General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

User-id don't read security log

I have several domain controller configurated on user identification configuration in a Palo Alto with 5.0.8 version. Just one of them seems to function properly and if I use the command "show user server-monitor state all" I obtain this:Server: CD02(vsys: vsys1) Host: xx.xx.xx.xx num of log query made : 2 ...

JRSanch by L1 Bithead
  • 3979 Views
  • 4 replies
  • 0 Likes

How to handle email alerts

Hi Everyone,After firing up my new Palo Alto IDS, I turned on the ability to send emails for medium, high and critical threats. However, when hundreds of threats are detected in a short window, I get hundreds of emails. All of them are about the same event (a brute force event in this case.) Is there a way to configure alerting so that a spec...

HTTP DDoS attack block signature

I need to know how to create a custom signature to block HTTP DDoS attack signature against our Web server.The common pattern I can observe in the attack is - either (1) Automated specific URL access or (2) URL access request with Cache-Control: no-cache\r\n\I appreciate your comments or suggestions.Sincerely yours, Mike

Resolved! I can not filter the wildfire submissions logs whether malicious or benign in PANOS-6.0.0.

HelloI am testing the wildfire with PANOS-6.0.0 for POC.There are malicious or benign on category in detailed log view.But I can not add category column in wildfire submissions logs. I want to filter malicious or benign such as filtering source ip but there is not category column.Is it the bug? or not?If not, how should i do?Cheon

Group HA Peers are out of order in Panorama 6.0

When I select the "Group HA Peers" in Panorama 6.0, my Active firewall in the pair shows up underneath the Passive firewall in the "Managed Devices" display. Also, the Active firewall shows up in the parenthesis instead of the Passive firewall.Does anyone else have the same issue with Panorama 6.0?

jwolach by L4 Transporter
  • 2253 Views
  • 1 replies
  • 0 Likes

Blocking WebCam Traffic

Hello All,I'm sort of new to the Palo Alto firewall world, I had a question about blocking traffic to those adult free live cam sites, I dont want to block skype or facetime or anything simliar. All I really want to do is block specific traffic from those adult cam sites, I know its a weird question but if someone could shed some light on this I...

shane by Not applicable
  • 4194 Views
  • 4 replies
  • 0 Likes

allow Skype and Block Skype VoIP and file sharing

HiI've been asked if I can use our Palo's to allow skype messaging only and block users to make calls and send/receive files using Skype. I already seen some discussion saying that this is not possible but i'm wondering if paloalto comes with something new in the new PAN OS 5 and 6 releases since those discussion are from 2012 and 2013.Thanks

Lahcen by Not applicable
  • 3115 Views
  • 1 replies
  • 0 Likes

Resolved! Help setting up a rule to block all traffic at night

OK, I'm new to firewalls in general and I inherited our Palo Alto PA500 with PANOS v5. I"m trying to set up a rule that doesn't let any traffic in or out of the building from 7:00 pm to 7:00 am. Currently my boss has a rule that the last person out unplugs the internet from the LAN. I find this to be ridiculous and insist that we can do somethin...

acole by L1 Bithead
  • 6243 Views
  • 6 replies
  • 1 Likes

Can PA block Web shell or shell script?

Hello, guys~One of my customer want to know whether the Pan block web shell or shell script. In my opinion, there's no ips which can block those attacks 100%. Threat prevention of the PA is signature base also, which means if it detects well-known web shell, it might block it. If not, it can't.It's sure that web shell is based on web server appl...

JTR by Not applicable
  • 4684 Views
  • 1 replies
  • 0 Likes

packet size issue

Hi All,Noticed unable to ping packet size above 996 after upgrading to PAN OS 5.few of our internet apps(cloud) is acting intermittently Anyone encountering the same issue? Any advice is appreciated? Thanks.> ping size 995 source 172.21.194.22 host google.comPING google.com (74.125.226.14) from 172.21.194.22 : 995(1023) bytes of data.72 bytes...

ateo by Not applicable
  • 4474 Views
  • 1 replies
  • 0 Likes

Resolved! Traffic log showing "attempted" rules

Hi,I have a few security policies (below) and did some testing on them, and found the traffic log displaying some interesting results; I have an idea of why this shows up in the log, but may be somebody more experienced can confirm.I have a rule that allows DNS application, any port:and a rule below that allows any outbound traffic:When looking ...

MMCiobanu by L3 Networker
  • 3413 Views
  • 2 replies
  • 0 Likes

Wildfire Activation

I successfully actived Wildfire in my environment..however, no data is being pushed to my external syslog server (Splunk) or the online Wildfire portal. Is there a sample file I can download to test if its working?

rrau by L3 Networker
  • 2574 Views
  • 2 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels