General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

URL marled as category "ANY"

Hello, My customer has a PA-500 with URL filtering, since we have attach an url profile to security rules all websites are blocked with category "ANY".Furthmore, no logs in "url filtering". Someone has already face this issue ?Thanks for your help.

Capture.JPG

Looking for a way to allow an application without allowing all dependencies with no commit warnings

Issue background:We have a policy for Application Whitelist of allowed applications on the internet firewall. SourceForge-Base is one of these applications. SourceForge-Base had dependencies on SSL, Web-Browsing, and SSH. We allow SSL and Web-Browsing, but do not wish to allow SSH to the entire outbound internet. Our users traffic works fine...

Resolved! 7.1.2 Unable to reach GlobalProtect portal

Hey guys, I am trying to get the GlobalProtect piece of the FW to work, I followed word for word from the 7.1 admin guide and still no luck. When I go to monitor I see the source coming from the external-untrust zone (which is correct), but the to zone shows (internal - trust). If I am reading this doc correctly, the VPN should terminate on the...

Capture1.PNG
Capture2.PNG

Virtual Wire with Response Pages

From what I can tell, it isn't possible to set a Management Profile on a virtual wire? We wanted to take advantage of a response page for URL filtering but cannot seem to do so due to virtual wire. Thanks,

greeng by L2 Linker
  • 2795 Views
  • 2 replies
  • 0 Likes

Brightcloud URL filtering database download error

Hi all! I have a problem with the download of brightcloud URL filtering database. When i try to download the DB this message is shown:----------------------------------------------------------------------------------------------Download Status2017-02-06 01:05:21.733 +0100 Error downloading latest URL database-------------------------------------...

DKanta by L2 Linker
  • 3710 Views
  • 3 replies
  • 0 Likes

Resolved! EDL file empty?

We installed Minemeld on Ubuntu 14.04 as documented and it's mostly working, except that from time to time the output lists are empty and PAN-OS Monitor>System complains: medium::EDL(DSHIELD20) Downloaded file is either not a text file or empty file. Using old copy for refresh. It's an unpredictable behavior and the EDL file comes back after ...

Testing TAXII output using Postman.

Hi Minemeld Team, i have try using the below postman collection link and import to my postman. the output is shown in the attachment. like to know the output is exactly what i should see or i am doing it wrongly? please advise. https://gist.github.com/jtschichold/65ee13d29038f78e220d75e6668eeea1 Thanks Darren koh

dkoh by L2 Linker
  • 6124 Views
  • 1 replies
  • 0 Likes

PAN 6.1: Filtering inbound traffic layer 7

If I expose a server to the Internet, can I limit traffic at the PAN so that only a specific path can be reached? Say permit www.hoho.com/foo.html but deny www.hoho.com/fa.html or any other path?

palomed by L3 Networker
  • 2324 Views
  • 1 replies
  • 0 Likes

GlobalProtect on IOS - Automatically reconnect after the connection drops

The GlobalProtect IOS 10 app works great when stationary but I am using it in a mobile environment (on emergency vehicles to access 911 call information). Sometimes our internet connection drops while driving which causes the VPN to disconnect. Is there a way to configure the app or IOS to reconnect the VPN automatically when the internet connec...

TonyRC65 by L0 Member
  • 2078 Views
  • 1 replies
  • 0 Likes

Are wildcards also supportet in the UIA "exclude _user" List?

Hi, Version 7.1In the Agentless solution we have the nice Feature we can use to exclude Service-User from the User-ID by Username with "wildcards" completion.Can we enter in the exclude user List in the UIA also the user we want exclude with this wildcard Syntax?This would improve and simplify configuration very much.customer reportet this would...

rkuhn by L0 Member
  • 1950 Views
  • 1 replies
  • 0 Likes

Geoblocking Exceptions

Is it possible to configure ip exceptions for gel block regions ? For example, could the public ip for a company be whitelisted within a geo blocked region ? Thanks. Mike

DekiM by L0 Member
  • 4709 Views
  • 1 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels