General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! security policy in monitor mode only

Hi,

 

This is a new Palo Alto deployment.  We used to have Cisco FTD as IPS and now we are replacing with Palo Alto.  We have 3 devices (router and SDWAN) that we configured using vwire so all traffic to the DC would pass through the Palo Alto inspec

...

ismailsh by L1 Bithead
  • 1831 Views
  • 3 replies
  • 0 Likes

API - Fetching URLs from Custom URL object

Hi all, we have a Custom URL category object, WL-URLS, which contains a number of URLs for a whitelist policy.

 

I am looking to find some information on how to go about retrieving the URLs from this object via the XML API. My preference is the XML A

...

Epotts0 by L0 Member
  • 849 Views
  • 2 replies
  • 0 Likes

GlobalProtect and multiple AAD tenants

Hello -

 

We've set up a GlobalProtect portal and gateway to connect third-party individuals to our VPN. We've configured it to use SAML for authentication, leveraging an Azure Active Directory Enterprise Application that we have configured per the M

...

Resolved! New Anti-Spyware Signatures, false positives?

Hello,

 

The latest application and threat content update this week added a couple of new anti-spyware signatures:

medium

86759

AndroxGh0st Scanning Traffic Detection

spyware

alert

medium

86760

AndroxGh0st Scanning Traffic Detection

spyware

...

axemte by L0 Member
  • 5581 Views
  • 1 replies
  • 0 Likes

Resolved! Certificate based Site to Site VPN (IKEv2)

Hello Folks, I am trying to build a site to site vpn between a Palo Alto firewall running 8.1.7 and a Checkpoint firewall. Settings are configured to use IKEv2 only with certificate based authentication.

 

While the logs below are from lab setup, but t

...

Udupi by L1 Bithead
  • 20595 Views
  • 12 replies
  • 1 Likes

SSL Inspection and SSL Labs

Outside of minimum and maximum supported tls versions and ciphers what are some things to look for on SSL Labs that would be breaking decryption. In the Palo decryption logs if it shows error "Early close notify" what would be something to look for a

...

Claw4609 by Cyber Elite
  • 3349 Views
  • 7 replies
  • 0 Likes

GP Compatibility on Windows Server

Hello, everyone.

Does anyone know if you can install the Global Protect agent, on Windows servers, such as 2012, 2016, 2019????

Is there a documentation that tells me and confirms this?

I see in the Palo Alto Firewall, that the computer does not give

...

Matlu_NN by L2 Linker
  • 2395 Views
  • 6 replies
  • 0 Likes

Next Hop in default route using DHCP Comcast modem

Hello Group,

 

I am setting up a PA-200 in my SOHO with comcast as my ISP.  I have comcast for my isp and am using DHCP to optain my IP address.  My question is this.  Per the setup guide, if I check DHCP under the IPV4 tab, and check, Automatically cr

...

BryanMay by L1 Bithead
  • 4925 Views
  • 5 replies
  • 0 Likes

Factory Reset

I was in the middle of setting up a PA 850 and in the end needed to conduct a factory reset. I issued the commands to put into maint mode and was able to log in with maint@ip and the serial number as the password through putty. I had to step away for

...

Resolved! Minimum Code for PA-415/445

Hello, looking at the PA-415 for a small office and I can't seem to find the minimum code required.  The datasheet shows performance results using OS 11.0 but there's nothing to indicate if you can use 10.2 code.

TIA!

  • 23590 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels