General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

App and Threat Version fail when update.

When I download and install (choose sync HA) the update App and Threat version 386-1889 (2013/07/30), Dashboard in my device show info App Version and Threat Version mismatch (view attach files). And when I commit any change, HA will not work (view attach files). I must rollback to old Version and my device is ok. When I reinstall new update 3...

Multiple ISP load balancing

We currently have an Internet setup as shown in the image below. ISP1 is Metro Ethernet running over a disparate fiber path at 100Mbps symmetrical bandwidth. ISP2 is ATM over 1Gb Fiber, with a disparate fiber path and 250Mbps symmetrical bandwidth. ISP1 and ISP1 are running BGP. I use padding to control my preferred link, which changes depe...

EdwinD by L3 Networker
  • 6492 Views
  • 2 replies
  • 0 Likes

Resolved! ACC and filtering App Category or Sub Category

I couldn't find an answer after searching for a bit, so I thought I'd ask the community.In the ACC tab within the PANOS web UI, if I select an application in the report, within the Application Information section that appears I get links for the App Category and App Sub Category. I can then drop the filter for the Application, and work with the...

Resolved! No exempt profile in threat details

Dear,We have some traffic that is getting blocked because of a strict vulnerability profile.I want to exempt a certain IP from this profile.But when I click on details in the threat logs, there is nothing filled in the "Exempt profiles"Which is strange because it is blocking the traffic because of some profile, only it will not show me which one...

mr.linus by L4 Transporter
  • 5641 Views
  • 8 replies
  • 0 Likes

Resolved! NAT for ldap

I need to configure my PAN to allow LDAP and port 636 inbound from 10 specific IP addresses for authentication with a software company. Can't figure out how to do this correctly.

jpzynski by Not applicable
  • 4465 Views
  • 3 replies
  • 0 Likes

How to create custom vulnerability signature for SIP packets?

Hi,we are trying to create custom vulnerability signature for triggering on the specific string in the udp packet payload with destination port 5060. Unfortunately there is no context for SIP. We used "Pattern Match" and chose "unknown -req-udp-payload" as a context. We applied a Vulnerability protection profile to the security policy (a rule ...

Resolved! Spoofed IP address zone protection of vwire

Dear,We have created a zone protection profile with protection against "Spoofed IP address".We have put this protection profile on a vwire interface.Question:What will happen since a vwire interface has no IPs?Will this "feature" be ignored, or what will happen / how can we configure this to apply the protection?KR

mr.linus by L4 Transporter
  • 6091 Views
  • 6 replies
  • 0 Likes

Suspicious DNS Query's

Hello,We are running version 5.0.6 for a few weeks now and looks very good.We see now also in our threat detection the following threat "Suspicious DNS Query : ......" and this is blocked.This is very cool to block at dns level spyware and malware but the disadvantage of this is that the source client ip address is always your DNS server.So you ...

obor by L1 Bithead
  • 4154 Views
  • 1 replies
  • 0 Likes

Cant login to PA-VM300 via ssh or HTTPS

Can anyone help me here.. I recently installed a PA-VM300 and all efforts to login via https/ssh has proved abortive. I had to work my way via CLI to connect via http. Also everytime i click on commit on the PA-VM300, I get logged off , and always need to re-login? anyone experienced this?Olu

Resolved! Client certificate and LDAP authenticate on Global Protect

HelloI have a question.My customer want to use Global Protect.He want 2-factor authentication.User authentication client certificate on 1-factor.And then user authentication ID/PW to Active Directory by LDAP on 2-factor.I have searched and seen below."We're not using another form of authentication" on page 7 in this DOC.Can Global Protect use bo...

Resolved! Are there way that fw forward url & data filtering logs to ESM system by syslog??

Hello,I know there are not log type of url & data filtering on syslog server profile.But my customer want to receive two logs to ESM system by syslog.Are there ways?Please let me know it if there are.And I have a question.Panorama is received this logs(url , data) from FW.Why is it able to receive?Thanks.

Resolved! Help setting up internet connection

Hi thereWe're in the process of cutting over to a new internet connection and I'm trying to get our PA 2050 configured to handle to new IP range but I'm a bit stuck. We've been assigned the 111.69.54.112/28 subnet with 111.69.54.113 being the default gateway.Currently I've set the external interface to 111.69.54.112/28 and configured a virtual r...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels