General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Unused rules

I know it is possible to get unused rules since last reboot, but it is obvious the data is in Panorama. Is there no way to get a list of rules not used since a specified date? https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Identify-Unused-Policies-on-a-Palo-Alto-Networks-Device/ta-p/53202

SSaady by L0 Member
  • 5004 Views
  • 4 replies
  • 1 Likes

Resolved! Cannot ping connected adsl modem.

Hi all, i've connected a adsl modem to our 3020 to redirect some clients to, configured the interface as dhcp client, the port successfully gets an ip address from the modem but i can not ping the modem interface from firewall's cli. I might be missing a simple step but i'm fairly new with PA, any help appreciated, thank you

pa2.png
pa1.png
pa5.png
pa6.png
Oseberg by L1 Bithead
  • 9810 Views
  • 8 replies
  • 0 Likes

Resolved! Line Messenger APP

Hi All, Do we have an application for Line Messenger: https://line.me/en/ Cannot see it in Palo database. Thx,Myky

How to block TCP22 connections

Hi everybody I like to know if there is a way to block incoming connections attemps to port TCP 22. I have an end-customer which has lots of connections to his public ip range 0.0.0.0/24 to port TCP22 but not hit the vulnerability 40015 (SSH User Authentication Brute-force Attempt) because it neves triggers the child signature 31914 (SSH2 Login ...

SOC_CSG by L4 Transporter
  • 4389 Views
  • 4 replies
  • 0 Likes

what exactly is tcp-reuse and does it sends session closure traffic to the client and server?

heyhey we have some problem with old system that are beeign stuck after some tome it is working and on the logs we see the session end reason is "tcp-reuse" my questions are:1) what should be happaning on the network flow for this end-reason log to apear2) will the FW generate some traffic to the client and server to "close" their existing conne...

minow by L4 Transporter
  • 26299 Views
  • 1 replies
  • 0 Likes

Resolved! How to submit a CSR to Microsoft CA?

Hello folks! I have seen a few articles and documentation for generating CSR and submitting to Microsoft CA for subordinates. What about just a root stand alone enterprise Microsoft CA? I am preparing to configure a Global Protect portal, generated/exported my CSR, pasted into the Microsoft CA interface, but unclear of what option settings to s...

microsoftCA_1.jpg
OMatlock by L4 Transporter
  • 2525 Views
  • 1 replies
  • 0 Likes

Research paper shows vulnerabilities with SSL interception

On Feb 2017, some universities, Mozilla, Cloudflare, and Google released this paper on corporate and desktop HTTPS interception. First they figured out how to identify when someone connects to a web server through an SSL interception appliance. Then they found that most corporate "man-in-the-middle' appliances expose security vulnuerabilities. B...

Maxstr by L3 Networker
  • 4911 Views
  • 5 replies
  • 0 Likes

CLI debug pcap verbosity levels

I've been using the cli debug pcap captures for a number of issues recently but was frustrated in the last one by a lack of detail. In this case I was capturing OSPF (debug routing pcap ospf on). When I viewed the capture it looks more like a summary of the hello messages without the contents. Is there a generic was to turn up the level of infor...

JWileyR by L1 Bithead
  • 3028 Views
  • 1 replies
  • 0 Likes

Resolved! IPS best practise

Hello all, I configured my security profiles with default seetings .. Is ther any refrence for best practise for IPS and wildfire ??

Miner Data Priorities

Is there a way to have MineMeld prioritize miner data once they get to the output stage? Since some output feeds may be too large for certain firewalls, I want to ensure that our static blacklist is always at the top of the list. Currently new additions that don't overlap space with other miner data seem to show up at the bottom of the list caus...

groehl by L0 Member
  • 3071 Views
  • 1 replies
  • 0 Likes

How to configure Syslog to send a CEF in PAN OS 7.1.3

I had found this article for CEF on PAN OS 6.0.0https://live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-6-0-CEF-Configuration-Guide/ta-p/59938 Do the same rules apply for PAN OS 7.1.3? I would need to add "CEF:0|Palo Alto Networks|PAN-OS|7.1.3| before I add the attributes under my syslog server under custom tab? Would that then send t...

User-ID 8.0 - PKI Setup?

Anybody seen any specific directions on how to setup the new PKI enteprise certs in UA 8.0 beyond the fluffy "whats new" feature section. Also what is the different between UAinstall and UAcredinstall ... Release Notes are silent.

PeterT by L2 Linker
  • 4018 Views
  • 3 replies
  • 0 Likes

How to view Panorama related config applied locally on FW

Hi, When you locally export the config of a firewall managed by panorama, only local config statements are visible.would be very interesting to know how you see the whole configuration ( the one related to panorama and the one locally related ) directly from the Firewall CLI. Kind regards PierrickL

Resolved! VPN Site to Site traffic - ALLOWED even if there is defined A SPECIFIC proxy id

Hi All, First of all enviroment's specific:panOS 7.1.7PA 3050 The "strange behavior description": 1. VPN S2S between PA and third party vendor2. Usual configuration3. Proxy id:VTI: Tunnel.103Local: 10.48.0.0/13Remote: 10.64.22.176/28 4. Strange behavior --> Remote network 10.64.22.176/28 is able to reach 10.64.29.0/24 that is NOT defined as o...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels