General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4225 Views
  • 0 replies
  • 0 Likes

web crawling for google only

I know this topic has been discussed before but there is never a clear answer. It seems it is not possible to allow only specific web crawlers such as google. If that's the case, I assume most of you have web-crawling enabled for your site only? Google is still getting blocked from crawling our site. I was hesitant to enable web-crawling but it ...

bino150 by Not applicable
  • 4938 Views
  • 2 replies
  • 0 Likes

vcom-tunnel

Hi! We have a problem on the equipment pa-5020. when we look at the log traffic, the session ends with incomplete response Then I looked in and saw the following wireshark log. SYN - VCOM-tunnel Seq = 0 win = 8192 len = 0 mss = 1460 ws = 256 = 1 sack_perm=1ACK - VCOM-tunnel Seq = 0 ack=1 win=17920 len-0 mss=...

NTCUser by L1 Bithead
  • 7201 Views
  • 7 replies
  • 0 Likes

Resolved! How would I block social networking but allow a single Facebook page?

I have a URL filtering policy set to block the social networking category which of course includes Facebook. I need to allow the users that are assigned to this filtering policy access to a single Facebook page along with the pages that correspond to this single page. I tried the link below with no success and of course I tried to add the spec...

ClintL by L2 Linker
  • 11372 Views
  • 6 replies
  • 1 Likes

Resolved! What is HTTP OPTIONS Method

Hi,In our ACC I can see that the status bar is 3.7, thanks to the vulnerability HTTP OPTIONS Method. The problem is that I have no idea what this is and how I can fix this. How can I fix this problem?

ZEBIT by L3 Networker
  • 9368 Views
  • 3 replies
  • 1 Likes

Traffic from one zone to another

Hello. We have two virtual wires called 'eduroam' and 'live'. There are two zones linked to eduroam, namely 'eduroam_tr' and 'eduroam_untr'. There are also two zones linked to 'live', called 'live_tr' and 'live_untr'. We would like to allow communication of machines residing in 'live_tr' zone between a machine residing in 'eduroam_tr' zone. Do I...

shilpaal by L1 Bithead
  • 2874 Views
  • 3 replies
  • 0 Likes

There are drop counters when performance test

Hello,I am doing performance test with Breaking Point about throughput , CPS.While testing, I have found drop counters as below.session_dup_pkt_drop 701 3 drop session resource Duplicate packet: Applies only for multi-DP plat form with hardware (Tiger) broadcasting pkt to all DPsWhat does this mean???KC Lee

Moving/importing logs after HD failure

Hi.Recently, owing to an unplanned abrupt shutdown of my active firewall, I ended up with a hard drive corruption which prevented it from booting up (thank $deity for HA pairs).Quite apart from PA's *ridiculously* bad response time to replace the hard drive (which is being/will be discussed with my support partner, trust me), I need to know if a...

darren_g by L4 Transporter
  • 5575 Views
  • 10 replies
  • 1 Likes

Layer 2 vs. Layer 3 Deployment

Hi!At the moment, I hover between a Layer 2 and Layer 3 Deployment of my PA.My setup is: | | | | Internet <-> IPSEC-router <-> DMZ <-> internal firewall | | | | My IPSec-router-cluster and ...

Dynamic Roles vs. Role-based Panorama

Hi everyoneSo I was just wondering if anyone else has noticed a discrepancy between role-based and dynamic roles on their Panorama. I notice that "botnet" and "session browser" are not drop downs for my role-based admin role. That is fine since https://live.paloaltonetworks.com/docs/DOC-4172 goes to show they should not be there. However, when I...

jprice2 by Not applicable
  • 2551 Views
  • 1 replies
  • 0 Likes

Cisco to PA Access List Migration

Hello,I am in process of prepping a Palo Alto 5050 to replace a Cisco FWSM. I am doing most of the configuation on the PA by hand, but I was wondering if anyone knows how to best go about importing over 5000 Cisco access list lines into the Palo Alto, short of entering each one by hand? I understand that once they are in there there will need to...

mwhitlow by L0 Member
  • 4427 Views
  • 7 replies
  • 0 Likes

A lot of traffic on port 443 (https) to ip 65.52.98.231

Hello,I have a lot connections from my firewall to public IP addresses 65.52.98.231 port 443.Our SIEM correlated events and generating the following offense: Event Name: Excessive Firewall Accepts From Multiple Sources to a Single Destination Low Level Category: Firewall Permit Event Description: Excessive Firewall Accepts were...

SOC_CSG by L4 Transporter
  • 6547 Views
  • 3 replies
  • 1 Likes

Resolved! DCHP GLOBALPROTCTECT

Hi there. I wonder if it is possible to match an IP address with a MAC Address, this can be done in the normal DHCP in a public interface, but not if one GlobalProtect in DHCP can be made.

Axca by L0 Member
  • 4013 Views
  • 3 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels