Identifying files that were 'allowed' but are now known to be malicious
Wondering how others are tracking down files that were allowed through the firewall but later determined to be malicious (as a result of WF analysis)
Wondering how others are tracking down files that were allowed through the firewall but later determined to be malicious (as a result of WF analysis)
Hi guys, Is there anybody, who has PA-4020 with 6.1.x(perfect if it will be 6.1.5 🙂 )? I need some help.First, could you please execute a command:> show system environmentals thermaland share the output? Secondly, ask your box via snmp:snmpwalk -v2c -c COMMUNITY BOX-IP .1.3.6.1.2.1.99.1.1.1.4snmpwalk -v2c -c COMMUNITY BOX-IP .1.3.6.1.2.1.99....
My CISO want's to block known bad TLDs (such as .zip or .review) in our Palo. I know how to block specific url(s), but is there any way to block an entire TLD? I'm running into issues blocking *.zip since it will also block legitimate URL traffic that has *.zip* in its URL.
When I go to monitor reports and click a report- I can't select any date after July - I created a custom report and can report on information that way but the included reports don't seem to be working. Any suggestions?
Hello All,Quick question on the default behavior of QoS on the firewalls. Do interfaces on the firewall assume the QoS profile of "default" if I don't specify a QoS profile for the interface? The heart of my question is if I change the guarenteed and max values for the profile as well as class 4, would those values apply by default, or would I...
Could someone help me understand Difference between soft lifetime and hard life time in IPSEC VPN
I tried updating a PA3050 HA active/passive setup from 6.0.10 to 6.1 to eventually go to 7.The update works for both devices, everything seems to be working like it should, except for the tagged subinterfaces of the aggregated interfaces. They simply stopped working. They appear to be up, traffic seems to be allowed through them, but everything ...
I created a user account that so that the helpdesk can monitor the traffic and threate logs on the palo alto but not make any changes. But when I open up the traffic and threat detail instead of showing the exact IP address for the source and destination it show 95.10.147.0/24 and destination 136.176.56.0/24
What would cause traffic that is allowed through one rule to be denied by a rule below it. Shouldn't it just go through the rule allowing it and not even go any further.Odder even still is that traffic is not always denied sometimes it does pass through the rule it is allowed.
It seems that the cli command "set system setting ssl-decrypt skip-ssl-decrypt yes" doesn't work on PAN-OS 7.0.1. The decryption wouldn't temporarily disabled, nothing happens!? Has anyone the same problem?
Is there a way to set the blocking period for the block-ip action for a certain bruteforce vulnerability? From our logs this seems to be fixed at 5 minutes - I would like to set a longer blocking time for certain bruteforces going on. Thanks!
Hi,does globalprotect android app support autoconnect without the need to have a globalprotect mobile security manager ? Thanks
Hi, I have 3 domains in different locations (US, CN, TW) each one have its own User-ID agent.We deployed PA-3020 in each location and each one had set those 3 User-ID agents in the User-ID Agent configuration. If a user account belong to US and it login at CN, how does the PA appliance to get account information ? Does the PA in CN ask all 3 Use...
Hello,Does anyone else out there scan their firewalls with Nessus? Just curious if you have some other definitions defined other than what tenable has listed on their support site. I've tried google but its not helping much. Thanks in advance!
I don't know if anybody else has seen this, but we have safe search enforcement turned on (and I don't plan on turning it off) and Microsoft has moved all the clip art to Bing. When you try to add clip art from within MS Word and search for "cat" the search gets blocked at the PA and none of the thumbnails are returned. It makes sense because Wo...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 6 | |
| 6 | |
| 4 | |
| 3 |

