General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SSL Decryption - log for SSL certificate errors?

Hi all,

 

We are using PANOS URL Filtering and SSL Decryption, and we reject a variety of SSL certificate problems such as expired certificates, SHA-1 signing, etc.  When one of our users hits one of these web sites, they get a "block" page.  This in

...

RSKadish by L2 Linker
  • 6832 Views
  • 3 replies
  • 0 Likes

Resolved! Proxy IDs help

Hello

I have a Palo Alto Firewall which wants to have IPsec Tunnel with a peer firewall which is a Checkpoint Firewall. Any of the firewalls can initiate VPN Traffic.

Can someone kindly let me know, what proxy IDs can be set on my Palo alto firewall f

...

Domain-map showing no result

What can be the possible reason for debug user-id dump domain-map showing no result.

I have a domain with netbios name as test where in the actual domain is test.abc.def.com. I am using user-id agent. I am pulling mapping from the user-id agent as te

...

Westcon2 by L3 Networker
  • 2052 Views
  • 1 replies
  • 0 Likes

Wildfire signature

Hi folks,

 

After Wildfire detect that file is malicious , how can i block this file or how can i find this malicious file signature ?

User-ID domain-map

Hi guys.

 

I have a problem with a user-id setup in a large multi domain envoirment. User-ID agentd are working fine, but the user did not match against the group mapping. It looks like we have a problem with the domain map. The command debug user-id

...

Routing Multicast PIM SSM

Hi guys,

 

I have Palo Alto cluster A/P with PIM SSM, I would like to know how is manage the multicast routing if i lost the active member ?

 

Regards

Zacre by L0 Member
  • 2061 Views
  • 1 replies
  • 0 Likes

Resolved! How to find out the right app-id

Hi all,

 

I started studying PA firewall recently and am struggling with finding out the APP-ID for some traffic. I can easily find out the services(or ports for CISCO ASA) and create the rules based on services/ports, but by doing this we will lose

...

Firewall rule optimization

Anyone know of any good firewall optimization software for PA. One that can review the rules and make good suggestion to improve the rule order, removal etc?

jdprovine by L4 Transporter
  • 3040 Views
  • 6 replies
  • 0 Likes

PA Bypass Question - McAfee Evader

Does anyone have any information on the latest posted PA bypass?  The youtube video shows some of the FW features  being bypassed using McAfee Evader.  It appears to require an IP of the firewall to execute - the example also shows most of the evasio

...

DMast by L2 Linker
  • 1894 Views
  • 1 replies
  • 0 Likes

Custome report

Hi

How to generate trafficreport for webmail usage like gmail
youtube -education?

Thanks 

sib2017 by L4 Transporter
  • 1483 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrade question Current version 6.0.10

Hi

 

Am currently a PA n00b, looking at upgrading an active/active stand-alone pair of 3020s currently running 6.0.10, looking to upgrade to 7.0.

 

Question: do we upgrade to 6.1 and then 7.0 or is there a better 6.1.x version to make leap from 6.0.1

...

Resolved! VPN Proxy ID nightmare

Hi All,

I can't seem to resolve proxy-id mismatch on a Route-based VPN i have configured between the PAN Firewall and a Cisco 3G router.

On the PAN side, I have configured 10.5.0.0/16 as my local proxy-id and 0.0.0.0 as proxy-id of remote side. I sti

...

Bocsa by L3 Networker
  • 4828 Views
  • 7 replies
  • 0 Likes
  • 23727 Posts
  • 104 Subscriptions
Top Liked Authors
Labels