General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4473 Views
  • 0 replies
  • 0 Likes

Windows DNS Server behind PA

Did a PA install last night, the client had a public facing DNS server. the DNS server had a public IP before we moved it behind PA to nat it. while it was outside firewall with public IP the DNS queries from internet worked fine without any issues. Once we moved it behind PA and gave it static one-to-one nat with proper security policies for dn...

Wildfire options

Hey guys,As I'm sure most of us are, I'm seeing a huge string of issues related to Cryptolocker lately.I've reviewed the several articles floating around on how Palo Alto units deal with this, the fact is I'm seeing spam emails get through encouraging users to download executables which always come up as clean as far as PA's build in AV goes. Wi...

daraco by L0 Member
  • 3425 Views
  • 3 replies
  • 0 Likes

Resolved! how do i remove a rule that was configured on PanOS via Panorama?

Hi,I have a problem deleting a rule that was created on PanOS via Panorama.I have PanOS firewall (5.0.0) that was managed by Panorama (5.0.0), then i added the PanOS to a DG and created some rules. after a while someone deleted the DG and committed to the Panorama.now i have a PanOS firewall with a DG rule that i can't remove. does someone know ...

Zorik by Not applicable
  • 4862 Views
  • 2 replies
  • 0 Likes

DNS TXT records, use and implications of blocking?

In the recent past my organization was hit with a relatively new DNS Amplification attack which uses a botnet hosting DNS services with a specifically crafted DNS TXT record. The spoofed requests specifically requested this record hosted on the botnet. After investigating I found articles online of the attack being used but with different TXT ...

Dz3015 by L4 Transporter
  • 4742 Views
  • 2 replies
  • 0 Likes

ssh (or any) threshold?

I'm experiencing a ton of hits over ssh to servers that must have ssh access. Is there a way to do threat assessment based on SSH, port etc – and then automatically shut the attack down? For example if a certain IP begins sending all that traffic on port 22 within a certain timeframe – we shutdown the traffic and blacklist the IP. What would ...

Regin detection

Hi All,I understand that this bit of spyware is not well understood as to it's ultimate purpose, very hard to detect and in fact, with the media converge it has had recently I am sure whoever coded this nasty has since changed it's code/behavior. But my question is, does or is PA able to detect any such traffic from this malicious code given tha...

JRussell by L3 Networker
  • 6114 Views
  • 8 replies
  • 0 Likes

Automatic backup - Palo Alto

I would like to know how to perform automatic backup of Palo Alto and automatically copy every morning for a server backup.Can you help me?best regards,Paul Aun

Can I get a entries of Unused Rules with no repeat count from Custom Report?

Hi guys,I have question about PaloAlto Custom Report. I can find that document for getting used rules with counter from customer report as How to Create Custom Report to Show The Least Used Rules in Security PoliciesBut Customer want to know exactly UNUSED RULES WITH COUNTER from custom report. Is it possible?Customer really want to have that cu...

Palo alto captive portal not display on google chrome

Hi,I'm having problem with our Palo Alto PA-500 do not display captive portal on google chrome.however if open use other browser it can display the portal.Do anyone know how to fix it?Because it just happen last one week, previously we do not have problem with it.Thank you.

Netmin by Not applicable
  • 8036 Views
  • 7 replies
  • 0 Likes

Palo alto Qos question

Hi all Qos question The maximum bandwidth 60 to 80 Mbpsand approximately 36 subnet Q1. As per the picture attached am i distributing the traffic properly or i am holding something from the total bandwidth Q2. If i want to give guarntted bandwidth for certain IP's how can i do that Thank you

sib2017 by L4 Transporter
  • 2294 Views
  • 2 replies
  • 0 Likes

Resolved! Unknown App-ID

I noticed from Taffic Logs there are some App-ID that couldn't be found in Object (non-syn-tcp and incomplete). Is there any resources we can look for more description?

yu_jie by Not applicable
  • 5327 Views
  • 5 replies
  • 0 Likes

Resolved! Global Protect "Server Certificate Verification Failed" Multiple Gateways

We are unable to get multiple gateways working correctly with Global Protect. When we have one portal and one gateway, clients are able to successfully connect and establish a VPN tunnel. With two gateways we get the following error from both the originally setup gateway and the gateway we are attempting to add: "Gateway x.x.x.x: Server Certif...

Resolved! Since upgrade globalprotect 2.1 certificate problems

Hi all,We experiencing a problem with the new version of Global Protect 2.1.We have PA 6.0.3. We use a 3th party as authenticaton manager. The problem appears with the certificate of the gateway : we use forthis certificate a wildcard signed certificate. All the gp clients upgraded to this version receive the following error : Gateway external_g...

  • 24380 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels