General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4453 Views
  • 0 replies
  • 0 Likes

AOL Mail

Hello,Has anyone been experiencing any issues with using AOL Mail through a PAN device since last week? I'm assuming AOL changed the behavior of their webmail site and now sections of the portal are not available - such as the inbox. Errors also pop up saying "we have encountered difficulties". However, outside the PAN device, the portal loads...

MGoodnow by L4 Transporter
  • 266314 Views
  • 15 replies
  • 0 Likes

SYSLOG Issue after upgrade

Hi Team, I just upgraded my PaloAlto to 11.1.3. after upgrade we faced issue that syslog receied delay log. "debug log-receiver statistics" Logging statistics------------------------------ -----------Log incoming rate: 448/secLog written rate: 467/secCorrupted packets: 0Corrupted HTTP HDR packets: 0Corrupted HTTP HDR Insert packets: 0Co...

What encryption is my SSL connection using?

We're on 9.0.9 and want to turn on the feature allowing users to connect to GlobalProtect using SSL if there is a need. Is there anywhere in the Monitor tab you can look to find what encryption is used for a particular users connection? I read this where it says, "The gateway responds to the request and selects the encryption and authentication ...

What's the difference between custom URL filtering in security policy and in URL filtering Security Profile?

Hello, Guys, I have one question.First below is the packet flow from "Packet Flow.pdf" document. According to this document ...In the red square, before PA make session table, it checks packet's ip and port (like the legacy L4 firewall), and then after the session created, it check Content, APP-ID.So I made this rule(URL Block).According to pack...

JTR by Not applicable
  • 15171 Views
  • 9 replies
  • 0 Likes

FQDN security policy

Our internal servers connects to a server on internet . There are existing FQDN based security policies. The destination FQDN resolves into multiple ip addresses . I am seeing few allows and denies for that particular destination URL on paloalto traffic logs . Users facing intermittent issues . It seems like firewall is querying for that destina...

P.Gandla by L0 Member
  • 2382 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot connect to management server

Dear All:I had meet this problem for three times ,and It comes again , I can ping the Management port with a low delay , but can not login through the httpsand can login from SSH, but without any cli , I can't typing . and always"Oct 30 12:21:13 Error: pan_read_full(comm_utils.c:97): srvr: fatal recv error. sock=3 err=Connection reset by peer (1...

j.guo by L1 Bithead
  • 38432 Views
  • 12 replies
  • 0 Likes

Resolved! Palo Alto Security Profiles Suggestions

I am seeing that we have different Palo Alto provided Security Profiles that we can map to the security policy. What would best strategy to test it first in lower environments before rolling onto prod ? We just want to make sure it should not create any problems to existing traffic. Right now, we are not using for each security policy. But w...

"Device > Server Profiles > HTTP" gives error: Connection to: https://b76093c3662d5b4f.hook.limacharlie.io:443 failed: Couldn't resolve host name

Hi Palo Alto guys, I want to send traffic using HTTPS to LimaCharlie. I want to start by saying that I managed to get it working using CURL with the following command: curl --location 'https://b76093c3662d5b4f.hook.limacharlie.io/d61f357d-7e3e-42d7-a445-8ff62a479a4c/dev-fw-pa440-http' \ --header 'lc-secret: test' \ --header 'content-type:...

curl.png
00http.png
01HTTP.png
03Payload format.png

7.1 Dataplane CPU Utilization

I'm curious how many people out there have had high dataplane CPU utilization ever since updating to 7.1? We updated to 7.1 so that we could decrypt additional ciphers and ever since updating we've had abnormally high dataplane CPU utilization which does not make any sense to me as we are nowhere near the stated maximum specifications on our 50...

Impact of Rack Server Placement on Palo Alto Networks Firewall Performance

Hi everyone, I’m currently setting up a new data center and am wondering about the impact that rack server placement might have on the performance of our Palo Alto Networks firewalls. We’re using a mix of physical and virtual firewalls, and I want to ensure that we’re optimizing their performance as much as possible. Specifically, I’m curiou...

Arbitrary commands issue on ansible

Hi; While Executing Arbitrary commands like (eg: show lacp aggregate-ethernet all, show chassis status ) via ansible playbook its not getting exact output as we getting in paloalto console output some attributes are missing, I am using the paloaltonetworks.panos.panos_op modules for generating the ansible report. Is the any other spe...

URL Filtering issue

Hi All, So i'm trying to whitelist a site that was tagged as 'parked' by PAN-OS. i added this to a custom URL category, and configured the URL Filtering profile to allow/allow. The site is still getting blocked. To get around this, i filed a request to reclassify the site(to be fair, the update was very quick). This concerns me, as a a lot...

Negating an Argument for XML API Query

I am essentially trying to query the XML API for the active firewall to grab out operational logs using the below query except I would like to NEGATE the application so that I am grabbing out the logs that do not include that application type. Right now as it is written below, I am grabbing out ONLY the logs with application type "example-applic...

Palo Alto and Aruba Clearpass integration

Can someone please point me in the direction of any documentation for integrating PA firewalls with Aruba Clearpass. Understand Clearpass has a direct path into the API without the need for any programming?

jlucking by L0 Member
  • 24199 Views
  • 9 replies
  • 1 Likes
  • 24376 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels