General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4113 Views
  • 0 replies
  • 0 Likes

URL Filtering Log show Action block-url

my palo alto I see url-filtering log---in columns action show block-url---in columns rule not showand I don't add url-filtering profile to all security rulewhy url-filtering show action block-urlhelp me pls.PA5020 PanOS5.0.12PAN-DB

BaNk by L1 Bithead
  • 9725 Views
  • 3 replies
  • 0 Likes

Default threat ID correlation for action

Hi all,I was searching for a while and could not find the answer to this question.By default, does a Palo Alto block every instance a threat ID (that is enabled) is seen or does it wait until 1 threat ID hits 5 times in 1 minute (for example).I would think it would be the former, but was searching for confirmation.Thanks

Xbox Live with dynamic public IP

I know that this topic has been discussed before, but I cannot seem to find an exact scenario match since I am dealing with a dynamic public IP address.Interfacesethernet1/1Primary internal networkDefault virtual router172.16.50.1/24Zone: Internalethernet1/2Public internet connection with dynamic IP addressDefault virtual routerZone: Externaleth...

swoods79 by L1 Bithead
  • 7098 Views
  • 7 replies
  • 0 Likes

forward connectivity

Hi friends,How to forward connectivity when our VPN connectivity down or leasedline down.RegardsSatish

Satish by L4 Transporter
  • 1853 Views
  • 1 replies
  • 0 Likes

Resolved! CryptoWall??

I did a search for this... came up w/nada. Has there been any convo about CryptoWall? Has PA addressed it?thanks//moe

Resolved! How do I find out every place an object is used?

Does anyone know a good way to find out everywhere an object is used?What security and NAT rules is it in?What address groups is it in?What are the rules the address groups the object is in used?It would be great if there were an easy way to this.

Demast by L2 Linker
  • 13345 Views
  • 8 replies
  • 1 Likes

Troubleshooting tools

I am new to firewalls and new to PA so I really need to find some tools and technique to be able to troubleshoot issues on my PA

infotech by L4 Transporter
  • 24650 Views
  • 7 replies
  • 0 Likes

Statistics Service Setup

Hi,When we check "Unknown categories by URLs" will this option help Pan-DB and Brightcloud to be updated their databese (for unknown urls) related to which we use ? Or just one ? Or none of them ? Thanks.

Doubt about security rule

Hi,I have to create a rule bidireccional between two of my servers. My question is, do i have to create two rules to allow the connection in both flows, or i could only create the rule TRUST TO DMZ and the way back would be permit too?Its a bit tricky 2 rule for one connection, no???thanks

SOC_CSG by L4 Transporter
  • 1861 Views
  • 1 replies
  • 0 Likes

Resolved! security rule add web

Hi, i have to create a rule to permit my ubuntu server to take updates from es.archive.ubuntu.com and security.ubuntu.com. How can i create the rule for this two webs suing dns name?? the ips are changing so i cant use the web ips in destination........thanks....

SOC_CSG by L4 Transporter
  • 3017 Views
  • 2 replies
  • 0 Likes

Rate limit port forwards

Hey guys,Some of the iptables servers I'm replacing with Palo Alto firewall provide port forwards to RDP servers. In order to prevent abuse, they were rate limited, such that a single IP can only connect a few times before being blacklisted for a few minutes.This functionality existed within IP tables - is there a way to replicate this within a ...

daraco by L0 Member
  • 2026 Views
  • 1 replies
  • 0 Likes

ldap user authentication in security policy not working

i have configured ldap server profile with "base=" and "basedn=ldap string " and domain= blank.in group mapping under available groups only groups are there and no users can be viewed. i have included two groups here. which is added in security policy rule under user option.In authentication profile i have added above included ldap groups in a...

Resolved! Recommended cable length for HA

I'm unable to determine from the tech-docs if PAN has a recommended (or suggested) cable length for those cases where the HA ports are directly connected via crossover cable. Does anyone have any intel on this topic? I've set-up many HA pairs and when using directly-connected HA ports via crossover I typically use a 6' cable. I'm working at a pl...

tommyluke by Not applicable
  • 6207 Views
  • 5 replies
  • 0 Likes
  • 24333 Posts
  • 124 Subscriptions
Top Solution Authors
Labels