General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Skype & unknown traffic

Hello PAN,

It seems to me that in order to have skype working correctly - particually with multi-site PA's with Site2Site VPN tunnels in between - it is nessesarely to enable both unknown-tcp & unknown-udp.

At least - all our connection problems / deli

...

sitecore by Not applicable
  • 2162 Views
  • 2 replies
  • 0 Likes

Resolved! Known Malware passing through PA to Client

Hello PAN,

Today I had a client get infected with the "Windows Privacy Module" Fake AV, This wasn't cought by either PAN OS or Trend Micro while a MalwareBytes scan found it and removed it no problem. Is there something more I can do to increase the o

...

Bvance by L2 Linker
  • 2575 Views
  • 5 replies
  • 0 Likes

Getting Syslog in through PA 500

I have a router just outside my PAN 500, ver 4.0.5. I need to get syslog information in from it for my PCI requirements. Here is my setup:

The following objects are defined:

INT-NPM               Syslog server, IP address 172.15.10.8

TWC-RTR            

...

u7483 by Not applicable
  • 2437 Views
  • 3 replies
  • 0 Likes

URL logging in TAP mode

I have a business requirement to log URLs visited in an "out of line" manner for reporting and usage. There is no requirement to block URLs and it would be of great advantage not to use VirtualWire at this stage(still in pilot).

I understand it is not

...

loki by L1 Bithead
  • 1640 Views
  • 1 replies
  • 0 Likes

Multicast Support

Hi Guys,

Does PAN support IP multicasting to allow one IP packet to be sent simultaneously to multiple hosts for use in multimedia applications and video conferencing?

I did read somewhere that multicast forwarding / routing is now supported from versi

...

Stateful Package Inspection Features

Hi Guys,

I was just wondering if you someone could clarify a few doubts that are lingering in my mind.

1.  IP Checksum Enforcement

     -  Does PA have an option to enforce header checksums for IP headers and UDP packets?

2.  QoS

     -  Does have QoS sup

...

Custom Reports and Wildcards

Hello KPers,

My goal: To create a report of top X users who attempt to access blocked categories.

My problem: I would like to exclude a set of userids that share a common prefix.

What I've tried: I've created a URL log custom report based off of action

...

Global Protect - External IP as source in VPN tunnel

Hello PAN.

Trying to figure out why my connection on the VPN client was behaving a bit sporadic I noticed that *some* of the traffic send to the firewall from my GPA was using source IP = my client public IP, rather than my client private IP.

So. Some

...

sitecore by Not applicable
  • 1798 Views
  • 2 replies
  • 0 Likes

Block and NOT Alert

Is there any way of blocking an attack (threat) but not logging it?

By this I mean I have some attacks that I want to drop but don't really want to get spammed in the logs because they are just 'noise' as far as I'm concerned.

apackard by L4 Transporter
  • 1807 Views
  • 3 replies
  • 0 Likes

Resolved! How do I enable ping to a non-mgmt IP address?

Hello,

I'm trying to enable ping to an external address that is not assigned to an interface? Is this possible? This address is used for NAT'ing purposes or to access an internal server.


I've done the following but I'm still not able to ping the addres

...

x by L1 Bithead
  • 3811 Views
  • 5 replies
  • 0 Likes
  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels