General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 241 Views
  • 0 replies
  • 0 Likes

virtual routers

How can you tell if a virtual router is passing traffic? Is there a check or test you can run?

jdprovine by L4 Transporter
  • 3258 Views
  • 5 replies
  • 0 Likes

WMI probing issue - "list is full"

Hi all,

 

is anyone familiar with this issue? We are facing this currently but Google almost spits out nothing about this issue. I was going through the User-ID deployment and troubleshooting guide but nothing helpful there. Any ideas?

 

 

 

wmi.png
Rboehme by L2 Linker
  • 3111 Views
  • 2 replies
  • 0 Likes

Resolved! Decryption of SMTP using STARTTLS

Our current setup with Exchange uses SMTP with STARTTLS.  We have a requirement from the business to try and decrypt/inspect the traffic.  I configured decryption policy the same way as we do for our SSL web servers, but it doesn't seem to be working

...

Strange SNMP Trap from PA500

Hello

 

During last 7 days I got twice trap like this:

Otrzymano pułapkę SNMP (notyfikacja: 1.3.6.1.4.1.25461.2.1.3.2.0.1) 1.3.6.1.2.1.1.3.0 = 473590626 1.3.6.1.6.3.1.1.4.1.0 = 1.3.6.1.4.1.25461.2.1.3.2.0.1 1.3.6.1.4.1.25461.2.1.3.2.0.1 = 1,2016/10/10 1

...

_slv_ by L4 Transporter
  • 1604 Views
  • 2 replies
  • 0 Likes

Firewall policy for a web server with two websites

Hi Community,
I am new to this forum and also not an exprienced person on firewall policies. So I thought to put my question on the forum. This is what I try to achieve, I have a group of web servers with one virtual IP serving two websites (HTTPS). E

...

Resolved! Add locally managed FW to Panorama

Hello everyone,

 

I want to add clusters of locally managed FW to Panorama without modifying any local policies and objects. Can I do so and add them to a device group in the future?

 

Thanks,

SSL Interception and CDNs

Looking for your guy's feedback on potential issues you've seen with SSL Interception and CDNs?  I know there's a potential for thick clients like Dropbox to break if you crack SSL for the domains used there.  Are there any other concerns to keep in

...

Withdraw mesage source

Hi everyone,

 

I am currently working on connecting MineMeld with our SIEM solution. I however ran into a question.

 

When receiving an update message it states which sources the IOC originated from, also if there are multiple. example: (binarydefense an

...

Forseti by L1 Bithead
  • 3315 Views
  • 2 replies
  • 0 Likes

Resolved! Globalprotect 3.1.1 compatibility with PAN-OS 6.1.12

From the release notes for Globalprotect agent 3.1.1:

 

Minimum supported version

PAN‐OS 6.1 and later releases for GlobalProtect gateways
PAN‐OS 7.1 for GlobalProtect portals

 

We're on PAN-OS 6.1.12 and have portal and gateway on the same device. Does th

...

dieter_b by L4 Transporter
  • 3815 Views
  • 3 replies
  • 0 Likes

Resolved! Vulnerabilities detected during scan

Hi all, 

 

I ran a vulnerability scan on my Palo Alto this afternoon, and I am receiving the following vulnerability:

 

 

 

I am a little confused as to why I am receiving it since I have one TLS/SSL Service Profile (using TLSv1.2 strictly) that is setup t

...

Screen Shot 2016-10-11 at 6.56.17 PM.png
mmclimans by L3 Networker
  • 2280 Views
  • 1 replies
  • 0 Likes

PA-200 and ARP

I have a duplicate arp entry in a PA-200 I cannot get rid of. I have no clue where it is coming from. Its not HA just a standalone 200 on a single /24. I have looked at every device on the network and I cant figure it out. Any suggestions?

Replacement PA-500

Does anyone know where I can buy a replacement PA-500? I have one that failed on Saturday (won't power on) and PA Support is dragging its feet on approving a replacement. They said:

 

I have submitted the RMA request and you are entitled to next busine

...

Cramer by L1 Bithead
  • 3818 Views
  • 6 replies
  • 0 Likes

Resolved! ECMP link monitor 7.1.4

We had an issue with our secondary ISP last night that ECMP didn't handle passing all traffic to the promary ISP as the interface was still up.Does anyone have a suggestion on how to monitor the ISPs and down the link that is having issues? Current c

...

nwetech by L1 Bithead
  • 3044 Views
  • 3 replies
  • 0 Likes
  • 23625 Posts
  • 107 Subscriptions
Labels