General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 301 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3645 Views
  • 2 replies
  • 14 Likes

DHCP Relay source Interface

Hi all,

 

We're having some difficulties with DHCP Relay on PA 7.0.5.  Our setup looks like this:

 Client <-> L2 SW <-> PA <-> L3 SW <-> DHCP Server

 

We use a VLAN sub-interface on the PA as the default gateway for that subnet and I configured DHCP Relay

...

Question about application group and custom service group

Hi All, 

 

First off I appologize if this question has been answered before.

I have a question regarding the use of application groups and custom service groups in the same security policy. Can traffic identified in the application group use a non stand

...

jmathew by L1 Bithead
  • 1690 Views
  • 2 replies
  • 0 Likes

Warning on commit new config - anyone recognise the cause?

Folks.

 

I made a rule change this morning - first one in a while (fairly static environment of late) - and when committing, got the following warning

 

Error: Invalid id 6 for os WindowsUWP.(Module: useridd)

 

Anyone recognise this/know the cause/know wha

...

darren_g by L4 Transporter
  • 1608 Views
  • 1 replies
  • 0 Likes

Cannot enter "Maint" at boot via cli

All,

 

somehow I lost connection to my PA-200. Im trying to do a factory reset on it and I am not able to enter 'maint" during boot via console.  I am using putty .  When I try, it just keeps loading the kernal.  is there a way to pause to enter "maint

...

2016-10-07_14-46-38.jpg
BryanMay by L1 Bithead
  • 2530 Views
  • 2 replies
  • 0 Likes

PAN-OS 6.1.2 issue with threat updates

I'm looking to see if anyone else is having an issue with dynamic updates past the 596 threat update on a 3050 running 6.1.2.

 

Here is what we are seeing. A while ago the 596 threat update came out and we encountered an issue. This was a known issue b

...

Kadall by L0 Member
  • 1199 Views
  • 0 replies
  • 0 Likes

Resolved! PA-7050 LACP causing delay in fail-over times

We have an HA A/P PA-7050 cluster running 7.0.2 with QNPC (40G). The 40G links are bundled in AE1 with LACP enabled. We noticed during testing that LACP causes 8-10 ping loss during a fail-over event. With LACP disabled we have a 1 ping loss during f

...

lacp.jpg

U-Turn NAT with Port Address Translation in a DMZ

Hi Community,

 

I am configuring my first PA-200 and having a difficult time. I have a /27 external network and have the PA-200 seeing the internet properly. I have internet untrust zone setup as l3 on Int 1.1, and a DMZ setup as l3. The DMZ zone is on

...

DMZ Depiction PA-200.jpg

Resolved! Custom applications and application override

I'm looking to get a better understanding of how custom applications work in relation to application override policies vs security policies.

 

I have created a simple custom application with just a tpc port for an internal application. There appears to

...

Priority in PAN-QoS

Hi, 

 

When you are configuring QoS, it's possible to define more than one profile, and in this profile put 'til 8 Class defined. 

 

When you apply over the egress interface, it's possible to add this Class based over an source Subnet.

 

Here is my questio

...

nanukanu by L2 Linker
  • 3291 Views
  • 5 replies
  • 0 Likes

Resolved! PAN AD Useragent - Excluding users?

Hi.

Is it possible to exclude a specific user from the PAN agent configuration?

I know you can filter based on group - unfortunately, the user concerned, which is used for several automated processes, is also a member of AD groups which I can't exclude

...

dagibbs by L4 Transporter
  • 14380 Views
  • 29 replies
  • 0 Likes

Resolved! Wildfire verdict malicious and action alert

Hi all,

 

We have seen in Wildfire Submissions that all files identified as Malicious and Grayware the action is Alert. The Wildfire Profile is configures to forward to public cloud and Antivirus profile has reset-both in Wilfdire Action tab.

 

Is this a

...

image.png
COMIP by L2 Linker
  • 3850 Views
  • 3 replies
  • 0 Likes
  • 24183 Posts
  • 100 Subscriptions
Top Liked Authors
Labels