General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 264 Views
  • 0 replies
  • 1 Likes

zip file blocking is also blocking docx files

The organization policy is to block ZIP file types.

We are having problems with docx file type which they are a ZIP file but in the file blocking profile I can see Paloalto should know how to recognize docx files but we still get drops

i would like to

...

minow by L4 Transporter
  • 4423 Views
  • 4 replies
  • 0 Likes

File Types and Md5 Hashes

I write SIEM content (Mostly Arcsight and Q1), I have found PAN to be very effective in identifying adverse traffic. One thing that would be great, that in addition to recognizing the file type such as "file Microsoft PE File(52060)" which is useful

...

Another PA bypass

Found this one recently:

http://www.what2code.net/?p=150

http://www.youtube.com/watch?v=wPHeAkv8BaE

Where dns is being used to tunnel ssh traffic through and of course there will be ways to bypass things but how is/will PA address this latest finding?

(a

...

mikand by L6 Presenter
  • 6793 Views
  • 10 replies
  • 0 Likes

Ignore_user_list

Hello,

I'm using PAN Agent 3.1.2 on WIN2008 server and somethimes after restart the Ignore_user_list seams to be ignored )user on the lista are still identified by the PAN firewall).

Does someone had this problem ? there is way to have an alert or log

...

Security policies did not take effect after Sleep Mode

Hi,

Just like to find out if there is a known  issue with Palo Alto and Windows 8 for direct internet policy.  Currently, we have defined a policy in PA to allow AD user to connect to internet.  However, based on my observation, once my notebook goes

...

Operation Failed: Invalid Sequence

Hello,

I recently upgraded to Panorama 5.1.0 (I know, I'm a glutton for punishment!) and am experiencing an issue when attempting to add items to an application group. We've tested this with several workstations and both IE and Chrome and each result

...

Resolved! syslog no log sometimes

Hi,

Pa200 configured to send all to syslog.Sometimes(Random) no log comes to syslog.Did Anyone see an issue like this  ?

5.0.5 panos.

panos by L6 Presenter
  • 2940 Views
  • 6 replies
  • 0 Likes

Resolved! GlobalProtect assigning zone based on AD group membership?

I'm fairly sure I can't do as the subject line, so I'll explain why I think I want it, and hope someone can suggest a better workaround.

We're a college campus with (roughly) 3 classes of users: students, general faculty and staff, and "special" staff

...

rgraves by Not applicable
  • 4158 Views
  • 6 replies
  • 0 Likes

DHCP issue in vwire

Hi all,

Having a really simple archie with two ports in vwire (Allow all vlan and multicast on it), create a rule "trust to untrust allow all".

Issue is for dhcp request, I have to create a rule allowing dhcp answer from untrust to trust ....

In my mind

...

VinceM by L5 Sessionator
  • 3121 Views
  • 4 replies
  • 0 Likes

Is it possible to block method POST in any website?

    Hi guys,

               Our company don't want employee to post anything on internet so we're trying to create custom application that block method POST on http-request-message. But when we're trying to write a pattern. It's always pop up an alert

...

Global Protect Portal/Gateway Certificate Issue

Hi,

Just recently after upgrading to Global Protect Version 1.2.4 we started getting error messages on our external users laptops that there was an " CN Mismatch Name" but continuing still allowed them to connect..

After determing it was a Common Name

...

acmi by L1 Bithead
  • 2251 Views
  • 1 replies
  • 0 Likes

Resolved! Daily packet capture limit of PA-3000?

I would like to know Daily packet capture limit of PA-3000 serial.

Do you know this?

other serial device is...

>  PA-5000 : 786432

>  PA-2000 : 131072

>  PA-500 : 32768

>  PA-200 : 65536

Regards.

smaekawa by Not applicable
  • 3458 Views
  • 4 replies
  • 0 Likes
  • 23630 Posts
  • 107 Subscriptions
Top Liked Authors
Labels