General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 221 Views
  • 0 replies
  • 0 Likes

Resolved! SNMP request failed

Hi, I try to request to PA-5020 with S.O. 1.4.7 some snmp traps for extract certain information about fo temp, cpu used, max sessions, etcetera.

But when i try to extract the information since my snmp tool called snmpcheck the result is "Request Faile

...

Juniper ScreenOS VPN to PANOS

I have a Juniper firewall with ScreenOS 6.2 that I am attempting to build a LAN to LAN VPN tunnel to a PAN firewall with 4.1.10.

A quick overview of my setup. We have to frequently setup networks that are "mobile" for company meetings or whatever. We

...

Dynamic updates download but not install on HA

We've got an HA pair of 5050s.  They both have a job to download and install dynamic updates at 12:00 AM.

I've seen occasions where one of the boxes will download but not install the update.  They are also set to push a version of the update to the HA

...

aglej by Not applicable
  • 2098 Views
  • 1 replies
  • 0 Likes

Resolved! Device Group and Template admins in Panorama 5.0

After upgrading Panorama to 5.0 I can't find the option to limit access for an administrator to a specific device groups or templates in the webgui. In 4.1, it was possible to configure this under "Administrators" in the device tab. This option seems

...

torm by L4 Transporter
  • 2209 Views
  • 2 replies
  • 0 Likes

Approach to manage FTP

Based on recent research by Palo Alto there appears to be a greater emphasis needed  on managing FTP.  What approach have you found  most easily to deploy?  The two options I can think of are:

1. Controlling who can do FTP

2. Only allowing FTP access t

...

HITSSEC by L4 Transporter
  • 1928 Views
  • 2 replies
  • 0 Likes

Resolved! Could M-100 support shared policy of panos 4.1 device?

Hello.

I wonder about M-100 could support shared policy of panos 4.1 device or not. I tested about that and M-100 could not sync of shared policy for panos 4.1 device but panos 5.0 device is doing well.

Thanks.

Regards.

Roh1 by Not applicable
  • 2110 Views
  • 2 replies
  • 0 Likes

Custom URL Filtering

Hi All

I am trying to get customer URL filtering working and it's not making much sense to me.

What I need to do is protect the Exchange server by allowing only connections to OWA and not ECP etc.

I've created a Customer URL Category called 'OWA Sites'

...

TDC by L1 Bithead
  • 4321 Views
  • 3 replies
  • 0 Likes

LDAPS TCP-636 shows as SSL

Im creating a rule base to limit port access to a Domain Controller in a DMZ. I want to allow TCP/636 (or LDAPS) to this server as well as a group of other applications.

The only problem is that there is no LDAPS application defined. The application L

...

jhickey by L3 Networker
  • 8620 Views
  • 1 replies
  • 2 Likes

Resolved! Policy forwarding question.

An over-simplified explanation of my setup.  Trust me, it just has to be this way. 

ethernet1/1 - Internet 1.2.3.1/24

ethernet1/2 - LAN 10.10.10.1/24

Nat/dnat/1-1 nat between ethernet 1/1 and 1/2

I have a traffic shaping appliance that I need to loop da

...

Next Generation Performance Testing for NGFWs

I found this video last day which might be interresting for some of you:

http://www.youtube.com/watch?v=yxdJNK2YAQU

"

Next Generation Performance Testing for NGFWs

Published on Mar 27, 2013

In this video, Jerish Parapurath, Sr. Technical Marketing Manage

...

mikand by L6 Presenter
  • 1574 Views
  • 1 replies
  • 0 Likes

Tftp brightcloud databese issue

Hi,

We tried to upgrade brightcloud version using seed file on support with tftp.

After sending file successfully, when try to install it gives an error like :

Error decrypting BrightCloud database: This image doesn't meet authentication requirements.

...

panos by L6 Presenter
  • 1588 Views
  • 2 replies
  • 0 Likes

IPS Evasion

So are the techniques used in the following article realistic?

http://www.sans.org/reading_room/whitepapers/intrusion/beating-ips_34137

Palo Alto's PAN-OS 5.0 made it a bit harder, compared to the others at least.

mikoba by Not applicable
  • 3570 Views
  • 7 replies
  • 0 Likes
  • 23614 Posts
  • 107 Subscriptions
Labels