General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4228 Views
  • 0 replies
  • 0 Likes

Bulk upload of set commands in PAN-OS

Hello All,I'm working on a migration that requires me to breakout one large SRX config into a PAN-OS config while implimenting multiple VSYS instances. I am managing the configuration via Panorama, so I've got a base config out of the migration tool for the policies and I have that in a conversion device group. I'm using a CLI output of set co...

dan731028 by L3 Networker
  • 6519 Views
  • 1 replies
  • 0 Likes

Resolved! CLI - invalid syntax errors when pasting in config

Good evening I often have to configure a hundred new address objects at a time and then add them to an address group. I prepare the config by using Excel to combine columns with different values until I have the string of txt that I can paste into the CLI to add these objects to the PA. Here is an example of some of the lines of code I e...

RobSmith by L1 Bithead
  • 12613 Views
  • 4 replies
  • 0 Likes

PA-500 Url Filtering

Hello, i have another problem with policies... I used AD to filter people which can access the appropriate site. And I have rule in order: 1. Allow facebook (when I give access to whole facebook application) 2. Allow Youtube (when I use url filtering) In my opinion when user who is in group allow_facebook and allow_youtube and want to ope...

ITBT by L1 Bithead
  • 3621 Views
  • 3 replies
  • 0 Likes

configuration of the NAT rules to DMZ zone

Hello, In our office we have two servers in a DMZ zone (10.10.10.3 and 10.10.10.4). In the PA-500 I created a DMZ zone that's related to a vlan in the switch . This switch i related to the serves (10.10.10.3 and 10.10.10.4). The servers are in DMZ zone so I configure the NAT rules with static NAT and I open the necessary ports. But without any...

NAT-cisco.JPG
RCHAIBI by L2 Linker
  • 10751 Views
  • 13 replies
  • 0 Likes

User Activity Report - Username not available for report

Hi All, This is my first time posting, so if I am doing it wrong, please let me know. I have attempted to find relevant documentation, but nothing I have found actually seems to describe my issue. I had a request for an activity report for a user to be generated today - normally this process is quite easy and issue free; this time however, when ...

Signature Questoin - New Malware Affecting Cisco Devices - SYNful Knock

Please review the following white paper produced by Mandiant. This also has SNORT rules attached.https://www2.fireeye.com/rs/848-DID-242/images/rpt-synful-knock.pdfQuestion: Has Palo Alto produced a signature update for their IPS/Firewall devices to catch this type of attack/malware?If so, can you please provide details.Thank you,Baber

Wildfire Alerts

Has anyone else noted a materical change in 'dubious' Wildfire alerts in the last 24 hours? We have seen a material shift - as if a new detection engine/function has been enabled (and may possibly be a bit too sensitive).

apackard by L4 Transporter
  • 6087 Views
  • 8 replies
  • 0 Likes

Download Managers

Haveing alot of problems with Download Managers. We use continue/forward on alot of downloads including exe's but the problem we are running into is when someone downloads an installer that in turn tries to pull down other files from offline, They have no way of hitting a continue page and therefore the installer just stalls and fails. What ...

DNS big text threat seems to bypass security rule

I have a strange circumstance here, I think. I've received several threats in my threat log for "DNS Answer Big TXT Record Response Anomaly" Threat ID 31580 (not sure if that's relevant or not, it just seems an odd similarity) So yesterday I had a few instances of this threat from a particular IP. My usual response (like it or not) when I see ...

mkeller by L1 Bithead
  • 2129 Views
  • 1 replies
  • 0 Likes

Resolved! Usefull CLI commands to work with logs

Hello I spend a lot of time playing with logs, ie. less mp-log ikemgr.logHow to:- go to end of this file?- search forward/backward keyword- scrool up/down and you problably know many other userfull keywords. Please share with us who are not well trained 😉 - yet RegardsSLawek

_slv_ by L4 Transporter
  • 77707 Views
  • 6 replies
  • 1 Likes

PA Trunks ?

I want set up two interfaces from PA as shown below. Traffic via Link will get to SW1 and on to S1, the same for the other link. The two are separated for security reasons. The issue is that, say SW1 fails we will need to re-wire SW2 to allow continued operation (shown in dotted line). But the security rules on the PA will not allow this witho...

Untitled.png
RC-BHF by L2 Linker
  • 2267 Views
  • 2 replies
  • 0 Likes

Resolved! XML API config options - edit ordelete to remove user from config rules ????

I have a question about the XML API config REST requests. First, do I need to explicitly request the commit lock in the API before making calls to edit or delete elements in a request (or is this done automatically by the API ?) Second, I am trying to delete a user from a rule set. Can I use the edit config to a blank member (like <membe...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels