General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4247 Views
  • 0 replies
  • 0 Likes

Using AWS Bundle 2 as an Ironport replacement

I have a Bundle 2 in trail at the moment as a POC. At first glance, the interface is overwhelming, so navigating it is cumbersome at first. What I am trying to accomplish is a viable replacement for Ironport WSA. I have a Bluecoat POC in place and it can replace the Ironport, as well as TMG for Citrix, two of our criteria. My goal is to proof...

ACD-II by L1 Bithead
  • 2463 Views
  • 2 replies
  • 0 Likes

Weird Malware URL Reporting

Has anybody else noticed that their botnet report is triggering on weird URLs that couldn't actually exist. I've listed some examples but I can't figure out why some of the URLs being reported are so clearly 'wrong'. Visited malware URL 8M{zy!ces{~yeo{au?qfg.>Kcf~%7fwze%7fm%20}crzfeg!~znbe?mk%7fi%20}%7feca$lbkez|5#T82<:59<#%207;L-`bm2x...

BPry by Cyber Elite
  • 5269 Views
  • 9 replies
  • 0 Likes

Resolved! Block vs block ip

Hello all, what is difference between Block and Block ip ? Block for this current packet only ? Block ip for specific ip for certain time is it correct ? so Block IP is better

TeamViewer restrict unsupervised access

Hey everyone, i got a question from one of our customers, described below:Constellation:PC1 (At home, with internet-access) <--> PA-firewall <--> PC2 (at office, TeamViewer-controllable) Now, to the question. The costumer wants to restrict the access on PC2, so that PC1 can only connect when PC2 explicitely granted access (from a...

Weird routing problem from mgmt interface. Icmp-redirects? If so, how to turn it off?

I have a problem on a PA500. When it attempts to send traffic to one particular subnet via the management interface, the packets are sent to the wrong place. Instead of going to the default gateway, they go to an ASA. All other subnets route correctly. The PA500 has a very simple config. The management interface is connected directly to a switch...

Resolved! HA sessions synchronization initiated by or to the Active.

Hi Guys, Got a random question regarding the sessions synchronisation when running HA :0 If l understood correctly only the sessions that are not initiated by the Active device will be synchronised to the Passive device. Does it mean that all OSPF, BGP and l believe VPN tunnels will be re-established? So only traversing sessions are synchronise...

panorama server specifications

Hello all, can you please [provide me with panorma server specification to buy it this week .. what is implementaion method ? we must have esxi ? or windows server or what ? i`m new here

DHCP

We've used Palo alto as DHCP server for all our wireless infrastructure, we notice that after one hour the IP has to expire and be release, however it keep the expired session on the DHCP and we have to manually clear out this from cli. Once the pool is full no dhcp ip is released. Anyone does know the issue? Secondly can we automate the command...

Denis by L2 Linker
  • 4526 Views
  • 5 replies
  • 0 Likes

Block Facebook App

We are using a Palo Alto Firewall and have facebook blocked on the browser, but the mobile app still works on Android and iPhone. What is the catch all way to block the facebook app?

External Dynamic Lists requires "google-app-engine" ??

Greetings On PAN-OS 7.1.8 configuring EDL is giving some unexpected results - I have an application based security policie set for my PA management IP addresses to fetch the updates i.e. "paloalto-updates, widlfire, pan-db-cloud, ssl and web-browsing" with service set to application default. No profile actions set to block. After populating the...

Resolved! How to generate SNMP Trap from CLI/GUI?

Hello I'm on 7.1.7 PANOS and I need to generate traps for testing purposes. I didn't find in manual such CLI command. please advice me how to generate from CLI or if it's not possible how to make a workaround (ie. using trap on virus condition or so) With regardsSLawek

_slv_ by L4 Transporter
  • 10486 Views
  • 2 replies
  • 0 Likes

Resolved! Exfiltration detection?

Has anyone set up a PAN alert for egress bandwidth utilization? For example: If any internal host transfers more than (x) GB in (y) Minutes to the Internet - throw an alert.

Can not access to Web Admin GUI on Active Device Paloalto, can access to Standby device in HA System

Hi All, I have met a problem with access to my Active Pan Device by Web Admin GUI.I can access by SSH Console and I can access to Standby Device in HA System.My device: PAN 3020, OS Version 6.1.4. Have anyone meet the same problem, please share the solutions. Error logs---------------------2017-03-21 11:04:21.009 +0700 Error: pan_authd_user_is_l...

Problem wildfire submission logs missed sender/recipient address

Hi alli have this little issue: I have panorama with a pa 5050 cluster firewall 7.1.5 with wildfire licence. I have a rule to control smtp traffic with a wildfire profile.In the wildfire i have disable benign responce and in the configuration i have selected this: The problem is that i don't see anymore, after a malicous responce, the recipent/s...

Wildefire sub.JPG
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels