General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Accessing brightcloud.com returns block page

We are sometimes getting a block page when accessing brightcloud.com to report a site. The category returned is 'malware-sites'. The logs show that 'service.brightcloud.com' is correct, but 'brightcloud.com/support/lookup.php' and 'brightcloud.com/support/border-radius.htc' are URL blocked as 'malware-sites'.

cloughr by L2 Linker
  • 4227 Views
  • 3 replies
  • 0 Likes

Resolved! How to see historic load (CPU load) stats on 4020?

Let me start by giving the traditional, ive rtfm, this forum wont let me search it and ive tried hard to find it myself.I need one simple thing. How much load is on my FW and whats the load been historically? Where the heck can I find this? All I can find is the 'resource information' widget on the dashboard page.thanks!

choff123 by L3 Networker
  • 8846 Views
  • 2 replies
  • 0 Likes

Resolved! How to protect an https webserver in the dmz with vulnerability protection ?

Hi guys,the vulnerability protection is a really nice feature of the PA.If the PA is able to take a look at the trafficthis should work fine.But how does it work if the webserver in the dmz only accepts https connections ? So the possible attacker connects with https to the webserver.I guess i need to terminate the ssl tunnel at the pa to be abl...

cfpa by L1 Bithead
  • 5123 Views
  • 4 replies
  • 0 Likes

Traffic shaping and QOS clarification

HelloI try to do some traffic shapping for a server to control the traffic used by this server over internet, generally this was easy done over our old netscreen/juniper FWswhen i tried to figure it out over our PA 2020, i passed throught a not that the shaping is done only over egress port of the FW.and there are a document here that explain so...

daba1974 by Not applicable
  • 6130 Views
  • 2 replies
  • 0 Likes

URL filtering block page

I would like to customize our block page to show the ip address of the user.How do we add this on the html code of the blockpage?I have the entry <p><b>IP:</b> <user/> </p> in my block page, but it shows the username instead of ip address.Any thoughts?Thanks.

Resolved! Block FTP Brute Force Attemps - Threat ID 40001

Hello,I want to block Block FTP Brute Force Attemps.The default rule in the PA alert only in theThreat log.I added a new Vulnerabolity Protection Rule:Action: BlockHost type: Any (also tried Server)Category: brute-forceSeverity: AnyCVE: AnyVendor ID: AnyI placed the rule above al the default rules (see attachment).If I simulate a ftp brute force...

Resolved! AD Groups Not Showing Up

I'm using User-ID and Active Directory groups to identify traffic from specific people. The User-ID part seems to be working because Source User shows up in the logs and I can configure firewall rules using individual user-IDs. However, I'm having issues with the AD groups. The Palo Alto is able to pull existing groups from Active Directory a...

PSC_IT by L1 Bithead
  • 11235 Views
  • 4 replies
  • 0 Likes

Resolved! Multiple Block Pages?

Hello,Is it possible to create/select/use a custom response/block pages for specific URL categories? For example: can I have one specific custom response page for "unknown" categories, and another block page for "malware" categories?Thanks,-Paul

apc050 by Not applicable
  • 7726 Views
  • 3 replies
  • 0 Likes

Resolved! Best practice for committing changes in active-passive HA?

When making policy changes in an active-passive HA pair, do you usually edit and commit the policy using the active device, or the passive? I have always made my changes on the active device, but lately I've been thinking that because the management CPU usage on the passive device is much lower, it might be faster running the commit there. I c...

IPS \ Application Signature

Hi allI need to write ips / application signature to recognize sender and recipient in SMTPfor example:If smtp sender A send mail to recipent B - Allow.If smtp sender A send mail to recipent C - BlockI will be happy if anyone know how to do it.Alon

along by Not applicable
  • 2564 Views
  • 2 replies
  • 0 Likes

GP VPN dual factor auth, and contractor access.

I have two questions regarding the Global Protect Gateway / Portal (SAN the GP Licensing)- I am wanting to setup two factor authentication for users to authenticate to Global Protect Gateway/Portal with a (common) client certificate installed on their machine that our IT department installs. I currently have just AD authentication integrated but...

cmateam by L3 Networker
  • 4333 Views
  • 1 replies
  • 0 Likes

Chrome Updater not working if EXE is blocked / application not recognized

Hi,in one customer setup we face the following problem: We disabled EXE file downloading. In order do allow services to update we use an application filter with subcategory update and allow that traffic. Works like a charm for google-update, ms-update etc. However today I noticed tons of blocks from xxxxxx_Chrome_updater.exe (xxxxx being date, v...

  • 24429 Posts
  • 125 Subscriptions
Top Solution Authors
Labels