General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4235 Views
  • 0 replies
  • 0 Likes

IPS Evasion

So are the techniques used in the following article realistic?http://www.sans.org/reading_room/whitepapers/intrusion/beating-ips_34137Palo Alto's PAN-OS 5.0 made it a bit harder, compared to the others at least.

mikoba by Not applicable
  • 5245 Views
  • 7 replies
  • 0 Likes

Dns Proxy

Hi,is there a document for configuring Dns proxy function with detailed explanation about properties in it.Thanks

Which CLI modes can be granted to a URL Filtering Profile Administrator without granting full CLI roles?

Which CLI modes can be granted to a URL Filtering Administrator without granting full CLI Admin roles?We want to be able to see which URL Filter profile group a user is in using the CLI commands for showing group membership.We would also want to be able to grep for URL request per user and assigned IP Address.Thanks in advance.PotStirrer.

Best way to update app and content without impacting traffic...?

Hello All,I am posing this as a question to the community, but in the latest release of app/content updates for PA, a new more focused signature was released. The new more focused signature was ms-wmi, and it was previously identified as msrpc.So....What's the problem? The problem is that if I update content, I will essentially be blocking an...

btwright by Not applicable
  • 3318 Views
  • 1 replies
  • 0 Likes

Resolved! Replacement of PA Management Certificate

I asked this in a recent class (201/205) but the instructor wasn't sure of the answer so here goes: Can the management certificate be replaced? We use a private CA for internal sites, as well as public certs for some devices. Thanks.

joehansen by Not applicable
  • 2865 Views
  • 2 replies
  • 0 Likes

Resolved! ssl decryption with upstream proxy

We have a squid server behind our pa fw like this:Client <-> PA FW <-> Squid Proxy <-> ASA FW <-> InternetDecryption of site https://addons.mozilla.org adds the IP address of our squid proxy to the exclude-cache list and all following ssl connection are not decrypted anymore. Is this expected behaviour?

azwicker by L1 Bithead
  • 7658 Views
  • 7 replies
  • 0 Likes

Resolved! Custom App Cloning

Last question for today (but thanks for the previous responses - you all are very patient with the newbies): Is it possible to copy application definitions in order to make a custom one? I was looking for a clone app process that would save time for custom apps that were similar in design. Thanks again.

joehansen by Not applicable
  • 3465 Views
  • 2 replies
  • 0 Likes

About schedule reports error messages

Hi All,We run a PA-500 with PanOS 4.0.8 and setup a schedule report profile to sendout daily custom reports. However sometimes it works and sometimes doesn't.I would lke to find out something wrongs, and see many error messages in the mailclient.log by cli "less mp-log mailclient.log".admin@PA-500-2(active)> less mp-log mailclient.logNov 04 ...

Resolved! About ftp passive mode App-ID insufficient-data

Hi All,We find that if ftp runs passive mode and go through paloalto fw, in the fw monitor -> logs -> traffic, we'll see the application should be identified as insufficient-data.I also find that there are just few bytes for every logs in the Bytes column.Anyone knows how to explain those results ?

  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels