General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Predefined reports with several Virtual Systems

Hi all, We have a Firewall divided in two vsys and we are having problems with the configuration of some reports. When you try to generate a new "PDF Summary" and you have selected the virtual system "Shared" there are available some predefined reports that are shown as charts. However, if we select an individual virtual system there are not p...

Carracido by L4 Transporter
  • 3652 Views
  • 1 replies
  • 0 Likes

Custom Dynamic Block List

Does anyone know how long a custom dynamic block list take to refresh? Is it suppose to refresh\pull every 15 minutes? And if you do a commit does that make the change immediate?Here is my scenario, we are using a custom dynamic block list to add xp pcs to restrict the internet. When the pc is upgraded to Win7 we than remove the ip from the bloc...

lewis by L4 Transporter
  • 5783 Views
  • 6 replies
  • 0 Likes

Command Line : [show ntp] in M-100 result : op command for client dagger timed out

Hello, The M-100 is running on OS 6.0.9I did command via sshshow ntp Server error : op command for client dagger timed outthat is why management resource is consuming... I can't beleive that as time went by,, I have seen that result continusly continuing when I did command until now show clock is working properly and I did command as 'debug so...

John_Lee by L2 Linker
  • 4621 Views
  • 1 replies
  • 0 Likes

Resolved! script to rename address objects

Hi All, i have a requirement to rename alot of my address objects on firewall,is there a command with which it can be done so it can be made into a script? thanks for any help.

Harshit by L3 Networker
  • 11665 Views
  • 3 replies
  • 0 Likes

Recent BDS report from NSS

Hi Guys, Have any of you read the most recent NSS report for PA DBS below. Please let me know if any of you seen this. https://library.nsslabs.com/reports/technology-brief-palo-alto-networks-bds Thanks S

Donsen by L0 Member
  • 4107 Views
  • 1 replies
  • 0 Likes

Resolved! Unblocking ninite.com

I created a URL filter to block shareware sites; however I need to unblock one that I use. ninite.com. I have had no success getting this site to work. Adding the url ninite.com to the allow list, I am given an SSL error (enable TLS 1.0, 1.1, 1.2) which is enabled. I tried adding the IP address and that did not work. It appears the site is using...

jharlow by L3 Networker
  • 8522 Views
  • 7 replies
  • 0 Likes

Radius Authentication - Passive Firewall

Hi, I am trying to authenticate the passive firewall via Radius for management purposes. In the active firewall I have the same radius server configured with two different secret keys (one for active and one for passive). On my radius server I have two clients. One is the active firewall and the other for the passive. I can authenticate...

indysogi by L2 Linker
  • 4601 Views
  • 4 replies
  • 0 Likes

PCI compliance and port 443

We are employing GlobalProtect VPN on our PA, which also happens to be our intranet gateway (NAT) to the Internet. Technically speaking, the setup works very well. Because port 443 is typically open on most firewalls, we can connect to the VPN virtually anywhere. Unfortunately, our PCI compliance scan (public side of our PA) flagged the open HTT...

How to block access to internet based on User name and group

We have a request from our teachers for a way to block access to the internet based on students' username.Oh - and the teacher needs to be able to grant or deny this access from a simple interface... Myself and my colleague are scratching our heads on this one. What we are thinking is of trying to leverage Active Directory Groups in our PAN ...

ABAdmin by L1 Bithead
  • 9068 Views
  • 3 replies
  • 0 Likes

Resolved! Does statistics for appid ssl include other appid's using ssl such as gmail-base, facebook-base etc?

This is a fork of https://live.paloaltonetworks.com/t5/General-Topics/Statistics-reports-on-how-much-SSL-traffic-you-got/m-p/67945 but with a specific question. Dealing with reports in PA I wonder if the counters/statistics regarding appid ssl includes other appid's who also use ssl such as gmail-base, facebook-base and the others? That is l...

mikand by L6 Presenter
  • 2469 Views
  • 1 replies
  • 0 Likes

Google QUIC Disconnects

We started getting complaints from users that various Google services were showing intermittent disconnects. I think we've tracked it down to the QUIC protocol not being accurately identified by the PAN firewalls and getting blocked. I see 443/udp traffic from the hosts in question getting dropped as "unidentified-udp" mixed in with the allowed ...

cosx by L2 Linker
  • 4953 Views
  • 2 replies
  • 0 Likes

Reporting on Security/NAT Polcies and Hit Counts

Is there a way to export the current Security and NAT Policies to CSV, or even just PDF? I need to clean up a dirty firewall that I inherited, but I need other teams to let me know what is active/inactive. Screenshots or CLI outputs can work, but I want to provide this in a clear table format that is usable. I'd also like to know if there i...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels