General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

App downloading issue for wi-fi mobile users

Dear Friends,Need your suggestion for below issue.PAN OS 6.0.9Unable to download app from play store thru mobile.There have wi-fi environment, when mobile (smart phone ) users connected thrue wi-fi, he is able to browse internet but not able to download any app from google play store. security policy like source wi-fi zone destination untrust a...

Satish by L4 Transporter
  • 6234 Views
  • 8 replies
  • 0 Likes

Is possible create a custom admin role with a specific filter?

This question is for administration of PANORAMA and PALOALTO.I want to know, if is possible to create a custom admin role with a specific filter. For example, If I make a admin role for vsys or device group and check Monitor-Logs-Threats I want to that the users of this role only can view the logs of virus and wildfire, and the other threats the...

aromero by L1 Bithead
  • 3735 Views
  • 2 replies
  • 0 Likes

how to block UNKNOWN url category

how to block UNKNOWN url category on PA 5050.tddmwwnnowxo.com is unknow url category so PA URL DB allowed into my network. How to block unknown category.If we block unknown category will it affect any new urls which is not register in PA URL DB

KMallela by L2 Linker
  • 3832 Views
  • 2 replies
  • 0 Likes

DNS Proxy

Hi,Can someone post and example of how they set up their dns proxy?

Ifsnbpt1 by L0 Member
  • 5901 Views
  • 7 replies
  • 0 Likes

How can I be notified of failed hardware via email, snmp or syslog?

Hello everyone,We have experienced a FAN failure on our PA-500 and had the red led for the fan and a red fault led (but no idea for how long) - As we wasn't notified of this hardware failure. So my question is how can I set the Palo up to notify me of hardware issues either via Email, SNMP or syslog or all 3. Can some let me know how I could se...

Can I block files by signature?

I had a client ask if I could block files by hash. Without additional information -- such as what protocol, application, host, user-agent, etc. -- it wouldn't be possible to do this with a threat signature, so how else could it be done?Cheers,Coreymlutgen Brad Spilde

Resolved! Panorama doubts.

It is possible to edit a rule placed on the firewall through the panorama, because I can not edit rules coming panorama, directly on the firewall.

How to drop new SSL sessions when limit is reached in 6.1.X?

We'd like to drop any new SSL sessions if the system has reached the SSL Decrypted Session Limit.This page, How to Implement and Test SSL Decryption, says to run:> set deviceconfig setting ssl-decrypt deny-setup-failure yesbut it doesn't seem to be there in version 6.1.4In the Web UI, there is an option under when creating a Decryption Profil...

eugenep by L3 Networker
  • 3999 Views
  • 4 replies
  • 0 Likes

How to Avoid Remote SSH Scan

HelloI have a lot of events "deny" followed by other "allow"; All of these to port 22 (SSH) from remote host to several IP(s) in my Untrust and DMZ Zone.<14>Jun 24 04:01:17 fw2orgt 1,2015/06/24 04:01:16,0003C102047,TRAFFIC,drop,0,2015/06/24 04:01:16,46.228.199.253,213.0.58.124,0.0.0.0,0.0.0.0,rule76,,,not-applicable,vsys1,Untrust,Untrust,e...

SOC_CSG by L4 Transporter
  • 4370 Views
  • 1 replies
  • 0 Likes

Local user passwords problems with GP after upgrade PAN OS

Hi, I've just migrate from PAN OS 5.0.10 to 6.0.7 and GlobalProtect users have got problems with login. They had the password saved on their GP agent, but connection was refused and users were blocked due to intensive login attempts. We're using local users. It seems like users who couln't login are those with same string as user and password. I...

ACortes by L2 Linker
  • 2956 Views
  • 3 replies
  • 0 Likes

Resolved! Reset an interface to initial state of Not configured

Hi,just starting up with my first PaloAlto device, and have a simple question for which I don't seem to find a solution in the documentation. By default, the interfaces of a new firewall are are unconfigured, i.e. the GUI shows their status as "not configured and down". However, if any change of config is made, it seems to be impossible to get t...

itsup by L2 Linker
  • 11218 Views
  • 5 replies
  • 0 Likes

Resolved! ECMP

Hi - is it possible to do ECMP (equal cost multi-path routing) using static routes? If not - is it possible to achieve ECMP using OSPF on the PA4050. We have a need to load balance the default route out of a PA4050 over multiple L3 gig interfaces (the customers current solution support ECMP with static routes). Many thanks.

fmd by L3 Networker
  • 7056 Views
  • 6 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels