General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4120 Views
  • 0 replies
  • 0 Likes

CVE-2004-2761 and CVE-2008-5161 vulnerability applicable to PAN 7.0.3

Hi all, Hope everyone doing great. I have a Palo alto firewall running in 7.0.3 version. Recently there was an audit happened and submitted some vulnerabilities found in our firewall. I am very curious to know that whether captioned vulnerability appiicable to PAN 7.0 or not. Below are the description for the vulnerabilities: • SSL Certifi...

Resolved! How to downgrade HA pair from 7.1.X to 7.0.X version.

Hi Guys, What is going to be a right way/steps to downgrade PA from the version mentioned above? 1) Disable "preemption" on the both nodes. Commit changes. 2) On the "passive" node load config that matches your version. Let say l am going to install 7.0.1. So config has to be compatible with this version. Install and reboot. 3) Passive back ...

Resolved! EBL Issues

I've just started to test working with an EBL to quickly update a block list without having to apply the URL Filter to all of the different groups that we have. I've verified that I have connection to the document and that the Palo Alto sees it but I can't actually get it to stop showing traffic, instead the HTTP Request Brute Force Attack reset...

BPry by Cyber Elite
  • 8325 Views
  • 11 replies
  • 0 Likes

HA pair on different os version

I have a HA pair (active/passive) that I want to upgrade from 6.1.11 to a stable version of 7. I also am using global protect with certs. According to some information I gathered from the community if I upgrade to what I was told was the current most stable version of 7.06 that is would break my vpn certs. So I am trying to do an upgrade that w...

jdprovine by L4 Transporter
  • 8509 Views
  • 14 replies
  • 0 Likes

Where to apply Anti-Spyware Profiles

I've looked around in various places and can't seem to find a definitive answer on this. In regards to anti-spyware profiles, is there any need to apply these to security policies with a source of the outside Internet zone bound for your inside network (lan or dmz, etc). As I understand it, the purpose is generally to identify and stop "phone-ho...

Resolved! Anyone having issues with Threat ID 40059 (HTTP Brute Force)?

Palo Alto pushed out an update to the HTTP Request Brute Force Attack signature (40059) on 06-15. Since then I've seen a rash of threats being identified from Akamai Technologies IP addresses (about 8 different addresses). I'm wondering if anybody else is having this issue and it's a problem with the threat signature or if someone is using Akama...

BPry by Cyber Elite
  • 4243 Views
  • 2 replies
  • 1 Likes

IPsec Phase 2 Lifesize Coutdown

On an Phase 2 IPsec SA with a non-zero lifesize, I see the proposed initial lifesize in the "show vpn ipsec-sa" output,crclark@<redacted>-pa5050b(active)> show vpn ipsec-sa tunnel <redacted>-cisco-gwGwID/client IP TnID Peer-Address Tunnel(Gateway) Algorithm SPI(in) SPI(out) life(Sec/K...

cosx by L2 Linker
  • 10164 Views
  • 5 replies
  • 0 Likes

Identifying Applications

Hi guys, Got an odd one here. Traffic is being identified as a completely different application to what the traffic actually is. For example, see below. I've cleared the dataplane cache and re-downloaded the DB categorisation as per the document below, but to no avail. https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Handle...

traffic application.png

Multiple PA-200 Firewall's lock up and require a reboot in order to function.

I have 24 PA-200 firewalls. They are running on PanOS 6.1.3. At random times the firewall will lock up and requires the device to be power cycled to restore connectivity. I have called Palo Alto support and them connect to one of the devices that had stopped forwarding traffic. This specific firewall I was able to connect to the outside mana...

New to Palo Alto

Hi all I am a firewall engineer and I am completely new to Palo Alto firewalls. Would any of you be able to recommend any training, certification I should start with? Thank you in advance. M

cve-2009-3555

Hello When scanning management interface or enabled https layer3 interface it shows the related vulnerability, is there a way to fix.version is 6.1.10 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3555” thanks.

PanIst by L3 Networker
  • 3218 Views
  • 2 replies
  • 0 Likes

Custom DNS name

We have a DNS name genieo that is not being recognized and is not included in the signatures. Two things first is there a way to identify it with a custome signature with the object/anti-spyware and then be able to send it to a sinkhole?

jdprovine by L4 Transporter
  • 5150 Views
  • 10 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels