General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

MTU problem PA-500 5.0.6

I have a PA-500 5.0.6From inside my network I see an MTU maximum of 1023. From outside through my ISP I see the MTU that I expect of 1492. Traffic through the PA sees an MTU of 1023. I haven't changed the interfaces. Is this possible to fix? Where in the PA config would I look?bb33@bb33-vlinux:~ $ ping -s 995 google.com PING google.com (7...

gmoss by L1 Bithead
  • 4506 Views
  • 3 replies
  • 0 Likes

Resolved! HTTPS traffic suddenly blocked

Hi,We have had same issue twice in two days, where the firewalls would suddenly block HTTPS traffic; this happened on two platforms, PA-3020 and PA-5020, both running 5.0.8 PAN-OS, and the work around was to create a "Do-not decrypt all" decryption policy at the top, until we could schedule a reboot; the reboot seems to fixed the issue for now i...

MMCiobanu by L3 Networker
  • 7428 Views
  • 2 replies
  • 0 Likes

Resolved! Security Policy Limit Alarms

I'm trying to setup an alarm to trigger is we have excessive drops on a firewall rule.When looking at this functionality the Help section states:-"Use Security Policy Tags to specify the tags for which the rule limit thresholds will generate alarms. These tags become available to be specified when defining security policies".However, whenever I ...

apackard by L4 Transporter
  • 5488 Views
  • 3 replies
  • 0 Likes

GameOver Zeus

Does PaloAlto provide any protection against this malware, either in downloading the virus, making the DNS quesries to the list of .ru domains that the FBI released on June 4th, or in the call backs that it makes?

Panorama - Simple Question

We are currently running Panorama on a VM and need to take it down to add more resources to it. Will taking down Panorama or rebooting it have any affect on connectivity for the 2 PAN's that it manages?

SSL Decryption Certificate

For SSL Decryption does the cert on the PALO need to be issued from the same enterprise cert chain as the workstations, or does the cert on the workstation have to match the cert on the PALO exactly? We have about 2000 workstations that have been issued a unique cert already for other applications. ThanksMark

markk96 by L3 Networker
  • 1912 Views
  • 1 replies
  • 0 Likes

Panorama without direct internet connection

Hi,I have a setup where panorama is not allowed direct internet connection, therefore I would like a setup where a server in a DMZ sone gets the updates from Paloaltonetworks.com and my panorama installation gets the update from that server. Has anybody seen or tested a solution like this?/kristian

kristian by L3 Networker
  • 2403 Views
  • 1 replies
  • 0 Likes

SSL Decryption Certificate

For SSL Decryption does the cert on the PALO need to be issued from the same enterprise cert chain as the workstations, or does the cert on the workstation have to match the cert on the PALO exactly? We have about 2000 workstations that have been issued a unique cert already for other applications. ThanksMark

markk96 by L3 Networker
  • 1806 Views
  • 1 replies
  • 0 Likes

Resolved! Manual editing an existing PA5000 config for PA7000 migration

Hi guys,a customer gets a replacment of PA7050 for the PA5000 model they are currently using. Since the PA7k uses the blade slot as reference for the Interfaces my idea was to replace "ethernet1/1" from the PA5k config with "ethernet7/1" and load it up in the PA7k. Well, it didn't work as the Mgmt tells me that the reference is invalid.A small e...

TRisec by L1 Bithead
  • 2918 Views
  • 1 replies
  • 0 Likes

Resolved! issue with SSL decrypt-forward proxy

Customer Network configured with SSL decrypt-forward proxy. Now they can't able to browse more sites (eg:birdres.com, sap.snn,etc). They were not satisfied with exclude ssl decrypt. (due to more no.of sites in exclude list). Is there any other way?Thanks

Javith by L3 Networker
  • 5277 Views
  • 8 replies
  • 0 Likes

Application Groups "service" in security policy

I have the following scenario I came across and just curious if this is expected behavior. It is recommended when "whitelisting" and application to use the application-default service (so it only works on its default port), or if you are "blacklisting" to use the service "any" (to block the app on any port used). I'm not so sure this works using...

froggyj by Not applicable
  • 3936 Views
  • 2 replies
  • 0 Likes

Resolved! ports unknown allowed

Hi all,We have an application group that specifies the applications to allow from untrust to our DMZ. Mostly its just web browsing, ssl, pop and smtp. We are not allowing ms smb port 445 or Port 135 msrpc.Our recent PCI security scans are telling us these ports are accessible. if I look in the monitor logs I can see msrpc (port 135) and ms-ds-sm...

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels