General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Clarification on http2 traffic and decryption

Hi all,

 

I was hoping to get some clarification on http2 and firewall interaction. I understand that generally http2 works without issue as long as it's being decrypted. I also understand disabling inspection/decryption (Strip TLS ALPN) on http2 tra

...

KGDrake by L0 Member
  • 982 Views
  • 1 replies
  • 0 Likes

Resolved! Adding IP's on Policies on panorama

Hi All,

 

Needing your suggestions i'm adding a list of ip addresses on policy that I created on branch and when I push it I got an error on NAT ISP 1, NAT is not a problem I knw because everything is working correctly. I notice that this has been ad

...

weezy by L2 Linker
  • 725 Views
  • 2 replies
  • 0 Likes

Layer 3 sub interfaces on Hyper-V

Hi all,


I am trying to get Palo Alto VM series (10.2.3) to work with layer 3 sub interfaces on Hyper-V (2022).
I configured interface/subinterface from the documentation (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRkCA

...

pa_subinterface.png

Resolved! Implementing Applications Over Services

We recently completed a migration and I am in clean up mode.  I would like to utilize applications but we do some no decryptions exceptions rules that bypass decryption.  I am concerned that without decrypting, the rule will break and traffic won't f

...

Access PA-440 MGMT Interface via Cisco Switch

Hi Guys,

I am working with below scenario and would like some help.

 

As shown in diagram:

A cisco switch IE3400 is connected with PA-440 with trunk connection and also one of the interface of switch is connected to MGMT port of PA-440.

There are mu

...

Janmejay_Dave_1-1687412475430.png

Resolved! Packet drop in the Firewall

Recently, we did a Migration activity, From the Juniper SRX to Palo Alto.

 

After successful Migration, we can notice that one drop over the PA firewall.

We did troubleshooting from our end and in the global counter can see below error with drops

 

flow_f

...

Traffic redirects to captive portal

We currently have a policy in place that allows all HTTP and HTTPS traffic from a test server (Trust) with a static IP address to reach untrusted networks. However, when accessing the server from a browser, it automatically redirects to a captive por

...

Bijesh by L1 Bithead
  • 749 Views
  • 1 replies
  • 0 Likes

URL Profile Known Bad Categories

What are the known bad url categories that palo checks is blocked? We currently block all the categories in this document but AI-Ops still flags it. Is there a way to see specifically what its failing? 

 

Malicious URL Categories (paloaltonetworks.co

...

Claw4609_0-1687291149037.png
Claw4609 by L4 Transporter
  • 985 Views
  • 3 replies
  • 0 Likes
  • 24203 Posts
  • 100 Subscriptions
Top Liked Authors
Labels