General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

Resolved! Create threat signature

Hi Guys, I need to know if I can create a threat signature in case I've only the malware hash. Is it possible to do on PA? If not, Is there any other way I can block malwares based on hashes only? Regards,Sharief

Troubleshooting ipsec tunnel setup.

I have setup ipsec between PA200 and cisco device. When trying to bring tunnel up not even able to establish phase1.Getting following errors in logs. I have keyed in pre-shared key again on both the sides. ikev2-nego-child-start:'IKEv2 child SA negotiation is started as initiator,non-rekeyike-generic-event- received notify type AUTHENTICATION_FA...

Globalprotect - User-ID - missing domain prefix - group mapping not working

Hi I have been trying to get User-id / Group mapping to work in one of our installations but without any luckTried both Radius and LDAP authentication.I do see User-ID / IP mapping - but the domain prefix is missing."10.253.250.1 vsys1 GP sensagummi 2591361 2591361" I do as well see User-ID / Group mapping and the domain prefix is present there ...

Resolved! PA drops traffic apparently without NO REASON

Hi All, I have PA 2050 with panOS version --> 7.0.9I have two rules:Rule 4 --> Permit for svc-casse application as (ssl, ms-updated ecc)Rule 5 --> Cleanup for svc-casse That's the situation check :RULESLOG Really really strange behavior I never seen this before.Rule 4 permit ssl and ms-update but it's ignored.. Another crazy thing? Some...

Rule_INVOLVED.JPG
LOG_DROP_Without_no_reason.JPG
SSL_Allow_random.JPG

Resolved! Message of the day adn Embedded Message for cotent updates

How does one go about getting contents updates as part of message fo the day running 7.1.6 according to below in Red from PA the content and software messages have to be embedded and then I should be able to log in and veiw messege of the day and see ant content or softwared update messages If you or another administrator configured a message...

PA drops traffic apparently without NO REASON

Hi All, I have PA 2050 with panOS version --> 7.0.9I have two rules:Rule 4 --> Permit for svc-casse application as (ssl, ms-updated ecc)Rule 5 --> Cleanup for svc-casse That's the situation check :RULESLOG Really really strange behavior I never seen this before.Rule 4 permit ssl and ms-update but it's ignored.. Another crazy thing? Some...

Rule_INVOLVED.JPG
LOG_DROP_Without_no_reason.JPG
SSL_Allow_random.JPG

Info Wildefire analysis and wildefire in antivirus profile

Hai allafter the upgrade to new version of pan os(7.0.13) i found some difference in security profile. Can you help me to understand the difference between: - Security Profile > Antivirus > wildefire action- Security Profile > Wildefire Analysis is Antivirus profile to block malicious file knew in the dat file and wildefire for zero day...

Resolved! PA5050 | temperature sensor | how to disable false alarm

Hi all, could it be that somebody know:we have a problem with a temperature sensor on our PA5050 deviceS1 Temperature @ 10G Phys [U171] False 17.40 5.00 60.00Time to time we see temperature 0!!! [screen 1] and it triggers a temperature alarm event and increases FAN speeds to 6-7k for 1min and than alarm is gone. We have thous...

pa5050temp.png
IHEP by L1 Bithead
  • 7663 Views
  • 8 replies
  • 0 Likes

Application Filtering and Basic Setup

Hi All, I would like to ask the FF. 1. I want to use Application filtering but permits web browsing. - Enabled App filtering, Permit Web-browsing, SSL and DNS but I can't browse and launch any website. Any idea how to permit only browsing on app level? What should i allow? 2. In future is it hard or does it affect you in production when ...

What's new in MineMeld 0.9.30

Release Date: 2016-12-02 How to update: Updating MineMeld Core - log retention is now configurable via file - fixed a bug preventing the removal of old trace files API - fixed a session leak Docker - fixed a problem with volumes. Backup your config before upgrading ! Nodes - new Miner for O365, this Miner can automatically collect IPs ...

Screen Shot 2016-12-02 at 19.22.31.png
lmori by L7 Applicator
  • 11358 Views
  • 3 replies
  • 2 Likes

PA-200 fails bootup after hard power outage

I'm having multiple devices with this issue and I'm just curious if anyone else has seen it. Basically I have a ton of PA-200's that may experience someone power them down by removing power or shutting a site power off. When power comes back, they don't always boot up safely. They get a message stating "boot corruption" when you ssh into them...

Erinmac by L0 Member
  • 5970 Views
  • 1 replies
  • 2 Likes
  • 24357 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels