General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Usefull CLI commands to work with logs

Hello I spend a lot of time playing with logs, ie. less mp-log ikemgr.logHow to:- go to end of this file?- search forward/backward keyword- scrool up/down and you problably know many other userfull keywords. Please share with us who are not well trained 😉 - yet RegardsSLawek

_slv_ by L4 Transporter
  • 79466 Views
  • 6 replies
  • 1 Likes

PA Trunks ?

I want set up two interfaces from PA as shown below. Traffic via Link will get to SW1 and on to S1, the same for the other link. The two are separated for security reasons. The issue is that, say SW1 fails we will need to re-wire SW2 to allow continued operation (shown in dotted line). But the security rules on the PA will not allow this witho...

Untitled.png
RC-BHF by L2 Linker
  • 2339 Views
  • 2 replies
  • 0 Likes

Resolved! XML API config options - edit ordelete to remove user from config rules ????

I have a question about the XML API config REST requests. First, do I need to explicitly request the commit lock in the API before making calls to edit or delete elements in a request (or is this done automatically by the API ?) Second, I am trying to delete a user from a rule set. Can I use the edit config to a blank member (like <membe...

Can't Email Monthly Reports?

I can generate monthly custom reports, andI want to mail these to management but the email scheduler is only giving me the option for daily or weekly email schedules. "Management" unfortunately aren't very keen on logging into the Palo to retrieve their reports, they want them sent. Is there a way to schedule monthly reports?

djr by L4 Transporter
  • 2396 Views
  • 1 replies
  • 0 Likes

VM-100 responding with SYNACK on all ports

Hey, I've got an evaluation of the VM-100 (v7.0.2) setup, but I'm finding that for some reason the firewall appears to be intercepting requests and completing a TCP 3-way handshake, regardless if the ultimate destination has the port open or not. Has anyone got any idea if this is normal behaviour, or if I've miss-configured something somewher...

block http download based on the download file hash value

Dear all, I have asked to look for a solution, we want to receive alert based on specific file download via http, we have the file MD5 or SHA1 hash value. Can I do this with a PAN? The filename could change, I don't know the file size but I have the file hash value.. Thanks for your helps in advanced, E

Palo Alto networks PA-500 with PowerDesine 3001 POE modem

Hello, I like to replace the cisco ASA 5510 with PA-500 in the company . I do all the necessary configuration in the PA-500 but always it still a problem of internet connection. I configure the PA-500 with the same specification configured in the Cisco ASA5510 ( MTU size, the Vrouter...) but always I still have the same problem. In the guide ...

RCHAIBI by L2 Linker
  • 3807 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama Traffic log forwarding

I have traffic log forwading from Panorama to an external syslog server working correctly however I would like to see the device the log was generated from included and not the default "Panorama". Is this possible? This is what I see on the external server: Oct 20 13:10:59 Panorama 1,2015/10/20 13:10:59,001801009725.............. Thanks

r24481 by L1 Bithead
  • 5078 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama CLI - list of values

We run Panorama v7.01 and have a requirement to edit the template stack from the CLI. The CLI path is as follows: configure edit template-stack <stackname> set template ??? Under the set template context I need to add a list of templates, however cannot work out the correct syntax. The help (?) switch shows "[ start a list of values" b...

Resolved! shell request failed on channel 0

Trying to do an SCP copy to a server, but I can't get past "shell request failed on channel 0". Using Solarwinds, and it says Authenticated user "username" from IP "ipaddress", but it always fails from the firewall. Any ideas?

craymond by L4 Transporter
  • 22339 Views
  • 4 replies
  • 0 Likes

Resolved! PAN-OS 7.0.2 SSL Decryption certficate untrust issues (No problem on 7.0.1)

Yesterday i upgraded my pa vm-100 from panos-7.01 to 7.02.After that facebook stopped working with SSL decryption on. After some testing and troubleshooting this seems to be the problem.The problem is that some akamai domains that facebook uses gives me an palo alto certificate untrusted page.for example this domain: https://fbcdn-profile-a.akam...

Beware ! PAN-OS 7.0.2 - Seemed to kill AV and inspection

Hello Environment Rule base is established and working with LDAP integration for users . Outbound SSL SSL decryption is also setup and working 7.0.1 Rules allow a group to talk to the Internet. Security profile are used for AV, Anti Spyware , URL filter and File blocking. SSL decryption is also setup . Symptom A bespoke Response Page is setu...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels