General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4234 Views
  • 0 replies
  • 0 Likes

Resolved! FTP Protocol Injection Bypass Palo Alto Firewall

Hi About News SMTP over XXE attacks against Linux-based firewalls. - link (https://www.bleepingcomputer.com/news/security/java-and-python-contain-security-flaws-that-allow-attackers-to-bypass-firewalls/) How we can create custom signature or disable classic mode FTP in PANOS to protect from this Vulnerability . Thank you.

Resolved! User-ID. Is WMI really needed?

Hi all I have an end-customer who is using ServerMonitoring and User-Id agent at the same time. His AD has been audited by Microsoft and discovered that their performance is affected by thew WMI probbing. My questions is. If they remove all ServerMonitoring and kept only the User-Id Agent? Do they need the WMI configuration in both Firewall and ...

SOC_CSG by L4 Transporter
  • 5638 Views
  • 4 replies
  • 1 Likes

Resolved! HA scenario questions?

Hi folks, I am learning (self training at this point) about my company's two Palo Alto 3020 devices in our datacenter. We are currently only using one device for our routing, firewall, etc. I am tasked with eventually configuring the second one as HA and the switches below it as redundant. As I am continue in the self paced learning, I put to...

PA_HA.jpg
OMatlock by L4 Transporter
  • 4963 Views
  • 3 replies
  • 0 Likes

NAT question for stretched external IP and different internal IP

The setup is 2 data centers with 2 sets of PANs (5060). An AS is stretched between the 2 data centers /24 primary in each data center, so if one ISP fails /24 block will enter the other data center. Normally for just internet failures internal IP is preserved. When a data center outage occurs, internal IP are changed. How do you configure NA...

takhtar by L0 Member
  • 2553 Views
  • 3 replies
  • 0 Likes

New Minor Support

One of my customers wants to see new Minors for these feeds below. Is there anything planned? If so, what is the timeframe? Thanks! 1) Crowdstrike 2) CCIRC - I can see one for Australia named AusCERT. Anything for Canada?3) R-CISC – Retail Industry LG

Youtube streaming not blocking

We want to block youtube streaming via Palo Alto. We create the Custom URL Category "testing" and enter the site "*.youtube.com" (with quotation). We select the testing category in Decrpytion profile and Action "Decrpyt" and Type SSL Forwarding. We create the security policy src:any, destination:any and deny youtube-base. But still we can we vie...

Resolved! O365: No Indicators, Miner not working

Hi, we use Minemeld for grabbing the Microsoft Office 365 IP's and URL's. It run's on a VMWare Server, build with the "Full" .ova with Ubuntu & Minemeld. The installation works fine. After importing the config "office365-config.yml" no indicators are shown. I tried to import every single Miner with saving and restarting the engine. Thi...

Resolved! Single IP List

Just getting started with Minemeld - I noticed that even if a single IP feed is provided (e.g compromised IP list), the inboundfeedmc list still shows as an IP range, e.g 1.179.202.22-1.179.202.22It is possible to get jts a list of single IP addresses instead of an IP range?

calamari by L1 Bithead
  • 5947 Views
  • 5 replies
  • 0 Likes

Info: GlobalProtect VPN with iOS 10.2 and T-Mobile LTE network not working

T-Mobile appears to no longer be issuing IPv4 addresses on their LTE network for iPhones running iOS 10.2 and Carrier Profile 27.1. This caused GlobalProtect VPN on our iOS 10.2 phones with T-Mobile LTE to stop working. Summary of the testing - See attached screenshots:Platforms: Two iOS 10.2 iPhones - one on T-Mobile LTE and one on AT&T LT...

AT-T.PNG
t-mobile.PNG

Any way to remove the config/commit lock button in a custom admin role?

Hi all, I'm wanting to set up a "Monitoring and Reporting" only role on Panorama. I've gone throughe and disabled commit/validate as well as all of the tabs except Dashboard, ACC, and Monitor. The thing is I've noticed the commit/config lock button is still present and clickable. Is there any way to remove this on accounts I want to be read-on...

jsalmans by L4 Transporter
  • 2167 Views
  • 2 replies
  • 0 Likes

Resolved! Syslog Miner Prototype Age-out Policy Prevents Engine from Starting

We've been working on getting the syslog miner working to block IPs from the threat logs. However, we want them to stay on the block list for longer than the default 1 hour. From reading through the prototype customization documentation, I think I should be able to configure a prototype somethink like this: source_name: panos.syslog age_out: ...

mboehlke by L1 Bithead
  • 4698 Views
  • 3 replies
  • 0 Likes

Resolved! Debug TAC commmand

Hi I have a pair of lab boxes and looking to test the debug TAC -login and TAC-response commmands. My understanding ia usually TAC provided a password to unlock the data is it possible to get a test password for my company to use? We do not require TAC support but just looking around at different feature and what's there to view.

  • 24357 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels