General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1946 Views
  • 0 replies
  • 0 Likes

When will a new GlobalProtectClient GUI/UI be written?

We've been holding off replacing our Cisco Anyconnect clients as the interface of GlobalProtect is a big downgrade for us.

 

Any idea when/if there will be improvements made to the GP UI?

 

At the moment it looks like it was developed by engineers with n

...

GPforWin7.png
anyconnectwin_reconnect2.png
pmc by L2 Linker
  • 7546 Views
  • 4 replies
  • 6 Likes

Resolved! cli: traceroute host, ping host use connected interface

Is it possible to have traceroute host and ping host default to using the interface the cli was connected to?

 

We have the Management Interface of our PA 500 set to an internal address, like 192.168.129.11.  We can connect to it from our mpls networ

...

Crazy policies needed for BGP and VPN

Hi,

first read this article:

https://live.paloaltonetworks.com/t5/Learning-Arti​cles/Any-Any-Deny-Security-Rule-Changes-Default-Be​...

 

then

 I have this exactly behavor but I don't have wrote any/any/deny rules!

In my enviroment both intrazone-defa

...

Vulnerability exemption

Hi


what is actually
simple-client-critical
simple-client-medium

 

I

 

I  want to change the default action from alert to block .
the rule is under simple-client-medium , but the search result shows it is under
simple-client-high

Thanks

 

 

 

36029.png
sib2017 by L4 Transporter
  • 2200 Views
  • 2 replies
  • 0 Likes

URL White Listing

Hi all,

 

First of all, we are impressed about MineMeld, thanks Luigi for your ideas and work.

 

We have just started to play with MineMeld and wandering the format to whitelist domains and network ranges using stdlib.listURLGeneric (as wlURL)

 

We would l

...

Resolved! CLI checking licenses

Hi everyone! 2 quick questions in 1:

 

-To be able to include a URL as destination in a policy, do I need to have license for URL filtering?

-How can I check what licenses do I have in the CLI?

 

Thank you!

No Email protection for SaaS

The closest way to protect a SaaS email soltuion I have found is Proofpoint which has a wildfire API hook option.

 

I am supprised there is no SaaS service for forwarding attechments or inline scanning of email directly from paloalto networks.

Tech101 by L1 Bithead
  • 2666 Views
  • 3 replies
  • 0 Likes

TAP interface questions

I'd like to monitor a portion of my network on my failover PA in TAP mode.

 

Will this affect my HA pair at all? 

 

Is it possible to set up an aggregate TAP of 2 ports?

 

thanks in advance...

any to application default

We are working on hardening our firewall rules by replacing any to application default(service) and from any to the specific application(application). Example - we changed any to web-application and any to application-default. People hitting the same

...

jdprovine by L4 Transporter
  • 4822 Views
  • 11 replies
  • 0 Likes

ipv6 aggregator

Is there an ipv6 aggregator on the roadmap?

I noted that the URL aggregator can already extract them when the miners includes ipv6 IPs in the URLs (ex: office365), but did not find a way to get just the IPv6 addresses.

mr.linus by L4 Transporter
  • 2927 Views
  • 1 replies
  • 0 Likes

Resolved! dns amplification attack

Hi,

 

What are the best practices need to be followed  to  protect from the ddos  dns amplification attack . 

How to  filter the  trace  from the  log  if there is any attack happened ? 

Thanks

sib2017 by L4 Transporter
  • 6170 Views
  • 4 replies
  • 0 Likes

Resolved! RegEx for specific DNS strings

I was working on getting Data Filtering to block specific DNS requests with no resolution.

So, I am creating a Custom Application for DNS with a Pattern matching, which is partially working.

Working strings:

Under Objects/Applications/("Added applicatio

...

Export config from TFTP (non-management interface)

I was trying to export my running-config.xml with TFTP. It works fine when doing it from the management interface but is not working from any other interface.

 

If I use the source-ip to export the configuration i get a Timeout even though I can ping m

...

  • 24197 Posts
  • 117 Subscriptions
Top Liked Authors
Labels