General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4139 Views
  • 0 replies
  • 0 Likes

Time stamp of traffic/threat/url logs are 3 minutes into the future?

Threat logs, traffic logs, url filtering logs are all in the future by 3-4 minutes where everything else has the correct time from the ntp server. The dashboard shows the correct time and what's interesting is that the Configuration and System logs show the correct time (same one as in Dashboard - General Information) yet as you can see the Logs...

zbierskik by Not applicable
  • 2683 Views
  • 1 replies
  • 0 Likes

Resolved! Data plane User-ID mappings empty

We currently have a pair 5020s using LDAP for User-ID - up until about a week ago it was working.I can see in the logs that the mappings are taking place, and the management plane mappings are there, however the data plane table is empty.This is causing drops on policies which have User-ID as a stipulation.Any ideas?

VPN Tunnel between static Palo Alto and dynamic Fortigate

What is the exact settings in order to establish a VPN tunnel between a Palo Alto firewall that has static WAN IP address and a Fortigate that has Dynamic WAN IP address?If both has static IP address, the tunnel works.If Fortigate has dynamic WAN address, I cannot get the VPN working. I tried aggressive mode on both sides. Palo Alto log keeps ...

Not understanding "WildFire: Automatically Detect and Prevent Unknown Threats"

First of all I'm very impressed with Palo Alto's firewall, I'm definitely a "fan", however we purchased a wildfire subscription under this premise:WildFireTM simplifies an organization’s response to the most dangerous threats, automatically detecting unknown malware and quickly preventing threats before an enterprise is compromised. Unlike legac...

HIPmatch IP?

Palo currently emails me the hipmatch alert and includes the internal IP that globalprotect assigned it. How do I get the public IP that the user came from in the hipmatch alert email?I know I can manually find it via the interface (which shows both the internal and external IP for users) but since hipmatch is emailing the internal IP field, how...

ulti by L3 Networker
  • 2152 Views
  • 2 replies
  • 0 Likes

Resolved! Captive Portal logs

HelloDoes anybody know how can I get some logs to check how many times a specific user was authenticated via Captive Portal?Is it possible ?Thanks in advance!!!

Resolved! Wildfire cannot test some Word docs - unsupported file type

Greetings all!I have discovered WF is not able to test some Word docs; it gives the following error:Unsupported file type: HTML document, ASCII text, with CRLF line terminatorsHowever, I am able to open these Word docs within a VM. They contain malicious macros and they are in tact. Has anyone else run into this? I haven't dug deeply yet but am ...

SDorsey by L4 Transporter
  • 8153 Views
  • 4 replies
  • 0 Likes

Resolved! Vulnerability - disable event log

Hi,I would like to get rid of events created by specific Vulnerability signature. Is this possible somehow?Thank you for any suggestions!BR radek

radp by L1 Bithead
  • 3716 Views
  • 1 replies
  • 0 Likes

Traps and Antivirus

Hi All,Looking at the Traps solution and wanted to know if the solution allows for a replacement of Antivirus or does it supplement one? I don't really want tot have to support multiple services and agents on all the devices so i was hoping for the former?

bcsgroup by L2 Linker
  • 2881 Views
  • 2 replies
  • 0 Likes

we are not getting URL in syslogs, is there any way to URL in syslogs?

<190>Mar 31 08:52:56 XXXX-firewall-name 1,2015/03/31 08:52:55,001606005137,TRAFFIC,end,1,2015/03/31 08:52:55,source_ip,,destination_ip,trust-untrust-web-services,,,paloalto-wildfire-cloud,vsys1,trust,untrust,ethernet1/1,ethernet1/3,Log_Forward,2015/03/31 08:52:55,57030,1,42349,443,45974,443,0x400053,tcp,allow,2319,1200,1119,20,2015/03/31 0...

Category explanations

I'm working to identify a few categories and what they mean. I looked in the online help and all it did was list the categories. Is there a document that gives more information about what content filtering categories are for? Specifically i'm trying to find out the difference between unknown and not-resolved? How are they used in PA?

240GB Raid SSD Upgrade

Hey guys, we are upgrading our PA-5050s drives from a single 120GB SSD to two 240GB SSDs and I was wondering how long this will take? I assume it will be pretty quick since we are installing two identical fresh 240GB drives but I wasn't sure how long it takes to build the raid and bootup after this. I can't find much in the install docs and I am...

  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels