General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Warning on commit new config - anyone recognise the cause?

Folks. I made a rule change this morning - first one in a while (fairly static environment of late) - and when committing, got the following warning Error: Invalid id 6 for os WindowsUWP.(Module: useridd) Anyone recognise this/know the cause/know what I need to do to fix it? Cheers

darren_g by L4 Transporter
  • 2242 Views
  • 1 replies
  • 0 Likes

Cannot enter "Maint" at boot via cli

All, somehow I lost connection to my PA-200. Im trying to do a factory reset on it and I am not able to enter 'maint" during boot via console. I am using putty . When I try, it just keeps loading the kernal. is there a way to pause to enter "maint"? It will not go past this either regards Bryan

2016-10-07_14-46-38.jpg
BryanMay by L1 Bithead
  • 3918 Views
  • 2 replies
  • 0 Likes

I'm getting an error when trying to log in maint mode on PA-2050

I have an Evaluation unit that I'm trying to reset to factory defaults via the Maint Partition, but not having any luck.Here is the error message I'm getting after I type in 'maint' at the prompt...Autoboot to default partition in 5 seconds. Enter 'maint' to boot to maint partition.Entry: masize: 12582912, sector_size: 131072Scanning JFFS...

westcon by Not applicable
  • 9238 Views
  • 7 replies
  • 0 Likes

Resolved! PA-7050 LACP causing delay in fail-over times

We have an HA A/P PA-7050 cluster running 7.0.2 with QNPC (40G). The 40G links are bundled in AE1 with LACP enabled. We noticed during testing that LACP causes 8-10 ping loss during a fail-over event. With LACP disabled we have a 1 ping loss during fail-over events.The LACP settings we have are the following: The remote side has been verified t...

lacp.jpg

U-Turn NAT with Port Address Translation in a DMZ

Hi Community, I am configuring my first PA-200 and having a difficult time. I have a /27 external network and have the PA-200 seeing the internet properly. I have internet untrust zone setup as l3 on Int 1.1, and a DMZ setup as l3. The DMZ zone is on eth 1.2 interface and has a few servers plugged into an unmanaged gigabit belkin switch as depic...

DMZ Depiction PA-200.jpg

Resolved! Custom applications and application override

I'm looking to get a better understanding of how custom applications work in relation to application override policies vs security policies. I have created a simple custom application with just a tpc port for an internal application. There appears to be two unrelated routes I can then take with this new application.1. I can add it to the applica...

Priority in PAN-QoS

Hi, When you are configuring QoS, it's possible to define more than one profile, and in this profile put 'til 8 Class defined. When you apply over the egress interface, it's possible to add this Class based over an source Subnet. Here is my question, what "priority use" or what is the behaviour if over the same interface applies in ex: From Su...

nanukanu by L2 Linker
  • 4817 Views
  • 5 replies
  • 0 Likes

Resolved! PAN AD Useragent - Excluding users?

Hi.Is it possible to exclude a specific user from the PAN agent configuration?I know you can filter based on group - unfortunately, the user concerned, which is used for several automated processes, is also a member of AD groups which I can't exclude, so it gets reported every time it runs a background process - which is skewing reporting, as th...

dagibbs by L4 Transporter
  • 21654 Views
  • 29 replies
  • 0 Likes

Resolved! PAN-OS 7.1.4-H2 Data filtering and Url filtering logging stops at serveral hours+ SSL decrypt fails

We upgraded a VM100 from PAN-OS 7.0.8 to PAN-OS 7.1.4 H2.We had 0 issues running 7.0.8 but we needed the DHE en EHCDE cipher support Now we have the issue that the Data filtering and Url filtering logging stops at serveral hours.Also some https sites starting to become very slow ands ssl decryption starting to fail for some websites.The vm100(4c...

Resolved! Wildfire verdict malicious and action alert

Hi all, We have seen in Wildfire Submissions that all files identified as Malicious and Grayware the action is Alert. The Wildfire Profile is configures to forward to public cloud and Antivirus profile has reset-both in Wilfdire Action tab. Is this a normal work? This is the Wildfire Submission Thanks a lot,Jordi

image.png
COMIP by L2 Linker
  • 5545 Views
  • 3 replies
  • 0 Likes

Resolved! PAN-SA-2016-0025 Kernel Vulnerabilities

SummaryThe kernel in use by the Management Plane of PAN-OS is vulnerable to CVE-2015-5364 and CVE-2015-5366. (Ref # PAN 52379/87408) Severity: HighThe CVSS Score of CVE-2015-5364 is 7.8, High; while the CVSS Score of CVE-2015-5366 is 5.0, Medium. Those could lead to a Denial of Service attack. What is the attack vector? Clients traffic pass thr...

Resolved! PAN-DB to BrightCloud

Greetings All, I know that we tend to recommend PAN-DB over BrightCloud, but in this instance I have a client who prefers to use BrightCloud. Can someone please confirm how to migrate over correctly. This use to be available in the following link, but now I do not have access to it for some reason: https://live.paloaltonetworks.com/docs/DOC-5554

Resolved! No inbound packets observed

Hello, Trying to troubleshoot an issue of aged-out traffic flow. It was SSH traffic originated from customer's LAN and destined to Internet address. Packet capture was configured on the firewall for troubleshooting but only outbound (but no inbound) packets were observed inside the PCAP files. Tried via WebGUI and CLI. Could it be that the incom...

Farzana by L4 Transporter
  • 4903 Views
  • 2 replies
  • 0 Likes

ACC traffic does not sum up correctly for different time ranges

Hi, Issue: Lets say we filter out web-browsing in ACC to check the traffic amount used by that specific app. We check three different ranges: Week1 - 300 MB & 8k sessions Week2 - 700 MB & 18k sessions Week3 - 1 GB & 23k sessions ... and now we select Week1+Week2+Week3 custom range, basically it contains everything within these we...

nikoo by L3 Networker
  • 5260 Views
  • 8 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels