General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

ACC graphs misrepresent the start times and the amount of traffics got transfed

Hi, I have an session this morning that ran from 7:38 to 9:29. The traffic log shows it recevied 6.5GB data and sent 473MB in that session within that period of time. If I go to ACC and select 6 hours and filter by application, From this screenshot, I am under the impression (Under the User|Source|Destination IP Activity), that session happ...

Screen Shot 2017-02-24 at 10.11.15 AM.png
Screen Shot 2017-02-24 at 10.22.40 AM.png

Disable Hardware Offload

Hi All, Whats the purpose of "Disable Hardware Offload" in Palo Alto Firewall ? Any traffic that is offloaded to the field-programmable gate array (FPGA) offload processor is also excluded, unless you turn off hardware offload. Can anyone please explain this more simpler manner, which i cant underrstand the concept and where to apply this ? Than...

Usage of Security Policy in Palo Alto Firewall

hi All, I am bit confuse of the usage of rule no 2 and 3. Eventually they will deny the traffic. But which two benefits are gained from having both rule 2 and rule 3 presents? Any clarification please.A. A report can be created that identifies unclassified traffic on the network.B. Different security profiles can be applied to traffic matc...

PA1.JPG

PAN-OS 8.0 Updates

I've recently upgraded a lab 200 to 8.0 from 6.1.4. After upgrade I couldn't get it to connect out for Software or Dynamic updates, getting an error saying no connectivity basically. I saw the changes about where communication via the mgmt interface has changed, and thought I had accounted for everything correctly, but I guess I must have missed...

Resolved! SIP aged-out session being left in the DISCARD state

Hi Guys, Has anyone come across this when the aged-out SIP session being left in the DISCARD state and the only way you can fix the issue is to clear the session with > clear session id 380025 command. xxxxxxxxxxxxxx(active)> show session all filter source xxxxxxxxxxxxxx----------------------------------------------------------------------...

Resolved! How do you do validation testing?

Hi all, I'm wondering if any of you do your own validation testing of security patces for PAN-OS and vulnerabily signatures. Example being, do you confirm your edge is vulnerable to a specific CVE, and then after patching do you confirm it's no longer vulnerable, and if so (any version of this kind of thing) what tools or processes do you use t...

Bug in GlobalProtect client

Hello, Global Protect client MSI is not installed correctly. Uninstall string is not correct : msiexec /I should be msiexe /X Silent uninstall of current version (3.1.4-7) in my case : MsiExec.exe /X{6AC613AB-3F53-424B-BED2-570C7869F30F} /QN Latest version 3.1.5-9 has the same error / problem.

Resolved! Help issue, wildefire dosn't upload file anymore

Hi alli have this little issue.We have activated wildefire on smtp to control and upload any permitted files to cloud for analysis. It started well and for a 6 days it sand files ad after malicious submissions it started to block files.But the last 2 days it stopped the process and in log we found only alert/forward and no more wildefire-upload...

High Management Plane CPU

Hello, good morning I am experiencing a High Management CPU situation (PAN OS 7.1.7)What is this mongod process? How to solve this problem? Thanks

Screenshot_1.png
Frazão by L1 Bithead
  • 6001 Views
  • 4 replies
  • 0 Likes

Resolved! GesoTrust Intermediate Certificate

Hi, We're having some issues with the Intermidiate certificate that we're using in one of our servers when trying to connect to it passing trough your firewall (installed in our client's system). Our certificate provider is GeoTrust Inc. and I've been reading that there may be some problems with your firewall when using it.Since only 2 users fro...

Resolved! How to enable only office 365 email (web and outlook apps) services in paloalto ngfw 3020

Dear geeks, I'd like to ask your kind support about how to enable only office 365 email (web and outlook apps) services in paloalto ngfw 3020. I've read some posts about safely enable office 365 in this forum and tested according to these guildlines but can't still get the solution. Really appreciate for all of your kind inputs. Thanks you all.

Wayne88 by L1 Bithead
  • 3286 Views
  • 1 replies
  • 0 Likes

Resolved! special subscription for site to site

Hey guys! We want to do a site to site IPsec vpn between two Palo Alto firewalls.Do we need a special subscription for site to site vpn?Global Protect Portal or Gateway license? Thanks!

MPI-AE by L4 Transporter
  • 2112 Views
  • 1 replies
  • 0 Likes

The latest reliable panOS version

Hi All, I'm currently checking documentation and release notes etc about 7.1.X.I have to learn how can I understand if a version is really stable/reliable? Obviously testing and working on it it's a good way to learning about a specific release.. I know it's sounds like a stupid question but in my opinion is not. Besides my first question, the...

  • 24415 Posts
  • 125 Subscriptions
Top Solution Authors
Labels