General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Dynamic block list and custom blocked page

Hi,I am planning to use custom blocked page. So far I have got the logic of creating custom block page and using it in the policy. I would however like to know if I can somehow redirect user to custom blocked page and inform user that his/her access is blocked for xyz reason.Thanks in advance.

File blocking..

Hi Gents,I have a Palo Alto 5050 installed between users and my Server Farm.I configured a security policy to allow access to the File Server, and applied a File type profile to block files such as exe, avi, and FLV.but the file blocking doesn't work, while the users are still able to put these file types on the server share.how can I resolve th...

File Types and Applications regarding SSL Decryption

Hi All,I don't have content Filter License.am I required to configure ssl decryption to block internet applications or file types?shall I've a content filter license to configure ssl decryption or not?Also I'm facing other Issues,to open internet access for users, I open web-browsing application and ssl.while I'm trying to brows the internet I f...

Policies security rules - filtering issue

Hi,Do you know is there any documentation regarding policies security rules filtering? I have found some strange behavior for filtering. Examples below on the screenshots are from Palo Alto testing firewall (sv 5.0.6). As it can be seen, if I use filter (source-user eq ‘any’) not all relevant results are returned which is obviously wrong.Also, I...

Monitor traffic - filtering issue

Hi all,we have noticed inconsistency in PAN OS 5.0.8 and 5.0.9, compared to 4.1.9, related to monitor traffic filter. In older version message box pops-up in case filter is not properly defined (i.e. if there is syntax error), which is fine and helpful. In mentioned 5.0.8 and 5.0.9 nothing pops-up in case of erroneous filter, only white area is ...

Active/Active traffic log.

HelloI knew session owner generate traffic log.Does session setup device generated traffic log If a session is denied L4 processing before L7 processing???Network DiagramRouter#1(Power-OFF) ------ Router#2(Power ON) | | FW#1 FW#2 | ...

Resolved! use GlobalProtect for Network Logon

Dear,Is it possible to use GlobalProtect with pre-logon enabled as a "Network Logon" for Windows?This way I want to use the GlobalProtect to tunnel the domain-login request to our AD when the pc is on the road.Ultimately we want to use this for users with expired accounts to be able to reset their domain password remotely.If this is not possible...

mr.linus by L4 Transporter
  • 5187 Views
  • 8 replies
  • 0 Likes

About updating AD group membership

Hello guys1. I configured LDAP profile and update from AD DC2. AD group named domain-users has about 10900 user3. Customer created new user and applied new user to domain-users groupSo I tried to refresh a group-mapping information by debug command. But PAN could not be updated domain-users group information and refreshing member of group.1. I c...

7-Zip ARJ File Buffer Overflow Vulnerability(31030)

Has anyone come across this vulnerability? We have several PC's with 7-zip installed for extracted .tar files in windows. Even after we delete 7-zip, we still see these vulnerabilities being flagged by the pan. Has anyone seen this behavior before? Possibly a rootkit or other malware on the pc's?Thanks

jmurphy by L2 Linker
  • 2367 Views
  • 1 replies
  • 0 Likes

Resolved! pa performance analyze

hey i am trying to analyse if the PA is under load regarding to the PA specs,the customer is having sometimes disconnects on the network, i can see that the CPU have peaks sometimes but mainly is OKnetcom@PA-IL-ACTIVE(active)> show running resource-monitor hourResource monitoring sampling data (per hour):CPU load (%) during last 24 hours:core...

minow by L4 Transporter
  • 3077 Views
  • 1 replies
  • 0 Likes

best practice User-ID strategy?

Hello,first I try to give you some information. Our headquarter is located in Germany. All of our subsidiaries are connected to Germany via relatively slow VPN lines. Overall we have round about 20 DCs in different countires. Until now we have only 3 Palo Alto firewalls (Germany, USA, Canada) but in the future we plan to buy more.Our setup until...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Labels