General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

FTP passive mode issue

Hello All,I was read somewhere on this forum similar article from October 2014, and seem that problem with passive ftp was on new content ID. However some time passed since, I have issue with ftp passive mode on my VM-100 (panos 6.0.5, content ver. 483-2549..). I catch traffic with pcap on pan directly (all stages) and noticed that had drop stag...

Tician by L3 Networker
  • 10792 Views
  • 3 replies
  • 0 Likes

Resolved! URL Whitelist Nightmare

I've tried without luck to add the URL 'addons.mozilla.org' to a whitelist. This URL falls under the 'shareware-and-freeware' category. This category is blocked. That's why I need to specify this explicitly in the whitelist. It just won't work. My monitor tab shows it is allowed for that traffic, but looking at logs for URL filtering, I see it b...

Bocsa by L3 Networker
  • 8110 Views
  • 10 replies
  • 0 Likes

Zero-day vulnerability in Adobe Flash, CVE-2015-0313

Vulnerability Coverage:Wildfire AV - WF 52532 (today) (PAN-OS 5.0+), and AV 1478 (tomorrow). Virus/Win32.CVE-2015-0313.a IPS Signature- Planning to release with 2/3 IPS signature releaseURLs associated with Malicious SWF samples:Malicious domains added to PAN-DB/malware already (PAN-OS 5.0 +) CnC/Spyware:Malicious DNS signatures added for domain...

Enabling forward trust certificate

Hi all, I'm hoping someone can assist. I can't enable the Forward Trust option for a cert that I generate using either a self-signed CA or 3rd party CA. The check is either greyed out or it's an option but doesn't keep the check after I hit OK. Any idea on how to get this working?Thanks!

Resolved! Error upgrading ESM to 3.1.3

Greetings all-I am trying to upgrade an ESM server from 3.1.2 to 3.1.3. When I run the installer, I get the below error message. I have ensured to run it as administrator. I have even tried disabling UAC, removing the AV agent and rebooting.Thoughts?

SDorsey by L4 Transporter
  • 3101 Views
  • 1 replies
  • 0 Likes

UniDirectional Link Failure Detection without UDLD

Hi,Does anyone know the network appliance could detect uni-directional link failure of SFP+ without UDLD?I tried the test with PA-5060 and Juniper-EX,but SFP+s kept link-up cause TX might continue to shot laser when RX came not to receive laser from peer.I though it is general problem as SFP+ and UDLD has been defined.But our customer said it co...

komure by Not applicable
  • 4252 Views
  • 1 replies
  • 0 Likes

Blocking Facebook apps without ssl policy

We are trying to let users to have read-only access to Facebook' but not allow them do posting or download anything from it. We don't have SSL policy. Can you block Facebook posting with you SSL policy decrypt traffic?Thank you

awarsame by L1 Bithead
  • 3508 Views
  • 2 replies
  • 0 Likes

URL filtering Profile - URL in allow list does not work.

Hello,PAN-OS 5.08I have a security police to which applied a URL filtering Profile.I have blocked the category "social-networking" and I need to allow "twitter.com"I tried putting the URL in allow List: *.twitter.com *.twitter.com/*www.twitter.comBut it does not work.I have also tried creating a Custom URL Category but neither works.How can I do...

SOC_CSG by L4 Transporter
  • 4393 Views
  • 3 replies
  • 0 Likes

Install GlobalProtect

Hi! I have problem with installing GlobalProtect in our environment. We are using System Center2012 to to install the GlobalProtect64.msi with installation behavior “Install for user” butthe problem is that it only creates StartMenu ico for that user. The next userthat logs in can’t find GlobalProtect in the start menu. The next user can’t see...

unygren by Not applicable
  • 5622 Views
  • 4 replies
  • 0 Likes

Active/Active performance benefit/impact

Hi,Anybody currently using or having had tested HA in an active/active mode with any insights into the the performance benefit or impact of such a setup?Is the additional complexity worth the effort and is the throughput effectively increased compared to active/passive?Any info or advice would be appreciated!

Resolved! TFTP file transfer on New Palo Alto PA500 Firewall

Hi Guys,I have already my files on working tftp server and already connected via serial cable to the firewall. As i know i should also connect one end of patch cord to my PCs ethernet intrface and the other end to the firewall interface, but to with one mgt? or the basic ones?how can i set up the ip address and the gateway from the CLI? and also...

Resolved! How to monitor pending commits

I'm looking for a way to externally check that there are no policy commits pending.Is there an SNMP OID signalling a commit is pending?Or, is there a SSH CLI command that shows a commit is pending?I'm running a PA-3020 with PANOS 5.0.15.

Resolved! User-Id Agent log file behavior

Hello,I have been running user-id agent in an environment and the log file size is increasing rapidly.Is there a limit for the file size? and what will happen when the file reaches the limit?In general, what is the best way to control its size?

  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels