General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1896 Views
  • 0 replies
  • 0 Likes

Issue with Global Protect and HP 6510b laptop

the GP client software will install (v1.1.6) however, keeps connecting and then disconnecting.. seems to only be happening with our HP 6510b 32bit laptops.  Any other people experiencing this?

rrau by L3 Networker
  • 3219 Views
  • 5 replies
  • 0 Likes

Resolved! Lookup URL in Custom Categories

I'm currently trying to verify a list of URLs is blocked in my configuration.  So far I have tried the following commands:

test url <URL>

and

test custom-url url <URL> rule <rule name>

The first command returns what the site is classified as by Brightcl

...

c_luck by L0 Member
  • 5642 Views
  • 1 replies
  • 0 Likes

How to block Skype VOIP, Video only

Hi,

Microsoft is going to retire MSN and replace with Skype. Is there any way to allow only Skype messaging and block skype video, VOIP calls and file transfers?

It seems that the current PAN apps ID does not have any specific apps for Skype VOIP and e

...

Resolved! block-url threat level

I am trying to set up notification for blocked urls.  I can see block-url syslog messages when I set log forwarding to log severity level informational.  Is there a way to modify the threat level for blocked urls?  I would like to use a higher threat

...

oshcomp by Not applicable
  • 2720 Views
  • 2 replies
  • 0 Likes

Resolved! Static nat commit warning valid...?

When I commit my configuration, I am currently getting the following commit warning:

· - Rule '<public ip removed>-snat' shadows rule '<public ip removed>-snat'

I know why I am getting this and its because I have 2 bi-directional static source NATs wit

...

Rjschultz by Not applicable
  • 3862 Views
  • 4 replies
  • 0 Likes

Failing close..

I think Palo Alto refers to "Failing Close" as still allowing traffic through in the event of a failure.  And by default, I think the Palo Alto 4020 Fails OPEN.  Is there any way to set it to fail closed?

We are using our Palo Alto as more of a sensor

...

jambulo by L4 Transporter
  • 6349 Views
  • 4 replies
  • 0 Likes

Resolved! High rate on "flow_host_ha_encap_err"

Hi folks,

By chance (okay, we were troubleshooting another issue) we found a potentially strange issue on our active PA-2050 (there is a secondary (HA passive) PA-2050 in place as well).

1) We issue the following command on the prompt: show counter glo

...

oschuler by L4 Transporter
  • 6818 Views
  • 5 replies
  • 0 Likes

Resolved! New Java vulnerability, CVE-2013-0422, released 1/11/13

Hello all,

Just wondering if anyone might be able to tell me whether this vulnerability, CVE-2013-0422, is being addressed? And, if so, when could we expect to see a patch for this? Thank you!

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-04

...

u13987 by Not applicable
  • 3410 Views
  • 4 replies
  • 0 Likes

Wildfire questions

Ran a very quick and dirty test with Wildfire using a few malicious files I could find online. 2 out of 8 of these were judged "benign" by Wildfire (the 2 that were missed were very similar, so 1 out of 7 may be more accurate). Anyway, I know that no

...

mscox42 by L0 Member
  • 2352 Views
  • 1 replies
  • 0 Likes

Resolved! NAT to multiple https sites

It is possible to NAT to multiple internal https sites behind a single external IP address?  If so any guidance on how to create the NAT policy would be most apprecaited.

tjcarter by L1 Bithead
  • 7249 Views
  • 10 replies
  • 0 Likes

PA-500 dual internet connections

Hello all,

First post here!!

I have a PA-500 that I'm trying to add a second internet connection to and I'm running into an issue. The goal here is to keep the primary line (a bonded T1 solution) for corperate traffic such as VPN tunnels, remote connec

...

  • 24257 Posts
  • 117 Subscriptions
Top Liked Authors
Labels