General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Firewall rule optimization

Anyone know of any good firewall optimization software for PA. One that can review the rules and make good suggestion to improve the rule order, removal etc?

jdprovine by L4 Transporter
  • 2937 Views
  • 6 replies
  • 0 Likes

PA Bypass Question - McAfee Evader

Does anyone have any information on the latest posted PA bypass?  The youtube video shows some of the FW features  being bypassed using McAfee Evader.  It appears to require an IP of the firewall to execute - the example also shows most of the evasio

...

DMast by L2 Linker
  • 1845 Views
  • 1 replies
  • 0 Likes

Custome report

Hi

How to generate trafficreport for webmail usage like gmail
youtube -education?

Thanks 

sib2017 by L4 Transporter
  • 1458 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrade question Current version 6.0.10

Hi

 

Am currently a PA n00b, looking at upgrading an active/active stand-alone pair of 3020s currently running 6.0.10, looking to upgrade to 7.0.

 

Question: do we upgrade to 6.1 and then 7.0 or is there a better 6.1.x version to make leap from 6.0.1

...

Resolved! VPN Proxy ID nightmare

Hi All,

I can't seem to resolve proxy-id mismatch on a Route-based VPN i have configured between the PAN Firewall and a Cisco 3G router.

On the PAN side, I have configured 10.5.0.0/16 as my local proxy-id and 0.0.0.0 as proxy-id of remote side. I sti

...

Bocsa by L3 Networker
  • 4751 Views
  • 7 replies
  • 0 Likes

WildFire & Office Documents/PDFs - Limitations?

We currently use Wildfire on "PE Executable" filetypes on our PA-500.

 

I'm interested in using it against Office documents and PDFs as those are clearly a major threat vector.

 

Thing is, whatever model of Palo Alto I look at, they all seem to show

...

Block unwanted traffic on port 1720

Hi,

 

I have a voice/visioconference system available on the internet (via NAT-ed IP) using H323. So of course the port 1720 is open and reachable from outside, without restriction on IP addresses because users must be able to reach the system from t

...

NVogel by L0 Member
  • 2854 Views
  • 2 replies
  • 0 Likes

Authentication Profiles on Global Protect

 

Is it possible to have two sets of authentication profile on Global Protect ? One ste of users authenticating through AD and another set through digital certificates only . 

usvi by L3 Networker
  • 1728 Views
  • 1 replies
  • 0 Likes

Resolved! Email alerts for threats.

Do I need Panorama to set up email notifications on high and critical severity threats? I know you can set up sheculed reports, but what if I just want to receive an email when a threat is blocked or detected, or what have you.

Netwerx by L2 Linker
  • 5062 Views
  • 3 replies
  • 1 Likes

SRX Config - XML Invalid

Since upgrading to MT 3.2.4 I have been unable to import the XML file from a SRX .  Previous to this release (3.2.1), I had no issues with the same XML.  However, it is not working on 3.2.4

 

The XML file is correct with the configuraiton tags at the

...

indysogi by L2 Linker
  • 2848 Views
  • 1 replies
  • 0 Likes

Meaningful User Reports

  • PA-500
  • Software Version 7.0.3

 

How do I generate meaningful user reports, or how do I better interpret the reports that are available.

 

With a User Activity Report I get application statistics, browsing summary by category etc.  But I can't say "Use

...

PinkCup by L0 Member
  • 2318 Views
  • 2 replies
  • 0 Likes

Resolved! Rudimentary TCP Session and Monitor Question

I feel like I should already know this, but I just need a sanity check.

 

I have a rule that allows host A to B via tcp/900.  So host A starts to communicate via host B via that port.  The firewall allows it and a session is created.  Now, assume A a

...

mrcs by L0 Member
  • 2558 Views
  • 4 replies
  • 0 Likes
  • 23708 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels