General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Bright cloud DB classifications on url

Hi,I wonder if anyone can help. there is a site - ea.sendcpt.com which is listed in both brightcloud and PAN-DBOn brightcloud it is listed as malware-sitesBut on PAN-DB which is a newer DB it is listed as business and economyThe end customer is having an issue as they are trying to access the site as it is a trusted site but they are getting bl...

Resolved! PAN-DB Evaluation - How to switch over with minimal impact?

We want to evaluate PAN-DB.We have the eval license downloaded.What I'd like to know is, if I hit "activate" in the Web GUI will it immediately kick in, or will it need a commit?Basically I'd like to know the smoothest way to change over with minimal impact to our end users.Thanks

GP Client 2.0.0 - is it next version after 1.2.8?

HiCould someone tell me that 2.0.0 is new version next to 1.2.8 or we can expect version 1.2.9 soon?2.0.0 Finally it has fixed issue with RDP connections:45997—When trying to RDP to a GlobalProtect agent installed on a Windows PC, the RDP login prompt window showed possible account option double. RegardsSlawek

_slv_ by L4 Transporter
  • 1831 Views
  • 1 replies
  • 0 Likes

Resolved! Identified User and NAT

Hi,for certain of our users is it aloud to use firefox. they are identified by their username. But if the want to go to internet they have to be "NATted" . It is possible and when how to create a NAT-Rule? What is known: username and the application.Best regardsKlaus

kdd by L4 Transporter
  • 5095 Views
  • 5 replies
  • 0 Likes

Palo Alto With TWO ISPs

Hello,We have migrated firewall from ASA firewall to Palo Alto firewall. In my case, we have below interfaces in Palo Alto firewall.1. ISP1 Interface (E1/1)2 ISP2 Interface (E1/2)3. DMZ Interface (E1/3)4. Inside Interface (E1/4)Since we are using ISP1 for accessing DMZ servers from internet and we are using ISP2 for web traffic of users from in...

Destination NAT with different subnet of Outside interface.

Hello,Outside interface of Palo Alto firewall is configured with aaa.bbb.ccc.ddd /30 subnet.I have some servers in DMZ those need to be accessed via internet with IP address(es)/subnet ZZZ.XXX.YYY.VVV/24.I have configured Destination Nat( including Security Policy) for these servers with the IP addresses as mentioned above.Please let me know how...

Resolved! address object strange behavour

Hi I create a address object base on a network address like 192.168.21.0/20 and when I used it as source address in my policy base forwarding rule this never matchbut when I create addresse object with a range like 192.168.16.1-192.168.31.254 and when I used it as source address in my policy base forwarding rule this matchwhat wrong ?is it bug?o...

Gregoux by L4 Transporter
  • 2887 Views
  • 3 replies
  • 0 Likes

Resolved! USER ID agent wmi probing

Hi something strange with old version of user-id agent version 4.1.6-5the user is connected on the network lan with wire and is authenticated on the active directory the result is the user is identicated in the traffic log If the user switch from wire connection to wifi connection the wmi probing should detect the new ip affected to user? or no...

Gregoux by L4 Transporter
  • 7780 Views
  • 5 replies
  • 1 Likes

PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site

I just stumbled on this security advisory while I was googling something totally unrelated...http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt"These issues have been fixed in PANOS 5.0.9, mentioned in the release notes like this:57343—Fixed an issue that caused improper handling of imported certificates that contained HTML."Also I thi...

Global Protect client issue - really annoying

This one has been bugging me for a long time and I've just been brushing it under the table, well new year, new resolve, so I thought I'd ask the smart people if anyone else has seen/experienced/fixed this.My organisation has the Global protect client installed on all our laptops by default, regardless of if the user is office based or remote.Al...

darren_g by L4 Transporter
  • 11481 Views
  • 12 replies
  • 1 Likes

Using application categories in security rules.

Hi all,I am in the process of configuring security rules to allow some applications for a particular user group, These applications I am taking from the app category "internet" & "Media", (131 applications in total) this I could do by adding these applications to a application group and applying it to the rule. In the same application group...

HughWalsh by Not applicable
  • 3309 Views
  • 1 replies
  • 0 Likes

Wildfire Analysis Email Alerts

Hi,Can you confirm how quickly we should be receiving the Wildfire analysis report following a malicious file detection?I have a wildfire upload that occured at about 2am GMT, I have the PAN log message reporting the upload, and in the PAN Wildfire THREAT log I can see it has been logged as malicious and links me to the online portal with the an...

apackard by L4 Transporter
  • 2477 Views
  • 2 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels