General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Getting the error "Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh.

We have PA 5250 which has configured with multiple EDL. Suddenly all the EDLs are failing that throws the "Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh." As a workaround we rebooted the firewall and it resolved the issue. Looking for the experts advise to resolve this issue permanently.

Trouble setting up Proxy ID's for a S2S with a Checkpoint peer and continuous rekeys

Hello, I'm quite new to PA and not much firewall experience. We are having trouble with a S2S VPN with a partner who has a Checkpoint FW. The clients are on our side, the server is on their side. What I see in our logs are constant rekeys for the IKEV2 tunnel every 2-3 seconds: ipsec-key-expireikev2-send-p2-deleteipsec-key-deleteikev2-nego-chi...

PID.jpg

arp Flooding

Cisco router is getting flooding from Palo Alto firewall Source NAT is basic getting scan from outside random countries We deal with users in other countries and blocking by countries will not work. the ranges from outside to our public ip address It looks like a scanning because it's rang of our public ip address what can we do to stop it or pr...

How to allow particular URL via Global Protect Split Tunnel and DNS should resolve for that particular URL.

Our BI team has snowflake setup in the azure, they have whitelisted on-prem public ip addresses and Global protect public ip addresses to allow the snowflake access. We have a split tunnel GP VPN so tried with including domain and port number of the snowflake in the global protect config. which is having a DNS resolution issue? is any one have...

tthapa23_0-1726688400290.png
tthapa23 by • L1 Bithead
  • 2923 Views
  • 1 replies
  • 0 Likes

Resolved! EDL global find XML API

Hi dear all, When I use /api/?type=op&cmd=<request><system><external-list><global-find><string></string></global-find></external-list></system></request> to search EDL with entry string, I can only search with IP list, for example, <request><system><external-list>&...

jyao by • L1 Bithead
  • 2990 Views
  • 4 replies
  • 0 Likes

Fuel Spark Event Discussion: AI in the Age of Cybersecurity (September 26, 2024)

Fuel User Group is hosting a virtual Spark User Summit on September 26: AI in the Age of Cybersecurity. This special event, from 9:30 until 11:30 a.m. PT on Thursday, September 26, is dedicated to AI. Join us for an insightful update from Rob Rachwald, Director of Product Marketing at Palo Alto Networks! We’re thrilled to welcome Rob back as...

September-2024_Spark-User-Summit_palo-alto-networks.jpg
emgarcia by • Community Team Member
  • 1459 Views
  • 0 replies
  • 0 Likes

Resolved! Where is the documentation that describes Syslog Log types formats for Palo Alto Firewalls?

On my Ubuntu Server I receive syslogs, that may look like this: <14>Sep 23 20:01:11 PA-440 1,2024/09/23 20:01:11,021201133296,TRAFFIC,end,2561,2024/09/23 20:01:11,10.10.10.103,20.190.177.21,192.168.10.20,22.120.127.11,rule1,,,ssl,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LFP LimaCharlie FW,2024/09/23 20:01:11,121977,1,60637,443,39335,4...

How can I send Palo Alto Firewall Syslog as JSON format to a Syslog Server?

I have purcased a PA-440 Palo Alto Firewall. I want to send Syslog from it to a Ubuntu Server with JSON format. I am sending Syslog from the firewall to a Ubuntu Server using "Device > Server Profiles > Syslog": The syslogs that I receive looks like this, and is CSV(?) - not JSON: <14>Sep 23 20:01:11 PA-440 1,2024/09/23 20:01:11,0212...

02_syslog_server_profile_traffic.png

PAN-OS

Name a version of PAN-OS that does not have a vulnerability. Ya that would be great

App-ID confusion and blocking spotify

Hello, I'm trying to work on a request to totally block Spotify on our network for 1 host (could be more in the future) and I thought App-ID would be the best option for this but since it depends on SSL and web browsing it's dropping all traffic when I add those dependencies; which I figured it would. When I just have Spotify in the application...

cruz77 by • L1 Bithead
  • 10555 Views
  • 5 replies
  • 0 Likes

Resolved! Spotify traffic showing up as an incomplete application

I have to allow certain streaming music apps (Spotify, Pandora, etc.) though my PA and I've been trying to see how that bandwidth looks like first before I allow it and throw it in a QoS ploicy for the rest of my company. I created a rule to allow the Spotify application outbound for just myself and created QoS policy on the PA that would limit ...

Globalprotect auth certificate profile

Hi, Question on global protect authentication certificate profiles. On our gateways, I've had a certificate profile configured to prevent non-company devices from connecting. Has worked great, no real issues. However, this was only configured on the gateway, no the portal authentication. I'm trying to resolve an issue where bad actors ar...

Resolved! Palo Alto VM GCP not using ssh key and forcing password authentication

I have tried multiple BYOL images in Google Cloud and re-generate SSH keys. It keeps asking to authenticate the admin user with no known passwords. It's ignoring the keys I guess. Is there something missing from my config when I deploy via Terraform? ebug1: Found key in /Users/arthurgreenwald/.ssh/known_hosts:1 debug3: send packet: type ...

  • 24460 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels