General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! Decryption Policy - Blocking things such as Facebook

We recently discovered that due to Facebook now being https:// that my users can get out to Facebook when using Internet Explorer. This actually cause quite an issue due to a bug also getting in. How do I configure the decryption policy to get in to the session and block the traffic? From what I'm reading I have to configure this to block http...

kaysun by L1 Bithead
  • 2952 Views
  • 2 replies
  • 0 Likes

BrightCloud® Real-Time Anti-Phishing Service

Does anyone know if the BrightCloud® Real-Time Anti-Phishing Service works with Palo Alto NGFW's? (with the correct license of course?)BrightCloud Real-Time Anti-Phishing Service | Webroot BrightCloud

Smi12 by L2 Linker
  • 4041 Views
  • 3 replies
  • 0 Likes

Resolved! Suspicious DNS Query Pan-DB and BrightCloud

We are using the BrightCloud URL DB for URL Filtering. Last week we had discovered an issue that users can’t access the URL http(s)://www.haalmeeruitjecard.nl Searching the PaloAlto we see that is not blocked by the URL Log. BrightCloud says as URL Category “business-and-economy” and that is allowed.Still the session can’t be setup and we did no...

obor by L1 Bithead
  • 4552 Views
  • 4 replies
  • 0 Likes

high management CPU

Hi,my PA500 management CPU is 100%PAN OS release 5.0.2 (same problem with 5.0.1)If I reboot the firewall, management CPU usage goes down for some days than raise again to 100%

diennea by L3 Networker
  • 13492 Views
  • 13 replies
  • 0 Likes

Schedule a management restart

Hi,regarding GUI slowness I've a question:a lot of people suggest to restart management server.How can I schedule a night restart of it?Thanksregards

diennea by L3 Networker
  • 9948 Views
  • 13 replies
  • 0 Likes

6.0.2 Upgrade on 2050

I recently upgraded code to 6.0.2 on a 2050 and am experiencing significant packet drop issues (network becomes inaccessible). It is resolved when you reboot the device, but it only is resolved for about a day, and then goes back to dropping traffic, has anyone else experienced this or knows of a solution? (I also have a case open regarding th...

Wildfire Email Alerts

Hopefully quick one..We used to get these alerts directly from the Wildfire cloud, but they have stopped (for a few months actually, I've only just got round to looking into it) - is this normal?We do get the email alerts setup via the logging mechanism from the FW itself, but these do not contain all of the Wildfire specific information:-Cheers

apackard by L4 Transporter
  • 3994 Views
  • 5 replies
  • 0 Likes

Global Protect Client SSO issue with AD group policy.

I am setting up Global Protect and trying to use Single Sign on, but with machines on my domain that have group policy provided, when the the domain id logs in, the global protect client prompts, if i use another machine that does not have group policy applied to it, it works fine.I have found this link, but I am stuck. Any help would be apprec...

markk96 by L3 Networker
  • 1957 Views
  • 1 replies
  • 0 Likes

Abnormal system memory usage detected, restarting ha_agent with virtual memory 3607332 KB.

I received a critical event in the system log with the error message "Abnormal system memory usage detected, restarting ha_agent with virtual memory 3607332 KB." After that, our ha active-active pair ran into a non-functional state:- the active-primary machine thinks that active-secondary is down. it continues work as remaining cluster machine.-...

Microsoft Lync 2010 - 2013

Has anyone rolled out MS Lync 2010 servers in your network and worked out the policies & rules for the Lync traffic. If so would someone be willing to share the details. I am very new to the PANOS and i do not want to create security risk.Thank you in advance,PlanoGuy

Resolved! How to block dodge chrome?

Hi.. allDo you know "dodge chrome"?This is bypass the url filtering by the modified google chrome.(http method : get \r\n )I do not find the related signature in palo alto applipdia.(app-id , ips , virus)How to block dodge chrome?

wooki by L1 Bithead
  • 4646 Views
  • 4 replies
  • 0 Likes

Trouble getting User-ID from MS Radius (NPS) using script

I am part-way in matching up IP addresses and user names, but struggling with the second......I'll explain.In our lab we have a PA5020, and I am running the User-ID agent on a VM close to the firewall. It successfull reads the AD credentials etc, and those users who authenticate with AD are showing correct names against their IP addresses The t...

how to work decryption policy?

Hi.. all,how are you today ? any one please describe about decryption policy and how log bits (0-2048) support? :smileyinfo:Thanks Satish

Satish by L4 Transporter
  • 7433 Views
  • 7 replies
  • 0 Likes

Resolved! CryptoLocker Reporting

I realize that as of me writing this, PA has ~123 variants of *.crilock.* registered. Is there a way to report on vulnerabilities by name rather than ID? It would be nice to be able to publish a report saying, "Our PA stopped CryptoLocker this many times" without having to build a custom report with 123 different threat IDs.

mrsold by Not applicable
  • 3011 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels