General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4141 Views
  • 0 replies
  • 0 Likes

Resolved! Configuring a port for a dedicated WAN link.

I recently ordered a 1GBPS dedicated fiber connection between my primary site and DR site. The ISP doesn't assign me an IP address or anything and says it is just a layer 2 connection. So I am a bit confused on how to configure my PA 3020s(one at each location). I have installed an sfp module from PA into each side but they are not coming up....

Mogus742 by L0 Member
  • 3334 Views
  • 1 replies
  • 0 Likes

critical severity default action alert

I am trying to understand the meaning of the default critical vulnerability action "Alert". This question was brought up by management who gets the PAN Content Update email and I want to give them an accurate answer. For example, Adobe Flash Player Memory Corruption ID 38112 is rated as critical and, as most critical vulnerabilities, the default...

Resolved! Baseline Procedure for DOS Prevention

Hello everyone,I was looking at setting up the DOS profile/protections on a PA-3020. I obviously need to baseline the traffic/system and was curious if there areany docs, Perhaps hidden, that would help me in this.Essentially I will need to grab stats. I realize Cacti can do this, but my customer does not have any available tools. : (thank you...

dbrenipc by L3 Networker
  • 4265 Views
  • 2 replies
  • 0 Likes

How do I create a browsing report thats easy for a CEO to read...

Hi,I have been tasked with creating a report out of our Palo Alto firewall that shows the following.For a period of 1 monthUsers Hours\Sessions on a websiteTop 20 visited websites.Top 20 Categories.We are using the user agent so all the data should be there, I can see some of it but getting this into a format that easy to read for a CEO?Can some...

tezza by L2 Linker
  • 4951 Views
  • 2 replies
  • 0 Likes

Trouble differentiating between malware already seen by WildFire and malware 'first seen' by WildFire

I'm having trouble determining which malware has already been seen by WildFire (therefore it was not re-sent for analysis and blocked by the FW) vs. a file that our organization sent to WF and was determined to be malicious after analysis (not seen before by WF) . This would significantly help our organization respond to malicious files that may...

r_gine by L1 Bithead
  • 4924 Views
  • 3 replies
  • 0 Likes

Resolved! Custom Button on URL Continue Response Page

Is it possible to create a custom button for the URL Continue Response Page? My customer is complaining that the Continue button that is part of the pan_form is too small and would like to create a larger one to use.

jwolach by L4 Transporter
  • 12845 Views
  • 8 replies
  • 0 Likes

Polycom can not answers a call

hi all.i have a problem with palo altl and polycom.When i make a call from inside to outside >> it okwhen a call from outside comming >> i can not answersi open all port, allow all application as: h.323, h.252, rtp...pls help me know why

dat.tran by L2 Linker
  • 8275 Views
  • 9 replies
  • 1 Likes

Import ssh key

Is there a way to import an ssh key into a firewall?For instance, I run the following commands:ssh-keygen -t rsa (The public key is now located in /home/demo/.ssh/id_rsa.pub The private key (identification) is now located in /home/demo/.ssh/id_rsa)ssh-copy-id user@myfirewallWhen I run the ssh-copy-id command, I asks me to login and I get this:Un...

QoS Guaranteed

Hi, I would like to book (guaranteed egress) 5Mbps for streaming in one of my vlan. My outide-Internet (egress) interface is eth1/1. The class for streaming is CLASS 1 (real time) right????whats the difference between "clear text traffic" and "tunneled traffic"??? Im using a PA2020, i can do QoS for limited bandwith and guarranteed in this model...

SOC_CSG by L4 Transporter
  • 4005 Views
  • 5 replies
  • 0 Likes

Resolved! ISP Failover Email Alert

Recently we configured ISP failover on two PA500s using PBF for the primary ISP and the virtual router for the backup ISP. We would like to setup some kind of email notification, or alert when this failover occurs. I've looked through the Admin Guide to try to figure out the best solution and the forums and haven't found a solution yet. What wou...

How to configure PAN to Azure VPN tunnel

I'm sure I'm not the first one to do this, but since I wasn't able to find a document on how exactly to do it, I figured I'd contribute one. I'd appreciate any corrections or optimizations.The Azure side documentation is pretty clear online and honestly there aren't many options available to configure. But here are is my Azure address space for ...

bjdraw by Not applicable
  • 14915 Views
  • 8 replies
  • 4 Likes

GlobalProtect Pre-Logon with Windows 8.1

I have been testing out a new GP portal/gateway on my firewalls for Pre-Logon/Always On as I would like to eventually like to move all remote workstations to this model. With that said, I notice when I enabled the pre-logon and SSO a new icon shows up on the logon screen which is confusing my users. Some click on it when logging in and others ...

nthen by L3 Networker
  • 4283 Views
  • 3 replies
  • 0 Likes

Resolved! Monitoring Accessed URL's

Hi Everyone,We have the URL filtering license, I am trying to log all websites that a user access, however, I noticed PA only logs websites which the user fails to access due to a URL filtering policy, ie only websites that are blocked from the user because they fall under a blocked category.Is there a way to log user access to all URL's.Thanks

rsaber by L1 Bithead
  • 6134 Views
  • 3 replies
  • 0 Likes

Resolved! Destination NAT of ESP and GRE

Hi all,I'm hoping somebody might be able to help with this unusual scenario please?I have been tasked with replacing an old linux based firewall with a PA-500 device.Initially the configuration of the PA-500 should just replicate what the current firewall is doing before we start phasing in the additional security capabilities of the Palo.The on...

DavePalo by L4 Transporter
  • 7486 Views
  • 3 replies
  • 0 Likes

Set time in report email scheduler

Hi,I think it´s a problem that we are not allowed to decide the time a report should be sent. According to support it´s automatically set at 2:am to releive the box of this burden during normal office hours. How Plao Alto knows every customer and their working hours is a mystery to me. And when trying to troubleshoot report delivery this becomes...

mgusta by L2 Linker
  • 2898 Views
  • 1 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels