nsatc.net shows as spyware?
I have a ton of entries in my spyware logs for DNS attempts to nsatc.net Some digging suggests this is a site run by Microsoft related to Windows Updates. False positive?
I have a ton of entries in my spyware logs for DNS attempts to nsatc.net Some digging suggests this is a site run by Microsoft related to Windows Updates. False positive?
Dear Friends, panos, panagent HULK hshah Steven Puluka hyadavalli mmmccorkleI have a doubt regarding PCI vulnerabilities scan and enable the signature for the same. when security team scan our WAN interface. he found below 1. SSL Certificate - Self-Signed CertificateVULNERABILITY DETAILSCVSS Base Score: 9.4CVSS Temporal Score: 6.9Severity: 2QID:...
I can't get the GlobalProtect Data File to download. I have it scheduled to update hourly for a couple of days already but nothing. If i click 'check now' I don't get any version to download. I didn't find anywhere to download it manually. Dynamic update finds the new version but doesn't download it with 'No ETAG from response' error message. ...
Hello All,I'm working on a migration that requires me to breakout one large SRX config into a PAN-OS config while implimenting multiple VSYS instances. I am managing the configuration via Panorama, so I've got a base config out of the migration tool for the policies and I have that in a conversion device group. I'm using a CLI output of set co...
I have used the XML API command to generate keys using the keygen option but I am searching for the PAN OS CLI command to do the same. Thanks for your help
Good evening I often have to configure a hundred new address objects at a time and then add them to an address group. I prepare the config by using Excel to combine columns with different values until I have the string of txt that I can paste into the CLI to add these objects to the PA. Here is an example of some of the lines of code I e...
Hello, i have another problem with policies... I used AD to filter people which can access the appropriate site. And I have rule in order: 1. Allow facebook (when I give access to whole facebook application) 2. Allow Youtube (when I use url filtering) In my opinion when user who is in group allow_facebook and allow_youtube and want to ope...
Hello, In our office we have two servers in a DMZ zone (10.10.10.3 and 10.10.10.4). In the PA-500 I created a DMZ zone that's related to a vlan in the switch . This switch i related to the serves (10.10.10.3 and 10.10.10.4). The servers are in DMZ zone so I configure the NAT rules with static NAT and I open the necessary ports. But without any...
Hi, I use V-Wire between ASA and core switch. I found the connections count of ASA is much more than PA's. Does anyone know how to explain about this ? Thanks.
Hi All, This is my first time posting, so if I am doing it wrong, please let me know. I have attempted to find relevant documentation, but nothing I have found actually seems to describe my issue. I had a request for an activity report for a user to be generated today - normally this process is quite easy and issue free; this time however, when ...
Please review the following white paper produced by Mandiant. This also has SNORT rules attached.https://www2.fireeye.com/rs/848-DID-242/images/rpt-synful-knock.pdfQuestion: Has Palo Alto produced a signature update for their IPS/Firewall devices to catch this type of attack/malware?If so, can you please provide details.Thank you,Baber
Has anyone else noted a materical change in 'dubious' Wildfire alerts in the last 24 hours? We have seen a material shift - as if a new detection engine/function has been enabled (and may possibly be a bit too sensitive).
Haveing alot of problems with Download Managers. We use continue/forward on alot of downloads including exe's but the problem we are running into is when someone downloads an installer that in turn tries to pull down other files from offline, They have no way of hitting a continue page and therefore the installer just stalls and fails. What ...
I have a strange circumstance here, I think. I've received several threats in my threat log for "DNS Answer Big TXT Record Response Anomaly" Threat ID 31580 (not sure if that's relevant or not, it just seems an odd similarity) So yesterday I had a few instances of this threat from a particular IP. My usual response (like it or not) when I see ...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

