General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4121 Views
  • 0 replies
  • 0 Likes

Resolved! Palo High vulnerability issue.

Dear,the palo's on our public internet are being scanned for vulnerabilities and other open issues. Last week scanning a issue regarding "OpenSSL ASN.1 Parsing Vulnerabilities port 443/tcp over SSL" on the portal website of the Palo for ssl-vpn access was detected and marked high.The security officer now wants to get this solved in a few days. ...

gejac by Not applicable
  • 11208 Views
  • 8 replies
  • 1 Likes

Block a specific spyware

Hi All,I just want to ask how can we do a spyware blocking. We want to block mariposa spyware but i tried to configure the policy but it does not deny it.Thanks.

TSPI by L1 Bithead
  • 2790 Views
  • 1 replies
  • 0 Likes

Weird problem with SSL VPN traffic

Hi folks,We have two PA firewall pairs.We have two three VPN systems behind the firewalls -- 3SP SSL-Explorer, Barracuda SSL VPN and Windows PPTP VPN.We've had a problem over the last week where the SSL VPN systems wouldn't load their client Java applets properly and the web interface (https) would just intermittently time out, and PPTP users co...

Resolved! Disable Admin Accounts

Is there a way to disable FW admin accounts? Let's say we have a situation where we have consultants who come on site and we only want to enable their access for certain periods of time and then disable them after the engagement is complete. Is this possible?I tried creating a custom role with no access, but it wouldn't let me commit.PANOS 5.0...

mark_dy by L1 Bithead
  • 8269 Views
  • 4 replies
  • 0 Likes

Resolved! Captive portal - time out

Hello Where I can change the time when a user enters for captive portal? Caduceus do not want the user session. I have a PA500 Software version 5.0.4 Thank you very much.

PA to Cisco 5505 VPN tunnel

When trying to configure a site to site VPN tunnel from a PA 3020 to a Cisco 5505 firewal I am getting th following messages on the Cisco firewallreceived encrypted packet with no matching sa droppingall ipsec proposals found unacceptable

infotech by L4 Transporter
  • 12060 Views
  • 22 replies
  • 0 Likes

VPN Tunnel Monitoring

What is generally used for a tunnel interface IP? Can it be arbitrary or must it be an IP that is part of the tunnel? I've read the docs on the site, but they don't say all that much about the interface IP itself.Thanks!

iguarino by L0 Member
  • 3495 Views
  • 3 replies
  • 0 Likes

Resolved! Need help in CLI command

HelloI have to make some order on my PAN device.I'm looking for CLI command:- that will show me all addresses and groups defined on my device- that will show me all services and groups defined on my device- how to list aplications from one policy and put the list of aplication to aplication groupI hope that for You it is easy With regardsSlawek

_slv_ by L4 Transporter
  • 4525 Views
  • 5 replies
  • 0 Likes

Not packet returned via subinterface

Lan2(trust zone-172.16.10.0/24)-> internal - switch from trunk-> (eth1/1-172.16.10.100)PAN FW(eth1/2-192.168.1.104/24)->(192.168.1.1/24) DSL modem(untrust)Lan2(trust zone-172.16.20.0/24)->connected thro. mpls -> (eth1/1.10-172.16.20.100)My vr config: Destination:0.0.0.0/0, Inte...

Javith by L3 Networker
  • 2357 Views
  • 3 replies
  • 0 Likes

Email containing detailed information when a download takes place

Hi everyone, I've read the user guide and searched around here but I'm not able to find an easy step by step guide. I'd like to setup/receive an email from our PAN whenever a download takes place. We currently receive other threat alert emails etc. but not these. I'm thinking it has something to do with Data Logs as the Dashboard provides a visu...

Crash28 by L1 Bithead
  • 2332 Views
  • 1 replies
  • 0 Likes

RSA Risk Based Authentication

Hi all,Recently I've been doing some research to secure our corporate vpn access with RSA SecureID or something equivalent. In my discussions with RSA, it seems they have a token-less risked based authentication engine that does not require users to carry around the RSA tokens. RSA is claiming that currently Palo Alto does not support this, ho...

Resolved! Panorama candidate config rollback

Hi,I prepared some rule changes within Panorama but did not commit them yet. I'd like to roll those back to the running configuration. How would I be able to do that?Thanks in advance.

przyboro by L1 Bithead
  • 4357 Views
  • 4 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels