,

 

I need to know if I can create a threat signature in case I've only the malware hash.

 

Is it possible to do on PA?

 

If not, Is there any other way I can block malwares based on hashes only?

 

Regards,

Sharief

Syslog Miner different confidence values.

Is there the way to separate traffic and threat logs from syslog miner to be directed to diferent outputs based on confidence. What i mean is something like that in rules:

conditions:
  - type == 'THREAT'
fields:
  - misc
  - url_idx
indicators:
  - src_tra

...

Shadosan by L0 Member
  • 2337 Views
  • 0 replies
  • 0 Likes

Troubleshooting ipsec tunnel setup.

I have setup ipsec between PA200 and cisco device. When trying to bring tunnel up not even able to establish phase1.

Getting following errors in logs. I have keyed in pre-shared key again on both the sides.

 

ikev2-nego-child-start:'IKEv2 child SA negot

...

GlobalProtect client upgrade "Prompt" file location?

We are using the GlobalProtect Agent Upgrade Process "prompt" method to upgrade our users GP client. We are having issues with our last version upgrade to GP 3.1.1 on all of our PAN firewalls, where some of our clients get this message - "The program

...

Resolved! PA drops traffic apparently without NO REASON

Hi All,

 

I have PA 2050 with panOS version --> 7.0.9

I have two rules:

Rule 4 --> Permit for svc-casse application as (ssl, ms-updated ecc)

Rule 5 --> Cleanup for svc-casse

 

That's the situation check :

RULESLOG

 

Really really strange behavior I never seen

...

Rule_INVOLVED.JPG
LOG_DROP_Without_no_reason.JPG
SSL_Allow_random.JPG

PA drops traffic apparently without NO REASON

Hi All,

 

I have PA 2050 with panOS version --> 7.0.9

I have two rules:

Rule 4 --> Permit for svc-casse application as (ssl, ms-updated ecc)

Rule 5 --> Cleanup for svc-casse

 

That's the situation check :

RULESLOG

 

Really really strange behavior I never seen

...

Rule_INVOLVED.JPG
LOG_DROP_Without_no_reason.JPG
SSL_Allow_random.JPG

Resolved! PA5050 | temperature sensor | how to disable false alarm

Hi all,

 

could it be that somebody know:
we have a problem with a temperature sensor on our PA5050 device

S1 Temperature @ 10G Phys [U171] False 17.40 5.00 60.00

Time to time we see temperature 0!!! [screen 1] and it triggers a temper

...

pa5050temp.png
IHEP by L1 Bithead
  • 5295 Views
  • 8 replies
  • 0 Likes

Application Filtering and Basic Setup

Hi All,

 

I would like to ask the FF.

 

1. I want to use Application filtering but permits web browsing.

         - Enabled App filtering, Permit Web-browsing, SSL and DNS but I can't browse and launch any website. Any idea how to permit only browsing on

...

  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels