General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

CLI Scripting to implement missing commands

Hi,in my opinion some commands are still missing in the PanOS CLI. I miss some features implemented in my conventional firewall to handle the policy rule set efficiently. Some other vendor has the possibility to use so called op-scripts in the CLI. This scripts allow to implement own CLI commands using the built in API. Is there already the pos...

Unibw by L2 Linker
  • 3543 Views
  • 3 replies
  • 0 Likes

Best Way to use User-ID Agent.

Hey everyone,I have been bashing my head onug how I can cleaninly use the USer-ID agent.. I wanted to stop WMI or event exclude internal vlans as I thoht it was used just for VPN. But its not its used to map source user info in the log files of the firewalls...Thing is when I have it enabled it probes everything! Gateways, iPhones, S4's ipads, e...

Zewwy by L3 Networker
  • 7081 Views
  • 8 replies
  • 0 Likes

Dynamic Block Lists and Spamhaus

Does anyone know if the Spamhaus format drop lists (that use ";" delimiters to denote descriptive text) are accepted as PA Dynamic Block lists?http://www.spamhaus.org/drop/drop.txtRgds

apackard by L4 Transporter
  • 10061 Views
  • 5 replies
  • 0 Likes

user agent refresh

hi!i was wondering what is the time frame for the user agent to "discover" newly added users or security groups, in an LDAP environment?if such a timer exists - is it configurable?can the agent be forced to update its database?thnx!

Resolved! Dynamic Block List format clarification

I need some clarification on this great head start on Dynamic Block List format:Working with External Block List (EBL) Formats and LimitationsI note that a few lists seem ready to use without re-formatting like:http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txtIs it safe to assume that the comments preceded by the pound sign and the...

MCmgt by L2 Linker
  • 4157 Views
  • 1 replies
  • 0 Likes

Failover latency

Hello,I have one question and I hope somebody will help me.Does PaloAlto has a recommendation for failover link latency. For example I have firewall cluster and this cluster is done across wide area. What max latency should be used for properly functionality between cluster members. For example cisco says that failover link latency should be l...

aaputis by L0 Member
  • 3048 Views
  • 2 replies
  • 0 Likes

Brightcloud Revision 4272 and *.googleapis.com

Just a heads up that revision 4272 of Brightcloud which installed on my PAN-500 overnight marks *.googleapis.com as spyware, so certain Google services will not load if you are blocking adware/spyware categories. I reverted back to 4271 before I figured out the issue. Have added *.googleapis.com to the allow list in case a future install does ...

AD integration and exclude one user

HiToday I faced with a problem, I had to add second gorup to my "Athentication Profile" and I can't do that...Every time when I try to past a "CN=VPN_users,OU=U,OU=Work Groups,OU=Security,OU=Groups,DC=contoso,DC=local" I got it as a user not a group, why?So finally I added "any" - but in my opinion it's bad idea because I allow all AD users to ...

_slv_ by L4 Transporter
  • 3289 Views
  • 3 replies
  • 0 Likes

PA 6.0.1

Hi,I am looking to find out if there has been any issues with 6.0.1. We are new to PA and we are thinking about upgrading to 6.0.1 from 5.0.11, but we would like to see if anyone had any issues with either the upgrade itself or the version.Any help is appreciated!Thank you!

Urgent: Enable to connect voip data in Virtual mode

Hi all, I am on site now with client and i had some problem in deploying the PA-500, please i need your help:I have configured PA-500 in Virtual-wire mode in a lan2lan liason between the two client sites and set the rule to allow any any. but when we try to test with phones to enregister from the callmanager server it's failed so i searched and...

Lahcen by Not applicable
  • 4008 Views
  • 5 replies
  • 0 Likes

Palo alto can detect SPAM

Hi i have a doubt about Palo Alto. Yesterday we realised that there was a massive spam sending from our email servers. This is the second incident of its kind in recent days. The question is whether the Paloalto can do some kind of test to detect this type of behavior, is able to examine headers or something like that?, There is some kind of fil...

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels