General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Can't find where an SSL cert is in use

I'm trying to delete an SSL certificate from a Palo Alto cluster I'm setting up via Panorama. It tells me the cert cannot be deleted due to this reason:because of references from:template -> {firewall cluster name} -> config -> devices -> localhost.localdomain -> vsys -> vsys1 -> captive-portal -> server-certificateI rem...

Issue in the syslog message format in Palo Alto 6 beta 1

Hello,I am currently on Palo Alto v 6.0.0-b23 and facing an issue with the format of syslog message.if we pass the same malicious file through Palo Alto device, syslog message forwarded by Palo Alto v5.0.6 and v6.0 beta are different. Palo Alto 5.0.6 forwards threat name and ID while Palo Alto 6 beta forward threat ID twice. Log on Palo Alto 6.0...

NHorsch by L1 Bithead
  • 2319 Views
  • 1 replies
  • 0 Likes

Detecting / mitigating Cryptolocker

Hello,my customer is worried about Cryptolocker infections in the network - CryptoLocker Ransomware Infections | US-CERT. Do you happen to have any best practices or general tips on how to use PAN tools to detect and prevent Cryptolocker from infecting hosts? Cheers, Tuomo

Tuomo by L1 Bithead
  • 4635 Views
  • 5 replies
  • 0 Likes

Can Nested Groups be used in the PAN (when using Group-Mapping)?

Hello, We are on PAN-OS 5.0.8 and use PA-5050, PA-5060, PA-200 (test boxes) and PA-3020's. We use the User-ID Agent running on VM servers. I have a couple questions, 1) When the PAN "loads" the group membership from our LDAP instance... we get the users that are part of the AD Groups we have "Group-Mapped"... Which is good and as expect...

Art by L3 Networker
  • 6169 Views
  • 1 replies
  • 0 Likes

Resolved! pdf summary report

I am having trouble finding how I would run a pdf summary report for a specific time period. If you click the summary report and then the date it generates for that day.Am I able to do this for the previous month?Thanks

haigroup by L1 Bithead
  • 3719 Views
  • 3 replies
  • 0 Likes

Resolved! Using Regex search in Monitor Tab

I want to make a search string with regular expression in Monitor tab --> TrafficLike that ( addr.src in (192.168.*?) ).If I have any miss syntax, please help me.Any document for Regular expression for searching in pan, please show me

Resolved! How to setup SSO on a Microsoft Surface PRO

Hi,We're using GlobalProtect client on many workstations. GP Agent is configured in SSO mode. This work flawlessly on Windows XP, 7, and some Windows 8 Pro PCs and tablets.I just got a brand new Microsoft Surface Pro running Windows 8 Pro 64 bits. For some reason, SSO won't work with this tablet. It looks like credentials are not sent to the GP ...

PatrickD by L1 Bithead
  • 4857 Views
  • 4 replies
  • 0 Likes

I'm having a problem with Canon printers communicating with an external IP (Canon site).

I'm having a problem with Canon printers communicating with an external IP (Canon site). They are trying to communicate to a particular IP on port 443 (simple, right?) but they aren't contacting the destination. I checked my Palo monitor and didn't see anything wrong but I thought I'd create fresh rules just for these printers. So, I've setup...

Resolved! Using Virtual Router

Hi all,Having a paloalto with multiple VR and subnet overlapping ( having multiple interfaces / Sub witth same subnet).EX: Int1 - IP: 10.1.1.1/24 - VR1 Int2 - IP: 10.1.1.1/24 - VR2 .....It works but does anybody knoes how: For management services, specify one VR or another. You can choose per IP but not per VR / Interface ? F...

VinceM by L5 Sessionator
  • 9800 Views
  • 9 replies
  • 0 Likes

How to disable the use of SSL compression on HTTP-TLS interfaces on the device.

Dear All,Please help me on this issue. The IT Security Audit team has scanned the PaloAlto Firewall PA-2050 and they found this vulnerability:*********************************************************************************************************62565 (1) - TLS CRIME VulnerabilitySynopsis:The remote service has a configuration that may make it ...

Resolved! Monitoring VPN tunnel by email

Hi all,Is there an effective way to send an email alert if a VPN tunnel is down? I checked several places in the web admin UI but could not find a good way to configure it.Thanks!PM

Securing IPSec VPN tunnel

Recently we are planning to roll out potentially hundreds of IPSEC VPN tunnels at our customer locations to access our own remote devices securely over the Internet. However, we don't have good control of physical access to these remote VPN devices managed by us and I don't want unauthorized access to our trusted network (in separate security zo...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels