General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Blocking Malware Callbacks

Malware Callbacks for command&control and also for data exfiltration are often transported in

HTTP POSTs.

 

The URL blocking of category malware URLs seems only to block the HTTP response. The GET or POST request seems to pass untouched to the server

...

Unibw by L2 Linker
  • 2911 Views
  • 2 replies
  • 0 Likes

Interface question

Hi!

 

This is our network:

 

My question is about interface 1/6:

I can ping the juniper from outside the network. But I can only ping the OpenVPN Server if I configure the IP-Address 80.0.0.5/32 explicit in this interface. Without this entry (80.0.0

...

netz-skizze.jpg
interface-aktiv.png
Morneweg by L1 Bithead
  • 1953 Views
  • 3 replies
  • 0 Likes

PA200 stops forwading traffic

Hi,

 

we have a pa200 (6.0.8) whichs suddenly stops forwarding traffic. So we had to reboot the device via managment UI to fix the problem. After doin some research i found this knowledge article from palo alto:

 

https://live.paloaltonetworks.com/t5

...

voip_class
iweltag by L2 Linker
  • 1639 Views
  • 2 replies
  • 0 Likes

Resolved! PA-500 destination NAT not working on PAN-OS 7.0.3

Hi guys,

 

I have a Zabbix monitoring server on an external IP/network which is listening on port 10060. I have a zabbix agent installed on my internal windows server that is also listening on port 10060. The server will make requests to the agent to

...

Resolved! Google Safe Search Brightcloud

Anyone else having Problems with SafeSearch And Google today? We were having dozens of reports that no matter what it was blooking google saying safe search was not set even if it was, we Roled back from 4668 to 4667 and it seems to ahve fixed its se

...

Resolved! Ultrasurf usage increase

Hi,

 

Since yesterday, I saw a big increase in the use of the Ultrasurf application. Actually, it went from 0 to 200k sessions per day. Is anyone else seeing this kind of increase? I noticed they modified that application in the last content update.

...

Experiences with PAN-OS 6.1.8 ...

Hi all

 

Does anyone already have installed 6.1.8 and tested? Are there any new issues?

What I can tell so far is ...

... some sites with supported ciphersuites and TLS versions which did not work in 6.1.7 are working now

... websites with ECDHE/DHE

...

Remo by L7 Applicator
  • 2534 Views
  • 4 replies
  • 0 Likes

Site-to-Site VPN with Dynamic Peer IP address not forming

In this set up, I'm trying to configure a site-to-site VPN between a PA and a Cisco 3G router (whose IP address will be dynamic). I'm unable to get the tunnel working. When I run the command 'show vpn ike-sa gateway <gatewayname>', I get no informati

...

Bocsa by L3 Networker
  • 4185 Views
  • 7 replies
  • 0 Likes

Disabled policy rules

Hi,

 

Under monitoring , still disabled policy rules matching to some some session .
And the session status are most of them 'incomplete' .
Why ?
Thanks

sib2017 by L4 Transporter
  • 1776 Views
  • 3 replies
  • 0 Likes

Resolved! DNS traffic allowed for one server but dropped for another

I have a perplexing problem with allowing DNS traffic from internal to the internet on our new PA-3020 running 7.0.3.

 

We have 2 DNS servers in our datacentre on the same subnet that perform queries to a couple of external DNS servers provided by ou

...

mitre10 by L0 Member
  • 4184 Views
  • 1 replies
  • 0 Likes

What Dynamic block lists do others use?

Hi there,

 

I have recently started wanting to setup using some Dynamic block lists in my PA box. I just wondered if others use these and if so, which sites do they use?

 

I was inially looking at using these 2.

 

www.spamhaus.org

 

www.openbl.org

 

...

JRussell by L3 Networker
  • 2387 Views
  • 2 replies
  • 0 Likes
  • 24006 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors
Labels