General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 

 

In the past six

...

survey-livecommunity.png
jforsythe by Community Team Member
  • 14575 Views
  • 1 replies
  • 4 Likes

Resolved! How to force Panorama to push out new configs in serial?

One of the admins mumbled today that when changing shared objects in Panorama and pushing out new configs he needed to do this one by one regarding managed devices.

That is click on sync, wait until the text "out of sync" changes to "ok" (or whatever

...

mikand by L6 Presenter
  • 733 Views
  • 1 replies
  • 0 Likes

Resolved! How to get friendly name of a vsys into the syslogs?

I have followed the order described in to create a custom log format for use by a syslogserver which is much more happy of getting the logs with spacesas delimiter instead of the commas.

However I noticed that the $vsys variable only gives out text l

...

mikand by L6 Presenter
  • 933 Views
  • 1 replies
  • 0 Likes

Stretching L2 VLAN's over IPSec tunnel

Hi All,

I am facing a nasty situation where i need to connect two sites together using an IPSec tunnel over the internet. The nasty part is where both sites have a VLAN that needs to be interconnected.. both in the same subnet. I am wondering if it is

...

bsanders by L2 Linker
  • 3491 Views
  • 4 replies
  • 0 Likes

Update Software on HA passive mode

I try to update software and GlobalProtect  on my PA configurated on HA Passive mode but it´s impossible. "Failed to check upgrade info due to generic communication error. Please check network conectivity and try again" :-S

I download de software on w

...

cmadurga by L0 Member
  • 730 Views
  • 1 replies
  • 0 Likes

Policy allowing ping/snmp not performing as expected

I have a policy which allows icmp / ping / snmp-base / snmpv1 / snmpv2 however when I review the logs the traffic which matches this policy is being caught in a lower policy that is more general (and we are trying to get rid of). Someone told me that

...

Resolved! Traffic log CSV Export Bytes Column

Hello everybody,

Software Version 3.0.5

when we make an CSV export for the traffic logs,
we have three columns with Bytes, called

- Bytes
- Bytes Send
- Bytes Received

All three columns have for the same row the same Byte values.
So, what is it for!

I thought

...

indevis by L2 Linker
  • 2585 Views
  • 7 replies
  • 0 Likes

Resolved! Vulnerability Protection - Exceptions?

Dear all,

We've got one, okay, two little questions on the configuration of vulnerability protection:

Assuming we have a security policy configured with the pre-defined vulnerability protection profile named "strict". From that policy we're getting "LD

...

oschuler by L4 Transporter
  • 2298 Views
  • 4 replies
  • 0 Likes

Resolved! Reports - Best way to see top URLs visited?

I'm struggling a little with the documentation on how to generate useful reports.

If I look in the ACC or default reports I can see destinations but they are simply a mix of raw hostname and rdns lookups - they might show a lot of traffic to, say, a88

...

SSL Weak CBC Mode Vulnerability

Our box was scanned by Qualys and the SSL VPN portal cames up with the following message:

If possible, upgrade to TLS v1.1 or TLS v1.2. If upgrading is not possible, then disabling CBC mode cipher will remove the vulnerability.

Any ideas how to disable

...

u5273 by Not applicable
  • 1337 Views
  • 2 replies
  • 0 Likes

Advantages of Virtual Systems...

...What are the advantages of using Virtual Systems, other than being able to divide Management and Reporting of "Virtual" firewalls.  In my case, I have a DMZ, Wireless, Trust and Untrust networks connected to a PA 5020.  Should I split up the DMZ a

...

jambulo by L4 Transporter
  • 2517 Views
  • 4 replies
  • 0 Likes
Top Liked Authors