General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Firewall Configuration Essentials 101 Exam Retake Help

The end of last year I took the Firewall Configuration Essentials 101 v.4.1 exam. I didn't pass so I've spent some time studying and playing with Palo Altos. I returned to retake the exam and it doesn't show up under pending evaluations and I request to take it again and it says I already requested it. My understanding is that we are given three...

Resolved! Blocking lists of IPs

I'd like to block a list of IP addresses based on the ZeuS IP Blocklist. What is the best/preferred method for doing this on the Palo Alto? Thanks

sconley by Not applicable
  • 8721 Views
  • 5 replies
  • 1 Likes

ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational

Hi All,currently we have a Test-device from PaloAlto for evaluation (PA-5020, PANOS 5.0.2, AV-Sig 946-1309, App&Threats-Version 357-1692, URL-Filter 4044).Today I took a look at Threat Prevention Summary in ACC and saw a few Hits "Trojan-Ransom.foreign:madeleine.adclear.net" ID=4091550 with Severity "Medium".Then I was searching in ThreatLog...

Resolved! about control softether

Hi All,We would like to control softether with PA5020 which runs PanOS 4.1.10, but we can not find keyword "softether" in the applications.Anyone knows how to control softether in the PA fw?Thanks.Regards,Joy

Resolved! Manually trigger a logevent for a threat or a rule?

There is a test-command one can use in the CLI to identify which security policy a specific packet will hit.But is there also a command to issue a log-event?For example when you are about to manually configure triggers in your logserver to react on - otherwise im forced to send real traffic through the box and it will take some more time to acco...

mikand by L6 Presenter
  • 2753 Views
  • 2 replies
  • 0 Likes

Resolved! Need help with BGP in Active/Active HA

We have a pair of 5520's in Active/Active mode at a colocation facility. The colocation facility is handing off to us 2 separate LC fiber connections, each has it's own public /30 address but utilize the same AS number for our BGP. We have a /24 from the collocation facility that we can advertise on our PA HA pair. We want to stay Active/Acti...

Commit failure 4.1.10

After my Palo Alto 2050 in HA active/passive is up for about 1 week, I begin to get errors committing policies.Management server failed to send phase 1 abourt to client logrcvrManagement server failed to send phase 1 abourt to client sslvpnManagement server failed to send phase 1 abourt to client websrvrcommit failedThis gets worse as uptime inc...

EdwinD by L3 Networker
  • 7128 Views
  • 8 replies
  • 0 Likes

Resolved! The hunt is on - 0day for java 1.7u10

How many hours/days will it take for:1) Wildfire customers2) Regular customersto get protected by a threat-db update regarding the latest 0day exploit for java 1.7u10 (and possible java 1.6u38) as descibed in:Malware don't need Coffee: 0 day 1.7u10 spotted in the Wild - Disable Java Plugin NOW !http://labs.alienvault.com/labs/index.php/2013/new-...

mikand by L6 Presenter
  • 9509 Views
  • 14 replies
  • 2 Likes

Resolved! Upgrade Palo Alto version

Hi,I have 2 problems:1) I refresh the Software in my Palo Alto and i cant see the new versions 5.x. The last version that i can dowload is 4.1.11. Why i can refresh the new releases????? I attached a screenshot with the error and the succesfull connecting to staticupdates.paloaltonetworks.com2) I want to do an upgrade in this firewall from versi...

Resolved! Problem LDAP

Hi I have a problem with my firewall palo alto. I hope you can help meI had configured an LDAP server (Active Directory) in my Palo Alto. Also I had created two Atuhentication profile. One for VPN access and another for the administration of Palo Alto.But from yesterday that I made ​​a commit to add a new user to access the VPN "Authentication ...

QoS

Hi,Please help me out with the below issue and relevant links to configure QoS also will be helpful.I have configured QoS Profile for class 8 traffic. and QoS Policy .. and then assigned the QoS Policy to an physical interface.I have initiated some class 8 traffic and allowed the traffic to pass through the assigned interface..The issue is when ...

HA and stateless connections...

Ok, I have what may be a newbie type question, but it is one that I wanted to ask.In the PA 201 class, they teach for HA, that stateless connections are not synched.What is considered a stateless connection? I do not think it would be UDP traffic (although this comes to mind), but if I am running a audio or video call to the Internet, it is goi...

scantwell by L4 Transporter
  • 3790 Views
  • 4 replies
  • 0 Likes

Resolved! Global Protect portal authentication with LDAP fails

We have set up GP to authenticate against an AD server . User group mapping has done and u can pull the users . However, whenever you try to connect with one of the users from the GP client or portal web page , you get authentication fails message . Connecting with local db works fine . Any ideas ? I saw an article about spaces in the authent...

usvi by L3 Networker
  • 5612 Views
  • 9 replies
  • 0 Likes

Resolved! vwire policies

HI all,when we deploy the paloalto firewall in vwire mode and we have multiple zones (system zone, application zone, bdd zone), can we create rules to permit traffic between these zones through pan firewall ??thank's in advance

atelcom by L3 Networker
  • 6121 Views
  • 4 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels