General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

Resolved! Logging Question

We recently switched from a Cisco ASA 5520 to the PA3020.On the ASA, I could see a real time log of incoming and outgoing connections, blocked or allowed. This was a very handy tool to verify connectivity.I have been unable to locate a similar log in the Palo Alto. The traffic log is not through at all. It doesn't show all traffic. Is there ...

Grubbsy by L2 Linker
  • 3769 Views
  • 3 replies
  • 0 Likes

HA Failover moniring Management port

Hi, I have an active/passive HA setup and have link state monitoring enabled on my data interfaces, but I notice I can't select the management port for this. To my thinking, if I lose the management port I would want the cluster to fail over because it would no longer be able to log to Panorama, or to look up user IDs.How would you recommend d...

djr by L4 Transporter
  • 9071 Views
  • 9 replies
  • 0 Likes

Vulnerability in Schannel Could Allow Remote Code Execution MS14-066 - Critical

HelloSome bad news ... this time addressed to Windows Systemshttps://technet.microsoft.com/library/security/MS14-066and some news SChannelShenanigans - Pastebin.comAt the moment this volnureablity isnt covered by thread prevention. We must wait some time. Probably until tommorow because this is critical volnureability and PA last time very quicl...

_slv_ by L4 Transporter
  • 6546 Views
  • 7 replies
  • 0 Likes

url filtering blocked sites not redirecting

Hi Some blocked sites ( by url filtering ) not redirecting to the page " Web page Blocked " ,Instead it shows " The web page not available " . But some are redirecting to the page " Web page Blocked " as expected Please help Thank you

sib2017 by L4 Transporter
  • 6569 Views
  • 7 replies
  • 0 Likes

Terminal Services Agents Server 2012

How can I install a Terminal Services Agent on a 2012 Terminal Server(RDS)? I rolled one out yesterday and forgot to install the agent. The latest agent 5.0.6-17-64 will not install. Is there a work around?

Resolved! white listed web pages (url filtering )link broken

Hi allHi all I have a white list and all other categories are blocked .After applying seems some links are broken ( images and css loading from other urls , these urls are also added in white listWhatever urls found on the source are added in the white list .) and web page looking like defaced .How can i check what are the missing links ...

sib2017 by L4 Transporter
  • 5010 Views
  • 4 replies
  • 0 Likes

Ultrasurf Blocking Fail

Hi,I am suferring from many failed attempts trying to block ultrasurf. i added the application to a deny policy on the top of my policies, but users keeps jumping to the allow policy. i tried to block unkown UDP/TCP apps, but it failed too. the applcation itself can't be blocked even though i blocked all the dependecies. i tried to do it on 5050...

Mohammad by Not applicable
  • 18026 Views
  • 30 replies
  • 2 Likes

Who's using an MSSP for security monitoring?

We have a need for 24x7 monitoring, so I wanted to explore partnering with an MSSP vs. setting up our own SOC. Anyone have experiences to share?We'll probably start discussion with one of these partners, but wanted to get feedback first:https://www.paloaltonetworks.com/partners/managed-security-services-provider.html

RyanF by L2 Linker
  • 5185 Views
  • 3 replies
  • 0 Likes

Sipvicious.Gen User-Agent Traffic

Hello everyone,This is my first post here. So i started a new job couple months ago and we have a PA 3050 . The daily reports is showing Sipvicious.Gen User-Agent Traffic coming from IP's all over the world. Any ideas?Thanks

Resolved! Global Protect

Does global protect log the user off automatically if the session is inactive? Also I was able to login without using any credentials, is that suppose to happen?

infotech by L4 Transporter
  • 4617 Views
  • 4 replies
  • 0 Likes

Resolved! FQDN Address Objects Not Resolving - PANOS 6

I have a few different clients with the same issue.I have some FQDN address objects and I assign a TAG to each of those objects. Then I create a Dynamic address object group which contains address objects with that tag. Then I add the dynamic group to a policy.Traffic is not matching on that policy; it is matching on explicit deny rule.If I run ...

SDorsey by L4 Transporter
  • 5436 Views
  • 7 replies
  • 0 Likes

PBR Monitoring

Hi,In Forwarding tab under PBR forwarding rule, what interface usually Ping or monitor the IP Address in Monitor option?Thanks,MBS

Resolved! wildfire-upload-fail

Looking to find out more about wildfire-upload-fail. Has anyone had any of these and if so were you able to determine the root cause?

lewis by L4 Transporter
  • 9901 Views
  • 13 replies
  • 0 Likes

UserID connecting-disconnecting

Hi, im having problem accesing to my PA (i think because of UserID). If i try with local user its ok but with my LDAP user is not working. The users cant access via VPN neither.I can see a lot of events about "connect-agent" and suddenly "disconnect-agent".........¿¿why this strange behaviour?Nov 11 10:57:48 Warning: pan_to_ms_conn_tcp_channel_s...

SOC_CSG by L4 Transporter
  • 9626 Views
  • 12 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels