General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4126 Views
  • 0 replies
  • 0 Likes

Panorama without direct internet connection

Hi,I have a setup where panorama is not allowed direct internet connection, therefore I would like a setup where a server in a DMZ sone gets the updates from Paloaltonetworks.com and my panorama installation gets the update from that server. Has anybody seen or tested a solution like this?/kristian

kristian by L3 Networker
  • 2376 Views
  • 1 replies
  • 0 Likes

SSL Decryption Certificate

For SSL Decryption does the cert on the PALO need to be issued from the same enterprise cert chain as the workstations, or does the cert on the workstation have to match the cert on the PALO exactly? We have about 2000 workstations that have been issued a unique cert already for other applications. ThanksMark

markk96 by L3 Networker
  • 1781 Views
  • 1 replies
  • 0 Likes

Resolved! Manual editing an existing PA5000 config for PA7000 migration

Hi guys,a customer gets a replacment of PA7050 for the PA5000 model they are currently using. Since the PA7k uses the blade slot as reference for the Interfaces my idea was to replace "ethernet1/1" from the PA5k config with "ethernet7/1" and load it up in the PA7k. Well, it didn't work as the Mgmt tells me that the reference is invalid.A small e...

TRisec by L1 Bithead
  • 2874 Views
  • 1 replies
  • 0 Likes

Resolved! issue with SSL decrypt-forward proxy

Customer Network configured with SSL decrypt-forward proxy. Now they can't able to browse more sites (eg:birdres.com, sap.snn,etc). They were not satisfied with exclude ssl decrypt. (due to more no.of sites in exclude list). Is there any other way?Thanks

Javith by L3 Networker
  • 5168 Views
  • 8 replies
  • 0 Likes

Application Groups "service" in security policy

I have the following scenario I came across and just curious if this is expected behavior. It is recommended when "whitelisting" and application to use the application-default service (so it only works on its default port), or if you are "blacklisting" to use the service "any" (to block the app on any port used). I'm not so sure this works using...

froggyj by Not applicable
  • 3882 Views
  • 2 replies
  • 0 Likes

Resolved! ports unknown allowed

Hi all,We have an application group that specifies the applications to allow from untrust to our DMZ. Mostly its just web browsing, ssl, pop and smtp. We are not allowing ms smb port 445 or Port 135 msrpc.Our recent PCI security scans are telling us these ports are accessible. if I look in the monitor logs I can see msrpc (port 135) and ms-ds-sm...

how to see posted data sent by attackers

Hi..Is there a way to see content of posted data by attacker.For example content of Generic HTTP Cross Site Scripting Attempt or sql injection.Palo alto shows only the name of attack and some information about them

ikaratas by Not applicable
  • 3320 Views
  • 3 replies
  • 0 Likes

Resolved! Does it exist any command to disable and enable a static route from the CLI to change the paremeter from "no-install" to "install"?

And about the question, I've already installed the static route using the GUI but with the "set network virtual-router default routing-table ip static-route <virtaulrouter_name> option no-install" command we can enable the "no-install" checbox, now I want to find the command to disable (unchecked) this, I know I can do it from the GUI but ...

Pull Report directly From ACC

I searched for this on the forum but couldn't find it so I apologize if this is a repeat question.I'm trying to pull a report just as it's shown in the ACC.Starting off without any filters, within the ACC, I click on the "online-personal-storage" URL filtering category. This displays the top applications in that category. That's perfect! That's ...

Port Forwarding

I am trying to create a webpage to display the video stream of two of our IP Cameras.The page works perfectly from inside the network but not from outside the network.I think I need to set up some kind of port forwarding rule on my Palo Alto and then program that into the web page, but am not sure how to accomplish this on the Palo Alto.Thanks,Mike

  • 24336 Posts
  • 124 Subscriptions
Top Liked Authors
Labels