General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 530 Views
  • 0 replies
  • 2 Likes

PA doesn't cover DROWN Attack?

A customer has been warned about DROWN attack (https://drownattack.com/) on one of its servers. As a server is behind PA I thought there was no risk. But searching through signature database I didn't find anything about DROWN attack. I've also checke

...

santonic by L6 Presenter
  • 5559 Views
  • 8 replies
  • 1 Likes

Resolved! Multiple PBF probes?

We would like to configure PBF to failover when several conditions are met. For instance, if we can't ping our next hop AND we can't ping some public server(s). The idea being, while our next hop might be pingable, there may be a routing issue in the

...

cburke by L1 Bithead
  • 3628 Views
  • 5 replies
  • 0 Likes

UserID instances

I would like to know if we can use the same UserID agent software for 2 domains in different windows machines. If we cant do it, we need to know if we can run 2 diferent instances of UserId agent in the same windows machine pointing to 2 different do

...

"Unusual traffic from your computer network"

Hi,

Users are often getting the message from google and they are forced to enter captcha  "Unusual traffic from your computer network",when i check palo alto it seems very normal . 

Is there a way to classify  or monitor the users who really sending

...

sib2017 by L4 Transporter
  • 7801 Views
  • 1 replies
  • 0 Likes

Resolved! Can we tweak a vuln threat sig settings?

I'm looking to tweak the "40015 SSH User Authentication Brute-force Attempt" which currently fires at 20 ssh attempts within 60 seconds - I'm looking to increase that 20 number. For some reason I can't think of how to easily tweak it right now... may

...

ulti by L3 Networker
  • 5296 Views
  • 2 replies
  • 0 Likes

Software packet buffer depletion

We're currently observing something quite interesting:
On our highly oversized PA-5050 firewall, software packet buffer 0 is, for several hours a day exhausted.

 

This is the platform (pair that runs in High Avalailability A/P):
family: 5000
model: PA-5

...

Dulle by L2 Linker
  • 7781 Views
  • 6 replies
  • 0 Likes

Resolved! OSPF with redundant route

Hello.

Currently we use OSPF as our routing protocol between five locations over a layer two IP Ethernet network provided by telco A. In order to get carrier diverse routes and add redundancy we are adding a second similar network provided by Telco B

...

ldavie by L2 Linker
  • 4346 Views
  • 3 replies
  • 0 Likes

Resolved! Multiple Addresses in the same ethernet interface

Hello everyone.

 

I need to publish 2 webservers (192.168.23.10 and 192.168.23.11), both located inside my LAN (trusted zone) through 2 different public IP addresses (200.111.111.114 and 200.111.111.115). This is the configuration:

 

admin@PA-500# sh...

adiazm by L1 Bithead
  • 16315 Views
  • 3 replies
  • 0 Likes

Resolved! Block google accounts

Hi,

can You help with following question?: In my policies i want allow google base searching, but do not allow google accounts,or google apps.

Resolved! Import PA-500 config on PA-3020?

We have a 500 that we're replacing with a 3020 which arrived today.

 

Should I need to do anything to migrate the config across other than an export and import of the running config?

 

I know some things like ports will clearly need addressing but in

...

Resolved! GP Client IP/Route Assignment

Hello,

 

I am having an issue with some clients when they connect remotely via the global protect client. Everything is working on most of the PC's who try to connect, but some users are receiving the issue. Here is the log of where the problem occur

...

Resolved! User Activity Report for Managers

Management has asked for a weekly summary of department web activity on our new PA-500.

 

I created a User Activity Report for each department but these reports are not conscise and difficult to read, especially for managers who would like a summary.

...

how to combine layer2 and layer3 on a single port

5050 at ver 6.1.9

Hello all!  You may want to sit down for this one. We have a core router that conects to a single layer 3 10GB port on a 5050 as the internet gateway.  The 5050 also has several server netwks attached via 1gb ports. Again these port

...

vnt90 by L2 Linker
  • 7911 Views
  • 12 replies
  • 0 Likes
  • 23732 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels