General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

QoS: only ever matches default-group

I'm obviously missing something simple here, but nothing I've tried makes a difference.

 

Creating a QoS Profile to configure the 8 classes:  works great.

Creating a series of QoS Policies to classify AppIDs, URLs, users, etc into difference classes:

...

fjwcash by L4 Transporter
  • 4412 Views
  • 9 replies
  • 0 Likes

Prisma global protect

Bonjour,

Lorsque l'on configure la gateway global protect sur Panorama, que doit on renseigner dans la partie " IP de la gateway externe" sachant qu'on se connecte à une gateway France North ou France south dans prisma?

 

Pareil que doit on mettre po

...

Sarou22 by L2 Linker
  • 631 Views
  • 3 replies
  • 0 Likes

Resolved! Site-to-Site IPSEC issue and MTU

Greetings all!

 

I've run into an interesting issue and I'm hoping someone here may have some previous experiences or maybe something on best practices I'm missing.

 

Basically, we have a site-to-site loopback interface set up and we have several tunnels

...

jsalmans by L4 Transporter
  • 12471 Views
  • 7 replies
  • 0 Likes

Resolved! DNS sinkhole , some questions

 

I'm a SOC analyst, and we receive firewall logs regarding DNS sinkhole alerts. I'm trying to understand them better.

I have received multiple logs of this type, and I want to make sure I understand them correctly.

In this log, the domain that was q

...

Virtual Wire & Virtual System assignment issue

Hi,
I hope this message finds you all well 

I have some configurations questions regarding virtual wire in PAN-OS FW that support multiple virtual systems, i would like to get some official documents regarding virtual wire configuration and assign it

...

T.Zidane by L0 Member
  • 290 Views
  • 0 replies
  • 1 Likes

Alternative for Data Lake

Are there any cheaper alternatives of Data Lake? Let's say, our retention is 6 months and we'd like to store incidents and all related information for 1-2 more years somewhere else. Has anyone used/using something like that, e.g. Amazon S3

add TWISTLOCK_CONSOLE env variable to twistcli

i am not sure if this is the right place to suggest this, but i think it will be really handy to have such an env variable i can set up in my zsh profile file (for example), and not having to write `--address $TWISTLOCK_CONSOLE` every time. similarly

...

NGal by L0 Member
  • 338 Views
  • 1 replies
  • 0 Likes

RabbitMQ App-ID Misidentified

We have a Security Policy Rule with Application rabbitmq, and Service is application-default. In the same Security Policy Rule, we allowed the dependant applications amqp and SSL. When we test traffic, in the Traffic log, we see it matching the zones

...

DNS Rewrite and NAT Traffic and without NAT Traffic

Hi,

 

We have scenario in which two different subnets in DMZ Zone communicating with Internal Zone but 

  1. One subnet is allowed to communicate with Internal Subnets (Internal Zone) without NAT (Source or Destination).
  2. 2nd subnet is allowed to communicat
...

A.jauhar by L0 Member
  • 284 Views
  • 0 replies
  • 0 Likes

Resolved! Wildcard URL for Non-HTTP/HTTPS traffic

 

Hi, this question may have been answered before, but I can’t find it anywhere on the LIVEcommunity. We need to allow traffic for the mssql-db app for a specific wildcard URL (*.example.com). It needs to be a wildcard because the alternative is to a

...

R8787H by L0 Member
  • 861 Views
  • 2 replies
  • 0 Likes

GlobalProtect Client Certificate not Found

Hi All,

 

I am trying to demo pre-logon and am really struggling with the client certificate authentication side of things.

 

I've generated a Root CA on the firewall which has been imported into the Personal and Trusted Root Stores of the machine.

The po

...

  • 23707 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels