General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 271 Views
  • 0 replies
  • 1 Likes

Resolved! script to rename address objects

Hi All,

 

i have  a requirement to rename alot of my address objects on firewall,is there a command with which it can be done  so it can be made into a script?

 

thanks for any help.

Harshit by L3 Networker
  • 9047 Views
  • 3 replies
  • 0 Likes

Recent BDS report from NSS

 

Hi Guys,

 

Have any of you read the most recent NSS report for PA DBS below. Please let me know if any of you seen this.

 

https://library.nsslabs.com/reports/technology-brief-palo-alto-networks-bds

 

Thanks

S

Donsen by L0 Member
  • 3256 Views
  • 1 replies
  • 0 Likes

Resolved! Unblocking ninite.com

I created a URL filter to block shareware sites; however I need to unblock one that I use. ninite.com. I have had no success getting this site to work. Adding the url ninite.com to the allow list, I am given an SSL error (enable TLS 1.0, 1.1, 1.2) wh

...

jharlow by L3 Networker
  • 6301 Views
  • 7 replies
  • 0 Likes

Radius Authentication - Passive Firewall

Hi,

 

I am trying to authenticate the passive firewall via Radius for management purposes.

 

In the active firewall I have the same radius server configured with two different secret keys (one for active and one for passive).   On my radius server I

...

indysogi by L2 Linker
  • 3120 Views
  • 4 replies
  • 0 Likes

PCI compliance and port 443

We are employing GlobalProtect VPN on our PA, which also happens to be our intranet gateway (NAT) to the Internet. Technically speaking, the setup works very well. Because port 443 is typically open on most firewalls, we can connect to the VPN virtua

...

Google QUIC Disconnects

We started getting complaints from users that various Google services were showing intermittent disconnects. I think we've tracked it down to the QUIC protocol not being accurately identified by the PAN firewalls and getting blocked. I see 443/udp tr

...

cosx by L2 Linker
  • 2986 Views
  • 2 replies
  • 0 Likes

Reporting on Security/NAT Polcies and Hit Counts

Is there a way to export the current Security and NAT Policies to CSV, or even just PDF?

 

I need to clean up a dirty firewall that I inherited, but I need other teams to let me know what is active/inactive. Screenshots or CLI outputs can work, but I

...

Resolved! Statistics/reports on how much SSL-traffic you got?

Hi, any of you who knows if there is a whitepaper or such on how to generate a report or otherwise pick out the numbers/figures/graphs for how much SSL-traffic you got vs non SSL-traffic through a PA device?

 

That is both in bandwidth and number of

...

mikand by L6 Presenter
  • 7984 Views
  • 17 replies
  • 0 Likes

Policy Based Forwading Capability Question

Hello All, Was just wondering if anyone may be able to help with this our question.

 

Please see the attached High Level Diagram. Both Firewalls are PA 3020's with the full licence set enabled. We need to replace the ISA server which is not providing

...

Data Flows.jpg
WesNeary by L1 Bithead
  • 5423 Views
  • 5 replies
  • 0 Likes

Resolved! Multiple Tunnels with 0.0.0.0/0 proxy-ids

The scenario is 3 firewalls, with PA-HO acting as the hub and PA-1 and PA-2 as the branch sites. The Branch sites connect to the head office network via ipsec tunnels to PA-HO and vice-versa.

Due to multple dis-contigous subnets on the branches, it w

...

Resolved! About address and EBL limitation for maximum

Hello.

 

I want to know my question what address and EBL maximum from you.

 

1.

https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-IP-Address-Lists-on-Palo-Alto-Networks-Policies/ta-p/57411

The above documnet describes " Each imported

...

  • 23638 Posts
  • 107 Subscriptions
Top Liked Authors
Labels