General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! New Anti-Spyware Signatures, false positives?

Hello,

 

The latest application and threat content update this week added a couple of new anti-spyware signatures:

medium

86759

AndroxGh0st Scanning Traffic Detection

spyware

alert

medium

86760

AndroxGh0st Scanning Traffic Detection

spyware

...

axemte by L0 Member
  • 4502 Views
  • 1 replies
  • 0 Likes

Resolved! Certificate based Site to Site VPN (IKEv2)

Hello Folks, I am trying to build a site to site vpn between a Palo Alto firewall running 8.1.7 and a Checkpoint firewall. Settings are configured to use IKEv2 only with certificate based authentication.

 

While the logs below are from lab setup, but t

...

Udupi by L1 Bithead
  • 18327 Views
  • 12 replies
  • 1 Likes

SSL Inspection and SSL Labs

Outside of minimum and maximum supported tls versions and ciphers what are some things to look for on SSL Labs that would be breaking decryption. In the Palo decryption logs if it shows error "Early close notify" what would be something to look for a

...

Claw4609 by L4 Transporter
  • 2177 Views
  • 7 replies
  • 0 Likes

GP Compatibility on Windows Server

Hello, everyone.

Does anyone know if you can install the Global Protect agent, on Windows servers, such as 2012, 2016, 2019????

Is there a documentation that tells me and confirms this?

I see in the Palo Alto Firewall, that the computer does not give

...

Matlu_NN by L2 Linker
  • 1475 Views
  • 6 replies
  • 0 Likes

Next Hop in default route using DHCP Comcast modem

Hello Group,

 

I am setting up a PA-200 in my SOHO with comcast as my ISP.  I have comcast for my isp and am using DHCP to optain my IP address.  My question is this.  Per the setup guide, if I check DHCP under the IPV4 tab, and check, Automatically cr

...

BryanMay by L1 Bithead
  • 4262 Views
  • 5 replies
  • 0 Likes

Factory Reset

I was in the middle of setting up a PA 850 and in the end needed to conduct a factory reset. I issued the commands to put into maint mode and was able to log in with maint@ip and the serial number as the password through putty. I had to step away for

...

Resolved! Minimum Code for PA-415/445

Hello, looking at the PA-415 for a small office and I can't seem to find the minimum code required.  The datasheet shows performance results using OS 11.0 but there's nothing to indicate if you can use 10.2 code.

TIA!

DHCP client support for IPv6

Hi,

 

You can't configure an Ethernet Interface as a DHCP Client for IPv6 like the IPv4.
Does anyone know this will be supported in the (near) future?
I can't find anything about this.

MrKit by L0 Member
  • 2058 Views
  • 2 replies
  • 2 Likes

IPv6 on public interface

Dear all,

 

I'm ttrying to get IPv6 up and running but so far without much success.

My ISP assigend a /48 range to me and they are saying I need to use DHCP. AFAIK, DHCPv6 is not supported, but NDP is.

Assume my IPv6 prefix is

abcd:1234:5678::/48

 

So I ena

...

SMB traffic identified as active-directory

From one of our management servers  (Windows Server 2016) SMB traffic is identified as active-directory, but from user clients it's correctly identified as ms-ds-smbv2. Anyone come across this? We have several storage solutions (NetApp filer, iSCSI,

...

  • 24195 Posts
  • 100 Subscriptions
Labels