General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! how do i remove a rule that was configured on PanOS via Panorama?

Hi,I have a problem deleting a rule that was created on PanOS via Panorama.I have PanOS firewall (5.0.0) that was managed by Panorama (5.0.0), then i added the PanOS to a DG and created some rules. after a while someone deleted the DG and committed to the Panorama.now i have a PanOS firewall with a DG rule that i can't remove. does someone know ...

Zorik by Not applicable
  • 4950 Views
  • 2 replies
  • 0 Likes

DNS TXT records, use and implications of blocking?

In the recent past my organization was hit with a relatively new DNS Amplification attack which uses a botnet hosting DNS services with a specifically crafted DNS TXT record. The spoofed requests specifically requested this record hosted on the botnet. After investigating I found articles online of the attack being used but with different TXT ...

Dz3015 by L4 Transporter
  • 4910 Views
  • 2 replies
  • 0 Likes

ssh (or any) threshold?

I'm experiencing a ton of hits over ssh to servers that must have ssh access. Is there a way to do threat assessment based on SSH, port etc – and then automatically shut the attack down? For example if a certain IP begins sending all that traffic on port 22 within a certain timeframe – we shutdown the traffic and blacklist the IP. What would ...

Regin detection

Hi All,I understand that this bit of spyware is not well understood as to it's ultimate purpose, very hard to detect and in fact, with the media converge it has had recently I am sure whoever coded this nasty has since changed it's code/behavior. But my question is, does or is PA able to detect any such traffic from this malicious code given tha...

JRussell by L3 Networker
  • 6286 Views
  • 8 replies
  • 0 Likes

Automatic backup - Palo Alto

I would like to know how to perform automatic backup of Palo Alto and automatically copy every morning for a server backup.Can you help me?best regards,Paul Aun

Can I get a entries of Unused Rules with no repeat count from Custom Report?

Hi guys,I have question about PaloAlto Custom Report. I can find that document for getting used rules with counter from customer report as How to Create Custom Report to Show The Least Used Rules in Security PoliciesBut Customer want to know exactly UNUSED RULES WITH COUNTER from custom report. Is it possible?Customer really want to have that cu...

Palo alto captive portal not display on google chrome

Hi,I'm having problem with our Palo Alto PA-500 do not display captive portal on google chrome.however if open use other browser it can display the portal.Do anyone know how to fix it?Because it just happen last one week, previously we do not have problem with it.Thank you.

Netmin by Not applicable
  • 8284 Views
  • 7 replies
  • 0 Likes

Palo alto Qos question

Hi all Qos question The maximum bandwidth 60 to 80 Mbpsand approximately 36 subnet Q1. As per the picture attached am i distributing the traffic properly or i am holding something from the total bandwidth Q2. If i want to give guarntted bandwidth for certain IP's how can i do that Thank you

sib2017 by L4 Transporter
  • 2356 Views
  • 2 replies
  • 0 Likes

Resolved! Unknown App-ID

I noticed from Taffic Logs there are some App-ID that couldn't be found in Object (non-syn-tcp and incomplete). Is there any resources we can look for more description?

yu_jie by Not applicable
  • 5459 Views
  • 5 replies
  • 0 Likes

Resolved! Global Protect "Server Certificate Verification Failed" Multiple Gateways

We are unable to get multiple gateways working correctly with Global Protect. When we have one portal and one gateway, clients are able to successfully connect and establish a VPN tunnel. With two gateways we get the following error from both the originally setup gateway and the gateway we are attempting to add: "Gateway x.x.x.x: Server Certif...

Resolved! Since upgrade globalprotect 2.1 certificate problems

Hi all,We experiencing a problem with the new version of Global Protect 2.1.We have PA 6.0.3. We use a 3th party as authenticaton manager. The problem appears with the certificate of the gateway : we use forthis certificate a wildcard signed certificate. All the gp clients upgraded to this version receive the following error : Gateway external_g...

Anyone using RANCID successfully with PANOS 6.x?

We have been using RANCID (panrancid) to conduct nightly off box backups of Panorama and PA5020s in versions prior to 6.x. After a successful deployment of PANOS 6.x RANCID backups fail consistently. Is anyone using RANCID successfully in PANOS 6?How did you get it to work?Debugging output fails with: End of run not foundpanrancid -d Alpha-502...

bobbarke by L0 Member
  • 4126 Views
  • 1 replies
  • 0 Likes

VOIP RINGING DELAY ISSUE

Hello world,I've the following problem after move a VOIP DMZ on PALO ALTO 2050 5.0.11:If I dial in from outside, then the answer is almost immediate, so that is fine, but when I call out the line is dead for 35-40 seconds before a ringing tone is heardI don't uderstand this delay? I try to do an application override but the issue stay. I can't s...

alle by L3 Networker
  • 8706 Views
  • 8 replies
  • 0 Likes
  • 24436 Posts
  • 125 Subscriptions
Top Solution Authors
Labels