General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Application Groups "service" in security policy

I have the following scenario I came across and just curious if this is expected behavior. It is recommended when "whitelisting" and application to use the application-default service (so it only works on its default port), or if you are "blacklisting" to use the service "any" (to block the app on any port used). I'm not so sure this works using...

froggyj by Not applicable
  • 4129 Views
  • 2 replies
  • 0 Likes

Resolved! ports unknown allowed

Hi all,We have an application group that specifies the applications to allow from untrust to our DMZ. Mostly its just web browsing, ssl, pop and smtp. We are not allowing ms smb port 445 or Port 135 msrpc.Our recent PCI security scans are telling us these ports are accessible. if I look in the monitor logs I can see msrpc (port 135) and ms-ds-sm...

how to see posted data sent by attackers

Hi..Is there a way to see content of posted data by attacker.For example content of Generic HTTP Cross Site Scripting Attempt or sql injection.Palo alto shows only the name of attack and some information about them

ikaratas by Not applicable
  • 3487 Views
  • 3 replies
  • 0 Likes

Resolved! Does it exist any command to disable and enable a static route from the CLI to change the paremeter from "no-install" to "install"?

And about the question, I've already installed the static route using the GUI but with the "set network virtual-router default routing-table ip static-route <virtaulrouter_name> option no-install" command we can enable the "no-install" checbox, now I want to find the command to disable (unchecked) this, I know I can do it from the GUI but ...

Pull Report directly From ACC

I searched for this on the forum but couldn't find it so I apologize if this is a repeat question.I'm trying to pull a report just as it's shown in the ACC.Starting off without any filters, within the ACC, I click on the "online-personal-storage" URL filtering category. This displays the top applications in that category. That's perfect! That's ...

Port Forwarding

I am trying to create a webpage to display the video stream of two of our IP Cameras.The page works perfectly from inside the network but not from outside the network.I think I need to set up some kind of port forwarding rule on my Palo Alto and then program that into the web page, but am not sure how to accomplish this on the Palo Alto.Thanks,Mike

Resolved! Palo High vulnerability issue.

Dear,the palo's on our public internet are being scanned for vulnerabilities and other open issues. Last week scanning a issue regarding "OpenSSL ASN.1 Parsing Vulnerabilities port 443/tcp over SSL" on the portal website of the Palo for ssl-vpn access was detected and marked high.The security officer now wants to get this solved in a few days. ...

gejac by Not applicable
  • 11804 Views
  • 8 replies
  • 1 Likes

Block a specific spyware

Hi All,I just want to ask how can we do a spyware blocking. We want to block mariposa spyware but i tried to configure the policy but it does not deny it.Thanks.

TSPI by L1 Bithead
  • 2919 Views
  • 1 replies
  • 0 Likes

Weird problem with SSL VPN traffic

Hi folks,We have two PA firewall pairs.We have two three VPN systems behind the firewalls -- 3SP SSL-Explorer, Barracuda SSL VPN and Windows PPTP VPN.We've had a problem over the last week where the SSL VPN systems wouldn't load their client Java applets properly and the web interface (https) would just intermittently time out, and PPTP users co...

Resolved! Disable Admin Accounts

Is there a way to disable FW admin accounts? Let's say we have a situation where we have consultants who come on site and we only want to enable their access for certain periods of time and then disable them after the engagement is complete. Is this possible?I tried creating a custom role with no access, but it wouldn't let me commit.PANOS 5.0...

mark_dy by L1 Bithead
  • 8760 Views
  • 4 replies
  • 0 Likes
  • 24449 Posts
  • 125 Subscriptions
Top Solution Authors
Labels