General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1959 Views
  • 0 replies
  • 0 Likes

Exchange 2016 Mailbox Servers in the DMZ

Has anyone had any issues deploying Exchange 2016 servers in a "DMZ" behind the Palo Alto firewall?

 

Microsoft does not support this configuration and their preferred architecture is to put the Exchange servers in the internal network.  Because these

...

jambulo by L0 Member
  • 6003 Views
  • 3 replies
  • 1 Likes

Upgrade to 7.1.6 application-default issue

So the release notes for 7.1 say that "When you configure a Security policy rule with the Application setting Any and the Service setting application-default, all applications are now permitted only on their standard ports as defined in Palo Alto Net

...

jtuten by L0 Member
  • 2405 Views
  • 1 replies
  • 0 Likes

Resolved! Wildfire - Connection hold

Hi all,

 

Just a question:

 

I didn't understand Wildfire mechanism related to a single session.

Is there a connection hold when waiting for a response (benign, malicious) from PA cloud by default? Is that configurable?

If the answer is Yes, but where?

 

Bes

...

What should we buy for active passive HA?

Hi,

 

We are using pa-3050 running 7.1.x with 3 year premium partner support and 3 year threat prevention license for about 2 months. We want to setup active passive HA. So What do we need to buy? Will buying only pa-3050 hardware without any support o

...

Skype is not working properly.

I am using skype for my office work. As i can send messages to others but i am not reciving messages from there side. And they are sending. If i check skype on mobile than i am able to see all messages. But on PC i am not receveing any of messages.

Ca

...

Chroomebooks and Transparent Authentication

We are a school district with 2-3,000 Chromebooks.

 

Currently, we have a Palo rule based upon subnet that applies correct filtering policy.  The problem is that we can't see which user is logged in, only the IP address.

 

Does anyone have a solution for

...

dannon by L3 Networker
  • 4001 Views
  • 6 replies
  • 0 Likes

Custom Report for Phishing Attempts

Folks,

 

Trying to make a custom report for phishing attempts in PANO. At a loss on how to do it for our 60+ devices.

(LIke a daily report).

Anyone here have any input? Couldnt find anything on the web for "phishing" specifically.

 

Thanks folks...

upgrade path for 5020

Hi

 

we have a requirement to upgrade a 5020 HA pair from 6.0.5-h3 to 6.1.15.

 

Can I confirm that 6.1.0 is the only interim release needed?

 

thanks

Resolved! Time-out Rule

We get a bunch of threat alerts from a single source IP from time to time, like someone running a script on or scanning a specific host for vulnerabilities. Some traffic is allowed through to the host. Does anyone know of a way to put an IP in a time

...

MineMeld Miner's no worky...

MineMeld Guru's,

Any advice on why Miners aren't downloading indicators is much appreciated.

 

Here's where I'm at...

-Running version 0.9.30

-System tab says everything is running

-Nodes claim they are connected but haven't pulled in any additional indica

...

running.PNG
indicators.PNG
nodes.PNG

PA is sluggish

I have removed a lot of rules and am down to 400 rules, I am up to OS 7.0.10 and upgrade the OS every other month

In the las couple months the PA seems to be getting slow and not as quit to commit changes or to pull up the dashboard when I first login

...

jdprovine by L4 Transporter
  • 3931 Views
  • 10 replies
  • 0 Likes

Resolved! Traps Pricing

Does anyone have a rough idea of how much traps runs per endpoint. We run roughly 800 laptops and desktops that this would be deployed to but I'd like to get a rough idea of pricing to determine if this is something that management would actually try

...

BPry by Cyber Elite
  • 4077 Views
  • 6 replies
  • 0 Likes

BFD in Active Active HA

Figured this out the hard way.  If you create a custom BFD profile in Active / Active HA mode, the BFD profile names need to be unique to each device.  If you try to configure a BFD profile with the same name on both devices, BFD will not come up.  

 

...

  • 24202 Posts
  • 117 Subscriptions
Top Liked Authors
Labels