General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

Resolved! some reports modification inquiries.

hi,i have some inquiries just recieved from a customer i dont think its possible but lets see if its achievable :.1- can we convert second to minute in reporting. 2- can we convert bytes to Mbytes in reporting .i tried but could not find anything.BR

SSL Decryption and Application Default

Best practice for building security policy is. For allow traffic always define the service as application-default, that way you only create session for applications on there default port and only perform application ID for those session this reducing the load on the unit from both a session and application id perspective.This works great, until...

Combination Signatiure in Custome Vulnerablity Signature

Hi when I create new combination Vulnerablity Signatures ( for examples create new threat ID 48888 inlcude threat ID 40000 or 40001 )1) I am not sure if ID=40000 attack happend , if threat log both have two log are ID=48888 & ID=40000 log , or which one of them ?2) if I put the ID=48888 in Vulnerablity Exception list , when ID=4000 attack h...

JeffJin by L2 Linker
  • 1941 Views
  • 1 replies
  • 0 Likes

Can Panorama manage Firewalls with Overlapping IP

HI.We have a requirement to manage a number of Palo Alto Firewalls. Some which have overlapping IP Addresses.Is it possible for Panorama to manage an estate with this configuration almost like an MSSPMany thanksRichard

rimpey by Not applicable
  • 3193 Views
  • 3 replies
  • 0 Likes

Cannot Ping

Hi,I have a small problem. I cannot ping and access the ip address of my external interfaces although I can ping their default gateway. I already assigned interface mgmt for each interface and allowed ping, https, ssh and response pages but no luck. I will use this to remotely access PAN and enable SSL VPN.Please help.Thanks,Rex

DHCP Not releasing IP addresses

Called support they said 'known bug' upgrade to 3.10 . Did the upgrade and IP addresses are still committed (lease expired for months in some cases) and not being released and added back into the pool. Any ideas on how to solve this?

Intermittent User-ID with eDirectory

We're on a PA2050, v4.0.5 using eDirectory Agent 3.1.2 (Windows 2008 srvr) connected to two eDirectory servers v.8.8.5.Users are being identified on the PA, but not all packets or sessions are showing a userid.If I filter a single busy source IP in the traffic log, over the span of a couple of seconds I might see 80% of packets with the 'SourceU...

Restricting data accessible by admin user/group for ACC/Monitor etc

Hi All,Can I, in a system that is NOT running multiple vsys, restrict the information that can be accessed, seen etc within the ACC, monitor tab etc. Like a pre-applied data filter is overlaying the entire use?For example, having a login that is for the head of a division, such as marketing, and when that use logs in, the only informationdisplay...

KatanaNZ by L3 Networker
  • 2952 Views
  • 2 replies
  • 0 Likes

Qos - Rewrite DSCP field

Hi all,Can PAN (i've got a pan 500)rewrite the DSCP field for some type of traffic(by Policy-Based routing or any way of doing this)?Indeed i need to rewrite the dscp field of any RADIUS traffic on ef to make it appears on the WAN as a high priority traffic.I can ask to my provider to do this on its routers but i prefer asking nothing and master...

steria by L0 Member
  • 3237 Views
  • 2 replies
  • 0 Likes

Resolved! Copy Policy Between VSYS

We are getting ready to start using multiple VSYS on our PA. Want to find out if there is a way to move or copy policy and objects from one VSYS to another?We have many policies in our original VSYS1 and want to move those policies and objects into the new VSYS which are now going to be configured for different Divisions in our organization.

Block Botnet Traffic

Hi All; Is there now or will there be a way to block botnet traffic based on thresholds. A few customers have fireeye and are looking for the same type of heuristic detection and blocking.Is there a way we can block unknown (Zero Day) botnets using the botnet piece?

amansour by L4 Transporter
  • 4950 Views
  • 2 replies
  • 0 Likes

Resolved! playboy.com and dropbox.com categorized as "unknown"

I just realized that playboy.com and dropbox.com are being catergorized as "unknown". "Unknown" has been set to alert only, and not block. I have no idea how long it has been like this, or what other sites may be doing the same thing. I'm on URL Filtering version 3713.Anyone else have this issue? Should I upgrade or revert my URL Filter version?

jambulo by L4 Transporter
  • 4659 Views
  • 6 replies
  • 0 Likes
  • 24357 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels