General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)

Hello Community! I wonder if anyone else is getting a FalsPositive-Hit in AntiVirus-Protection on downloading Silverlight.exe? When we use the following Link: http://go.microsoft.com/fwlink/?LinkID=623682 the page is blocked do to AntiVirus-Profile. In our ThreatLog we can see that the file Silverlight.exe is beeing blocked because it is ide...

L3 configuration

Hi, Distribution switch with multiple vlan created L3 interfaces . Multiple Edge switch connected with distribution switch via L2 trunk . if i have vlan 2 -10 configured with respective L3 interfaces like 10.0.2.1,10.0.3.1..10.0.10.1 , and i want to monitor traffic between these vlan How can i configure ?How the physical toplogy and logical topl...

sib2017 by L4 Transporter
  • 2911 Views
  • 2 replies
  • 0 Likes

Resolved! Palo Alto RADIUS authentication against Microsoft NPS is broken

Has anyone managed to get authentication on PAN-OS 7.0 working with microsoft NPS servers? Since version 7.0 authentication against our microsoft NPS radius servers is broken. Because the firewall now always first tries CHAP instead op PAP (see this article) and microsoft NPS always replies with a ACCESS-REJECT massage (see this article -> it...

nwsol by L2 Linker
  • 21396 Views
  • 16 replies
  • 0 Likes

App-ID RPC Syntax

So trying to further classify RPC data as the correct type of RPC data based on program number (300029 in this case). Not trying to re-invent the wheel though on how PA already correctly classifies it as RPC data, curious if there is a way in a custom App-ID to say something like "If known_existing_app AND XYZ then new_custom_app_ID", i.e. "If ...

PeterT by L2 Linker
  • 5238 Views
  • 2 replies
  • 0 Likes

Resolved! Site-to-Site VPN with PPPoE

Hi All,A somewhat interesting scenario pre-christmas here. I'm tasked with setting up a site-to-site VPN between a PA3020 and PA-200. The PA-200 will be connecting with PPPoE - which I've never set up before. I have some concerns on this and was wondering if anyone with some experience with a similar scenario can help with these questions: 1. ...

PPPoE.png
Bocsa by L3 Networker
  • 17066 Views
  • 7 replies
  • 1 Likes

Issues with netflow.

I have configured netflow profile and applied to an interface. I dont see anything in session browser,packet capture or traffic. I have port 9995 for netflow with ip in trust interface (172.29.5.248). setup active timeout to 1min.

ssl sever certificat can't be verified

Hi, This issue is on a Palo-Alto PA-500. I've renewed my SSL certificate from my provider and updated it in the Palo-alto / Device / Certificates. It tells me that this certificate is valid. Ok. thanls. But now that the date it should have expire is gone, my Global Protect clients have an error about the certificate that tells them that ...

About Facebook File Control?

Dear Sir, In facebook, There are many way to transfer file. Like In chat windows , Or In posting windows. In Paloalto App-ID facebook-file-sharing Description: Facebook file sharing is a feature offered on Facebook Groups that lets users share presentations, schedules, documents and many other file types with a group. You can post a fi...

BGP Active/Passive vs Active/Active argument

I'm running into an argument with our carrier for our 2 ISP links that I need to clarify. We currently have two 3050's with 2 ISP links coming into both devices in an Active/Passive configuration using PBR's to route traffic. We are adding a third ISP and dropping the slowest link, followed by implementing a BGP configuration with both ISP's....

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels