General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

attacking site and PAN

HelloFew days ago I discovered site with some information about VMware Update Manager. I had a problem with it and I was searching for solution.This site is www.bourgelat.net/cannot-patch-definitions-vmware-19988I have PA with all licences but PAN software doesnt detect any bad traffic I asked PAN to change categorization to malware site, but to...

_slv_ by L4 Transporter
  • 6389 Views
  • 13 replies
  • 0 Likes

Opt-out page for HTTP ?

We would like to have a web response page that is presented to the user when the user launches their browser for the first time that asks them if they abide by the AUP rules. Basically same concept as the https opt-out page. Is this possible? If so, can someone please advise how.Thanks in advance for your response

Resolved! Can't clear session from CLI

Running PANOS 6.0.1. I can't seem to clear a session from the CLI. Just tested on a PA-500 running 6.0.0-b42 and I have the same problem.Anyone knows if this is a bug?admin@PA-vm> show session all filter destination 212.x.x.x--------------------------------------------------------------------------------ID Application State Type...

Disable an IPSec Tunnel

I want to disable an IPSec VPN. I have currently blocked traffic both directions to the tunnel by using a Security Policies, but there should be a way to disable the tunnel in the IPSec configuration (or alternatively, disable the tunnel interface). I don't want to delete it, but I don't want it taking up processor speed for a tunnel that I don'...

blandis by Not applicable
  • 8838 Views
  • 5 replies
  • 0 Likes

Resolved! PA-5020 reboots to maintnance mode. No hardware problems... svc: failed to register lockdv1 RPC service (errno 97)

Hello, All!After unpacking and installing PA5020 in HA Active/Active we could not set up a basic nat - in dataplane packet dump there was an error smth like "Cant create session" after nat and sec.policy applied. NAT and security rules were fine.After rebooting one node it went to countinuos rebooting: after exit maint mode it starts, prompts fo...

MZRF by L1 Bithead
  • 6022 Views
  • 5 replies
  • 0 Likes

Decryption: sec_error_reused_issuer_and_serial

Hey all,I am having problems with decryption. The PA decrypts https websites, but when I surf to that website a few hours later, I receive the following error in firefox:I haven't tried yet in IE or Chrome. I have this problem for various websites, not just gmail (I already had the problem with paloaltonetworks.com)The issue is resolved when res...

Threats alert

Hello Team,I have configured the panorama threat alert for one of our firewall and its working fine. Alerts has been configured for High and Critical .we are getting so many alert from one IP (10.32.100.238) , one of vulnerabilities management device . I want to create a rule so that we can exclude the alerts from the source IP 10.32.100.238 and...

tiwara by L3 Networker
  • 2963 Views
  • 2 replies
  • 0 Likes

EU - European Union

Is it possible to view the countries that are included in the "EU" object? When new countries are added to the EU, will this object be updated via dynamic updates or by upgrading?Does anyone have experience with the accuracy of geo ip on palo alto?Kind regards

Intermittent SSL decryption issues for some, not all.

My Palo Alto Firewall 2050 running 4.1.16. I am having a lot of intermittent SSL decryption issues. I'm not sure what to do with some of these. An example is https://app.plangrid.com. I can this site when I have made this change and restart my browser:> set system setting ssl-decrypt skip-ssl-decrypt yesSetting this back to the no re...

EdwinD by L3 Networker
  • 4861 Views
  • 2 replies
  • 0 Likes

Resolved! ftp export log

Anyone know how to translate this show CLI command into the ftp export equivalent? > show log traffic src in 10.0.0.0> ftp export log traffic ?? (assuming query would work)I would prefer not to export all logs only need a subset.Thanks,Monica

MLaden by Not applicable
  • 3534 Views
  • 2 replies
  • 0 Likes

Resolved! About a session generated by override rule

Hi guys,A session generated by override rule that can be applied rematch session after commit configuration successfully? Or not? I guess that rematch session would not impact to session generated by application override rule.Please let me know above question.Thanks.Regards,Roh

Resolved! Apply policy on a vwire interface in passtrough mode

I want to apply a policy on my vwire interface but i have this error: Operation Commit Result Failed DetailsIn VSYS vsys1 from zone VW-MPLS-Trust of type vwire and to zone UNTRUST of type layer3 are incompatible in security rule Application block Configuration is invalid Is it possible to know how to apply a policy to this interface, if ...

dsevigny by Not applicable
  • 2925 Views
  • 2 replies
  • 0 Likes

Disable Inspection for Sip ?

In the ASA you can disable SIP Policy Inspection. In the Junipers I think you disable the ALG. How do I do this in the Palo Alto ?Firewalls often try to apply rules around the way protocols work which can cause them to break. I dont want SIP to be inspected or held against some EEE Group Standard. This might be breaking some video conference tra...

jhickey by L3 Networker
  • 12718 Views
  • 6 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels