General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! tcp/dynamic port range

I'm looking for a definitive answer on what port range "tcp/dynamic" and "udp/dynamic" uses. I would figure that it is 49152-65535, but I have not been able to locate anything in documentation or the community to confirm this.

Exclude www.google.* from decryption

Hello,are you able to exculde https://www.google.com ; https://www.google.de and other domains from SSL decryption?Or clients complain about the slow loading of the website when they open Google or try to search something.Currently i add in a white custom URL category:www.google.comwww.google.com/www.google.com/*www.google.*www.google.*/www.goog...

Hithead by L4 Transporter
  • 12201 Views
  • 17 replies
  • 0 Likes

High availability Links on different locations

Hi, we have 2 PA1410 on two different buildings. They act in an active-passive cluster. On each location is a switch, and the Firewall ist connected with all of its port (ha1a, ha1b, ha2, MGM, Data) to the switch. The switches are connected though a glasfiber to each other. Does it make sense, to buy a fiber sfp transceiver for each firewall and...

IT-Esp by L1 Bithead
  • 2787 Views
  • 3 replies
  • 0 Likes

Beaon PCNSE study guide - practise questions

Hi Guys did one of the prep exams and had a couple of questions marked wrong.. but not sure they were.. any ideas? Q1 GlobalProtect clientless VPN provides secure remote access to web applications that use which three technologies? (Choose three.) RubyHTMLHTML5PythonJavaScript (my selection in bold above) from PA DOCS they note this...

PA_nts by L4 Transporter
  • 2110 Views
  • 2 replies
  • 0 Likes

Cortex XDR service causing maxed out CPU and memory spikes on DCs

We are getting constant alerts from our monitoring system that out DCs are constantly having maxed out CPU and memory spikes. On every alert cyserver.exe is the top resource user. Cortex XDR Service 8.4.0.51691 Domain Controlers are all Windows Server 2019 VMs 4 Cores and 24GB of memory Does anyone have an idea on this? What might be the cause?

Resolved! Install the Cortex XDR Agent Using Msiexec

Hi Team, we need to install the agent using Msiexec, kindly provide the steps, and also, we have followed the below-mentioned command, but we didn't get the expected result. msiexec /i c:\Windows_agent_8_4_x64.msi /l*v C:\temp\cortexxdrinstall.log /qn

Resolved! How could i drop"unknown RADIUS authentication protocol"?

Hi! Recently we were receiving in our environment alerts of failed authentications from different random IP's and random usernames, i was able to reduce them following the next article: Detecting Brute Force Attack on GlobalProtect Portal Page - Knowledge Base - Palo Alto Networks, and creating a dynamic list, adding tags with forward logs, drop...

RTudon_0-1717363128954.png
R.Tudon by L1 Bithead
  • 2991 Views
  • 3 replies
  • 0 Likes

PA-410 Firewall not fetching dynamic and software updates

We have a customer who is not able to fetch software version and dynamic updates In CLI, we checked reachability to updates.paloaltonetworks.com, and we are able to reach and also updates.paloaltonetworks.com address is getting resolved we then restarted the management server from CLI still no luck . we then manually added the dynamic updates ...

Resolved! Zoom phone custom signature thru: ssl-req-chello-sni

Hi everyone! We are currently moving our phone system to zoom, and we had an issue with the zoom application, some of their traffic its categorized as an incomplete causing that some calls hang out, or don't ring, I made an custom application, using the signature ssl-req-chello-sni and pasting the complete server's name that was registred in t...

R.Tudon by L1 Bithead
  • 2882 Views
  • 1 replies
  • 0 Likes

Missing information on ACC

The ACC tab on Panorama shows inconsistent information about traffic, even though logging profiles on the managed firewalls is correct and send all traffic and threat logs to Panorama. Panorama ACC seems to only show "sactioned" applications, missing all other details. The ACC on the managed firewalls is accurate.This problem started with PAN-OS...

Senibo by L1 Bithead
  • 1364 Views
  • 1 replies
  • 0 Likes

Resolved! Same Mac address shared by two paloalto firewalls

Hi, I have seen strange behaviour between two palo alto firewalls. I have pair of PA-3020 and Pair of PA-500 in Active/standby scenario. They serve two different networks but to provide interconnect between two networks they (Eth 1/3) are connected to Cisco Nexus switch via FEX (VLAN 129). Has anyone seen a case where two different models of th...

DCN by Not applicable
  • 12876 Views
  • 4 replies
  • 0 Likes

Block scanning from shodan

Hello, Anyone have successfully block scanning from shodan.io? www.shodan.io ? It looks like Checkpoint has written specific signature to block shodan scanning, http://blog.checkpoint.com/2016/01/04/check-point-threat-alert-shodan/ -E

Delete Shared Objects in Panorama

Hi. I want Delete Shared Objects in Panorama Pusht to Panorama ↓↓↓↓ Equipment A and B do not have their addresses registered in the shared policy. It keeps bringing up addresses and service information from other firewalls. I want to delete the shared policy without using the push changes made function. The panorama software versi...

DFA.png
제목 없음.png
캡처.PNG
qmso475 by L3 Networker
  • 4226 Views
  • 2 replies
  • 1 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels