General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4445 Views
  • 0 replies
  • 0 Likes

Resolved! How to force Panorama to push out new configs in serial?

One of the admins mumbled today that when changing shared objects in Panorama and pushing out new configs he needed to do this one by one regarding managed devices.That is click on sync, wait until the text "out of sync" changes to "ok" (or whatever it says) and then click to sync the next device until all are synced.Is there no button to "sync ...

mikand by L6 Presenter
  • 2240 Views
  • 1 replies
  • 0 Likes

Resolved! How to get friendly name of a vsys into the syslogs?

I have followed the order described in to create a custom log format for use by a syslogserver which is much more happy of getting the logs with spacesas delimiter instead of the commas.However I noticed that the $vsys variable only gives out text like "vsys1" instead of the friendly name which is regulary used by the vsys in all configuration ...

mikand by L6 Presenter
  • 2642 Views
  • 1 replies
  • 0 Likes

Stretching L2 VLAN's over IPSec tunnel

Hi All,I am facing a nasty situation where i need to connect two sites together using an IPSec tunnel over the internet. The nasty part is where both sites have a VLAN that needs to be interconnected.. both in the same subnet. I am wondering if it is possible to stretch this VLAN between the two sites using an IPSec tunnel.This gives the followi...

bsanders by L2 Linker
  • 10275 Views
  • 4 replies
  • 0 Likes

Process impact of "Security Profile Group" all set to NONE ?

Dear all,Does a "Security Profile Group" with all security engines selected to "NONE" would have any processing(/performance) impact?Reason the so, is for future readiness. Allowing NOT to have chaning ALL individual security policies, in case we would like to enable a security content engine in this "security profile group".Thanks in advance!Ki...

wimjuste by L1 Bithead
  • 2207 Views
  • 1 replies
  • 0 Likes

Update Software on HA passive mode

I try to update software and GlobalProtect on my PA configurated on HA Passive mode but it´s impossible. "Failed to check upgrade info due to generic communication error. Please check network conectivity and try again" :-SI download de software on web but its impossible to upload from my pc. Img is Invalid.Can you help me??Thanks,Best regards,

cmadurga by L0 Member
  • 2110 Views
  • 1 replies
  • 0 Likes

Resolved! Setup SSLVPN w/ Radius Auth and limit to specific A.D. groups

What is the best way to accomplish this? I have the VPN setup with Radius auth and working correctly but in its current setup, ANY A.D. account can connect to VPN. I have already created the security groups to reference for access in A.D., just not sure where to just the access.

SDorsey by L4 Transporter
  • 2402 Views
  • 1 replies
  • 0 Likes

Policy allowing ping/snmp not performing as expected

I have a policy which allows icmp / ping / snmp-base / snmpv1 / snmpv2 however when I review the logs the traffic which matches this policy is being caught in a lower policy that is more general (and we are trying to get rid of). Someone told me that because icmp/ping are layer 3 and snmp is layer 7 that they cannot share a policy. I didn't beli...

Resolved! Traffic log CSV Export Bytes Column

Hello everybody,Software Version 3.0.5when we make an CSV export for the traffic logs,we have three columns with Bytes, called- Bytes- Bytes Send- Bytes ReceivedAll three columns have for the same row the same Byte values.So, what is it for!I thought there must be different values!Can sombody explain this, or is there a fix in another release!?K...

indevis by L2 Linker
  • 7044 Views
  • 7 replies
  • 0 Likes

Resolved! Vulnerability Protection - Exceptions?

Dear all,We've got one, okay, two little questions on the configuration of vulnerability protection:Assuming we have a security policy configured with the pre-defined vulnerability protection profile named "strict". From that policy we're getting "LDAP: User Login Brute-force Attempt" (ID 40'005, severity high) log entries from time to time. The...

oschuler by L4 Transporter
  • 5673 Views
  • 4 replies
  • 0 Likes

Resolved! Reports - Best way to see top URLs visited?

I'm struggling a little with the documentation on how to generate useful reports.If I look in the ACC or default reports I can see destinations but they are simply a mix of raw hostname and rdns lookups - they might show a lot of traffic to, say, a88-221-183-148.deploy.akamaitechnologies.com, but they won't show that traffic was actually people ...

Resolved! In which order are the fields (variables) in defaultformat for syslog?

Hi all,I use a tool for loganalyzing which isnt too happy of the PA default format for syslog which uses commas and no spaces.Like so: abc,def,ghiWhat I need is: abc, def, ghior even better: abc def ghiBecause of that I need to create a customformat for each of the syslog types Config, System, Threat, Traffic and HIP Match.Putting the variables ...

mikand by L6 Presenter
  • 3102 Views
  • 2 replies
  • 0 Likes

SSL Weak CBC Mode Vulnerability

Our box was scanned by Qualys and the SSL VPN portal cames up with the following message:If possible, upgrade to TLS v1.1 or TLS v1.2. If upgrading is not possible, then disabling CBC mode cipher will remove the vulnerability.Any ideas how to disable CBC mode cipher on the PA device. Is there any impact on doing this ?rgdsJohan

u5273 by Not applicable
  • 3248 Views
  • 2 replies
  • 0 Likes

Resolved! What is session_inter_cpu_sync_err count on global count???

HelloI am installing PA-5050 (PANOS-4.1.10) to my customer.I am monitoring all status of device.I am seeing many increase of global count.I have a question.What is session_inter_cpu_sync_err count on global count???andWhat is dfa_sw_fpga_not_loaded count on global count???Please let me know.

Advantages of Virtual Systems...

...What are the advantages of using Virtual Systems, other than being able to divide Management and Reporting of "Virtual" firewalls. In my case, I have a DMZ, Wireless, Trust and Untrust networks connected to a PA 5020. Should I split up the DMZ and Wireless networks into their own Virtual Systems?Something like this...eth1/1 - Untrust(intern...

jambulo by L4 Transporter
  • 6083 Views
  • 4 replies
  • 0 Likes
  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels