General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4120 Views
  • 0 replies
  • 0 Likes

Content Updates Failing

Hi,I am trying to update the content (application and threats) on our PA-500 firewall running version 4.1.8-h3. However, this is failing, and am getting the message below. Any ideas on how this can be fixed?OperationInstallStatusCompletedResultFailedDetailscontent update failed with the following messages: No matching apps package found in panup...

Resolved! Packet capture in traffic log

Hello,i have a hundreds pages of traffic log, how can i find captured packets? Searching for green arrows manualy is annoying, can i somehow use some filter or something?

Interface by L3 Networker
  • 7326 Views
  • 4 replies
  • 0 Likes

Dynamic Block Lists and IP's

I saw this line in an article about Dynamic Block Lists."as our threat team identifies malware, they automatically take any URL or IP associated with that threat and will include it as part of the PAN-DB URL filtering database. "Does this mean that the PAN-DB contains all the IP's that the URL's resolve to? I would not think so since that one IP...

jmayne by Not applicable
  • 2600 Views
  • 2 replies
  • 0 Likes

Panorama Template conflicts with base device config

I am in the process of building out my Device Groups and Templates to standardize configurations across all sites. Our sites are standardized in a way that we can actually apply device configurations across multiple sites. After the base templates are applied all I need to do is apply the site specific data such as their local subnets and up add...

Poe by Not applicable
  • 5692 Views
  • 2 replies
  • 0 Likes

URl Filtering Security policies

In URL Filtering Security Profiles, there are a few actions that can be configured for each URL category.- Alert – permits access to the category and logs it- Allow – permits access to the category, but does not log it- Block – blocks access to the category and logs the access attemptCan you confirm that “block” always...

Detecting Data Patterns in Large Files

A question came up in class today in regards to Detecting Data Filtering Patterns in Large Files. Does the firewall buffer the file being inspected by the Data Filtering Patterns so that it can detect all occurrences of the Data Pattern before sending the file out of the firewall? Or would the recipient get a truncated version of the file sinc...

jwolach by L4 Transporter
  • 5953 Views
  • 6 replies
  • 0 Likes

Resolved! Adding Users to a Security Policy

I have agentless User-ID setup on my PA-500 (Software is 5.0.4). I can do the command "show user ip-user-mapping all" and see a list of user accounts associated with IP addresses (not all of them in the domain, but I'm assuming that it's just what has been seen through the Security Logs on the domain controllers). I've set up the Group Mapping...

uscit by Not applicable
  • 6335 Views
  • 3 replies
  • 0 Likes

User activity reports

I'm getting a bit of a funny one on my Panorama. When I run a pdf UAR for a user using the "last 30 days" option - I only get the detailed reports on web activity from the 2nd of August till the 16th of August. When I change the date option to the last 7 days I get from the 16th till today. Anyone any idea why I'm not getting the full 30 days wh...

TIrvine by L1 Bithead
  • 6319 Views
  • 6 replies
  • 0 Likes

Resolved! Skype false positive

Hello guys,About skype: how to know, when users realy use skype and when PA detects only false positive? Because now i have lot of log with "secure.skype.com" URL and PA detects it as skype application.. I would be grateful for an explanation.

Interface by L3 Networker
  • 6552 Views
  • 10 replies
  • 0 Likes

Resolved! Product Support

Hello,I'm wondering what 3rd parties offer support for PA?In addition, what does it cost to get direct support from PA as opposed to a third party?Thanks,Chris

grkchr by Not applicable
  • 3060 Views
  • 3 replies
  • 0 Likes

Resolved! Global Protect for ios/android

Hi,What are the reasons to use Global Protect Gateway license (for software at markets) instead of Xauth for ios/android ?Can someone tell all of them?Thanks.

Resolved! VM-Series-L2 firewall configuration?

Hi,does anyone have VM series configured like L2 firewall (intra-host communication) and well working?My interface ethernet1/4 is configured like L2 and have leg to portgroup (vlan xx) glued to zone abcd....Polices was created in way to deny SSH between zones abcd to abcd and allow other traffic, but SSH pass anyway from one guest vm to another ...

Tician by L3 Networker
  • 7477 Views
  • 6 replies
  • 0 Likes

Cisco Systems VPN Adapter

Hi,I see there is now support for Cisco Systems VPN Adaper however I am trying to figure out what exactly is supported am I now able to connect to the firewall via cisco IPSEC VPN from the Cisco VPN Client software or is this support for something else?I ask as we have engineers that connect to many sites and global rotect is not geared this way...

bcsgroup by L2 Linker
  • 12259 Views
  • 16 replies
  • 0 Likes

PA-200 SAP router dropping tunnel

We have a PA-200 (running OS 5.0.4) being used as an SAP router. NAT translating between an inside 17.20.x.x address and an outside static global address (IP = a.b.c.d) which pushes all traffic to its VPN peer IP e.f.g.h. When a completely new session is initiated all goes well with phase 1 (time = x) and phase 2 (time = 6x) being accepted. Howe...

PeterG by Not applicable
  • 2588 Views
  • 1 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels