General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4444 Views
  • 0 replies
  • 0 Likes

Setting Restricted Access to Certain GlobalProtect Users

All,I am a PA beginner so bare with me. I am trying to restrict access to only a few servers to several of our GlobalProtect VPN users. I could set these users into groups but how would I restrict access for each group? We have a PA-500 with 5.0.6 OS version. Let me know if any other info is needed.Any help would be appreciated!Thanks,Troy

TroyFlex by Not applicable
  • 12771 Views
  • 4 replies
  • 0 Likes

Captive Portal - need help with configuration

HelloI'm using CP since over 6 months. It's working quite good.I moved my servers from internet (untrust zone) to my DMZ zone. I realized that traffic between WiFi network and servers in DMZ (using public adreses) is allowed without CP.In WiFi zone I have two networks: WiFi and WiFi_konferencja - traffic between them also should be blocked.I cre...

_slv_ by L4 Transporter
  • 5341 Views
  • 5 replies
  • 0 Likes

Application and Threat Summary report

Hello,i am confused a little bit when i found out that 10.0.0.0-10.255.255.255 is listed in Top 5 Destination country. What actually refers 10.0.0.0-10.255.255.255 in this instance?Regards,

OmarKhan by Not applicable
  • 2640 Views
  • 1 replies
  • 0 Likes

Resolved! schedule dynamic updates from Panorama

Dear,I was wondering if it was possible to schedule a dynamic update (download&install) from Panorama.I know I can configure dynamic updates from the panorama (templates/device/dynamic updates). But I don't want my devices to download the dynamic updates since they have no internet access; I want the Panorama to download them and push them t...

mr.linus by L4 Transporter
  • 3336 Views
  • 1 replies
  • 2 Likes

M-100 - Log collector storage commands

Anyone know the command to show the actual distribution of current logs on a log collector? Basically, i need the output of "show system logdb-quota" at a collector level. I know how to view my defined % allocations and how view the overall disk space usage. I just need a current view of my current usage by log type, so i can re-allocate more to...

chrisp by L3 Networker
  • 3063 Views
  • 2 replies
  • 0 Likes

Resolved! File Types blocking and logging

Hi Gents,I have installed Palo Alto 5050 between the users and my Server Farm.the Issue here is that I created a policy that allows access to the file server based on specific applications or ports, but now I want to prevent usersfrom saving mp3, and video files on my server. so I created a files profile that blocks these file types, and assigne...

Resolved! Blocking videos for a special url category

Hi,We know that url category only works with http and https.So if we want to block all videos(http-video,flash,youtube videos) for a url category(for example social-networking), can we do this with PaloAlto ?(with custom signatures or anyhting else)

Zone protection isnt blocking scan

HiWe have created a zone protection profile for zones UNTRUST/DMZ/TRUST to prevent scan but we have realised that this zone protection profile isnt working.Why isnt blocking this scan??? we have the default values in the zone protection profiles....I attach a screenshot about the scanThanks

Network Monitor

Hello all,I've noticed that when I compare the last 6 hours verses the last 12+ hours the bandwidth show double the bandwidth usage? Can some please explain why this is the case?thanks for all replies.

Resolved! Blocking file downloads based on content disposition

Hello,We are trying to block specific files based on the content disposition. Using all the different context values for http traffic has proven ineffective. The issue is that we don't see the file name until the end of the file download. A screen shot of the packet capture is shown. Support has not been successful at providing me how to ide...

HITSSEC by L4 Transporter
  • 3302 Views
  • 2 replies
  • 0 Likes

How to export all logs ( eg 5 moths detailed) to CSV or any other format?

Hi All,How to export all logs ( eg 5 moths detailed) to CSV or any other format?From monitor -> logs -> traffic i tried to export to CSV but it showing only for one day, is there any way to export all logs? In monitor -> Reports it showing logs from From 4th Feb 2013 to till date, bur when i tried to export to CSV from logs -> traf...

Gururaj by L4 Transporter
  • 16556 Views
  • 10 replies
  • 0 Likes

Using XML API to enumerate virus (antivirus) signatures

Hello,Using the panxapi (from @ksteves) I'm able to enumerate all the threats (scan, vulnerability, phone-home), but I'm not able to find an xpath I can use to enumerate information about the antivirus signatures. By way of example, I can see that in my log output each virus hit appears to have a name and and entry number:<snip>,Virus/Win3...

wfleitz by Not applicable
  • 2558 Views
  • 1 replies
  • 0 Likes

Resolved! Application Override Policy Match Criteria, does it match on Pre or Post-NAT Zone/IP?

HelloI'm currently configuring a PA-2050 running PAN 5.0.9Can anyone confirm if the Application Override Policy match criteria should be configured to match on the Pre-NAT or Post-NAT zones and IP addresses. I'm assuming it will match in the same way as a security policy does, and use the Post-NAT Zone, while the IP address match is based upon ...

Smi12 by L2 Linker
  • 3669 Views
  • 2 replies
  • 0 Likes

Error when trying to run User Activity report

I am trying to run a User Activity report. There are logs for this employee with their domain ID identified but when we run the actual report for HR it comes up blank. Is there a know release to resolve this issue.PAN OS version is 5.0.4.Thanks

unable to change the web-gui certificate

hi ,recently i wanted to changed the web-gui certificate i followed the procedure on how to create a certificate in openssl ( for panos 4.x) the certificate created successfully. i event imported into the appliance but whenever i click on the checkbox Certificate for Secure Web GUI i receive the following error system -> web-server-certificat...

  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels