General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Opt-out page for HTTP ?

We would like to have a web response page that is presented to the user when the user launches their browser for the first time that asks them if they abide by the AUP rules. Basically same concept as the https opt-out page. Is this possible? If so,

...

Resolved! Can't clear session from CLI

Running PANOS 6.0.1. I can't seem to clear a session from the CLI. Just tested on a PA-500 running 6.0.0-b42 and I have the same problem.

Anyone knows if this is a bug?

admin@PA-vm> show session all filter destination 212.x.x.x

-------------------------

...

bdeschut by L4 Transporter
  • 8803 Views
  • 8 replies
  • 0 Likes

Disable an IPSec Tunnel

I want to disable an IPSec VPN. I have currently blocked traffic both directions to the tunnel by using a Security Policies, but there should be a way to disable the tunnel in the IPSec configuration (or alternatively, disable the tunnel interface).

...

blandis by Not applicable
  • 6624 Views
  • 5 replies
  • 0 Likes

Decryption: sec_error_reused_issuer_and_serial

Hey all,

I am having problems with decryption. The PA decrypts https websites, but when I surf to that website a few hours later, I receive the following error in firefox:

I haven't tried yet in IE or Chrome. I have this problem for various websites, n

...

bdeschut by L4 Transporter
  • 6380 Views
  • 9 replies
  • 0 Likes

Threats alert

Hello Team,

I have configured the panorama threat alert for one of our firewall and its working fine. Alerts has been configured for High and Critical .

we are getting so many alert from one IP (10.32.100.238) , one of vulnerabilities management device

...

tiwara by L3 Networker
  • 2324 Views
  • 2 replies
  • 0 Likes

EU - European Union

Is it possible to view the countries that are included in the "EU" object? When new countries are added to the EU, will this object be updated via dynamic updates or by upgrading?

Does anyone have experience with the accuracy of geo ip on palo alto?

Ki

...

bdeschut by L4 Transporter
  • 3471 Views
  • 2 replies
  • 0 Likes

Intermittent SSL decryption issues for some, not all.

My Palo Alto Firewall 2050 running 4.1.16.   I am having a lot of intermittent SSL decryption issues.  I'm not sure what to do with some of these.   An example is https://app.plangrid.com.    

I can this site when I have made this change and restart

...

EdwinD by L3 Networker
  • 3605 Views
  • 2 replies
  • 0 Likes

Resolved! ftp export log

Anyone know how to translate this show CLI command into the ftp export equivalent?

> show log traffic src in 10.0.0.0

> ftp export log traffic ?? (assuming query would work)

I would prefer not to export all logs only need a subset.

Thanks,

Monica

MLaden by Not applicable
  • 2615 Views
  • 2 replies
  • 0 Likes

Resolved! About a session generated by override rule

Hi guys,

A session generated by override rule that can be applied rematch session after commit configuration successfully? Or not? I guess that rematch session would not impact to session generated by application override rule.

Please let me know above

...

Resolved! Apply policy on a vwire interface in passtrough mode

I want to apply a policy on my vwire interface but i have this error:

Operation Commit
Result Failed

DetailsIn VSYS vsys1 from zone VW-MPLS-Trust of type vwire and to zone UNTRUST of type layer3 are incompatible in security rule Application bloc

...

dsevigny by Not applicable
  • 2294 Views
  • 2 replies
  • 0 Likes

Disable Inspection for Sip ?

In the ASA you can disable SIP Policy Inspection. In the Junipers I think you disable the ALG. How do I do this in the Palo Alto ?

Firewalls often try to apply rules around the way protocols work which can cause them to break. I dont want SIP to be in

...

jhickey by L3 Networker
  • 8785 Views
  • 6 replies
  • 0 Likes
  • 23579 Posts
  • 103 Subscriptions
Top Liked Authors
Labels