General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

TrendMicro Officescan Updates aren´t recognized correctly

Hey folks,I´ve been having some trouble regarding TrendMicro Officescan. I made a policy which allows ‘trendmicro’, ‘trendmicro-officescan’ and ‘web-browsing’. The reason for adding ‘web-browsing’ was, that trendmicro usually get updates via normal http on Port 8080. I did this even though ‘trendmicro-officescan’ lists tcp port 8080 as one of th...

VUGD by L1 Bithead
  • 3413 Views
  • 2 replies
  • 0 Likes

Captive Portal don't show pages until refresh

HelloI'm having a curious behaviour with Captive Portal and web navigation, this is the situation.Every computer IN Windows Domain doesn't have any problems, user can navigate without issues, but computer or other devices (tablets, smartphones, etc...) which not belongs to the domain, when open a web page they are prompted to log in, when they l...

SOC_CSG by L4 Transporter
  • 2571 Views
  • 1 replies
  • 0 Likes

Resolved! how to make an exception for the specific case of vulnerability?

HiI found on this forum couple topic with examples but it desn't work for me - I don't know why.I have Thread lod filled with vulnerability: "HTTP OPTIONS Method" (id 30520) and "SSL Double Client Hello Cipher Suite Length Mismatch" (id 32467)I'd like to make exeption for it. But when I tryedto edit my Anti Spyware profile I cant find such idPle...

_slv_ by L4 Transporter
  • 7411 Views
  • 6 replies
  • 0 Likes

Problems with Custom Reports?

Has anyone else had issues with creating custom reports and then having them emailed via the scheduler? I have built an extensive custom reports list that allows us to see into the detailed traffic to discover infections, spyware, and an assortment of other information to discover things that the PAN does not alert us on. The problem is, that th...

craymond by L4 Transporter
  • 3051 Views
  • 2 replies
  • 0 Likes

Resolved! EDNS?

Has anyone implemented EDNS on their network? How does the firewall treat it? Is it just as DNS? Does it block it because the packets are too big?Does anyone know if there is a plan to make it its own discreet application?Thanks for the info...Ben

EDNS0 Packet blocked

Hi,We have internal DNS’s that send query EDNS packets andthose packets apparently are blocked by our Firewall (PA-3050 IOS Version5.0.2)I didn’t find any doc or discussion here about this issueCould someone help me to allow those packets pass throughour FW. (increase the DNS packet size as described for example below for ajuniper FW)Thanks a lo...

BSadozai by L2 Linker
  • 8602 Views
  • 2 replies
  • 0 Likes

Strange Log/Report Request

This idea might be a little strange so I apologize if it isn't completely clear.Currently, we get a daily PDF report from our PAs that include items like the top 5 egress interfaces, threats, etc. Our security team has been interested in these reports lately and I have been reviewing the findings with them on a daily basis. I feel that most of o...

TeamSpeak 3.x not recognized by App-ID

TeamSpeak is a voice app that uses a proprietary VoIP protocol. The 3.x version of TeamSpeak was no longer recognized by its existing App-ID, so I've captured some packets and submitted it to TAC for an update. This updated app-ID is targeted for release in the content database 380.

mancelin by L2 Linker
  • 4940 Views
  • 5 replies
  • 0 Likes

How to integrate PA syslog with Algosec ?

I am struggling with Algosec regarding the ability to forward syslog data with the right format.Traffic is hitting the Algosec server but is is not parsing any PA Traffic log data.Because the format and content in the traffic log is customisable I wonder if I am using the correct format here..Any tip is highly appreciatedRegardsStig

stig by L1 Bithead
  • 4697 Views
  • 3 replies
  • 0 Likes

PA incorrectly matching rule, lets C&C traffic out

One of our other IDS tools detected C&C traffic outbound. After further investigation, this traffic was allowed out through the Palo Alto because it matched on a rule that should have allowed ONLY the App-ID "github". The App-IDs that the PA was detecting and allowing were...-incomplete-insufficient-data-non-syn-tcp...why did this C&C ...

jambulo by L4 Transporter
  • 5486 Views
  • 3 replies
  • 0 Likes

Resolved! VPN Gateway to Gateway

We have over 100+ Gateway to Gateway VPN's to migrate to Palo Alto from an older technology. Does anyone know of scripting to streamline the migration process? Thanks for your time. Jerry

Jshively1 by Not applicable
  • 3476 Views
  • 3 replies
  • 0 Likes

WiFi with 802.1x and Radius authentication - source user in traffic log problem

HelloI'm thinking about WiFi network for my studnets. Now they are authenticating on HotSpot on Mikrotik AP's. They are complaining that must enter login and password so often.HotSpot also isn't good for me becase I can't see authenticated users in PAN logs.Is it possible to configure 802.1x authentication on AP and have in logs proper user name...

_slv_ by L4 Transporter
  • 12631 Views
  • 9 replies
  • 0 Likes

How to access console port on pan-2020 using a dial up modem

I have a single remote firewall (pa-2020) where I would like to set up the console port to be accessible via dialup modem. I called Paloalto support and they only were able to say that most people use a terminal server like an avocent type server to gain access to the console and haven't worked with anyone trying to use a modem. (I have one fi...

bigtone by L1 Bithead
  • 12539 Views
  • 12 replies
  • 0 Likes

yeoogh.com

seeing an excessive amount of traffic being tagged Suspicious DNS query (virus.virut:yeoogh.com) canno find any reference to this anywhere, ideas?

  • 24415 Posts
  • 125 Subscriptions
Top Solution Authors
Labels