General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 550 Views
  • 0 replies
  • 2 Likes

Protocol Migration from Checkpoint

Hello,

We have some protocols defined on Checkpoint, and we are not able to traduce to PAN 4.0.

FTP_mapped is defined as Protocol 6, match SRV_REDIRECT (21,0.0.0.0,21), set r_mhandler

HTTP_mapped is defined as Protocol 6, match SRV_REDIRECT (80,0.0.0.0,

...

jvmartin by Not applicable
  • 2392 Views
  • 1 replies
  • 0 Likes

Routing Issues with Layer 3 Deployment

Hello all,

I'm having issues with internet access on different subnets. I have attached a diagram on my network. The Server VLAN has Internet access but the rest somehow are not managing, I'm seeing the traffic in the logs but nothing seems to be work

...

devere by L2 Linker
  • 11148 Views
  • 7 replies
  • 0 Likes

APP-ID for IPSec over UDP

Hello Community,

the standard IPSec APP-ID did not handle complete IPSec-NAT-Traversal (UDP 4500) ...

I've noticed that reestablishement of NAT-T is not detected successfully.

This causes problems with temporary droped IPSec-Sessions.

Any idea ?

Regards,

C

...

cmock by L1 Bithead
  • 2023 Views
  • 1 replies
  • 0 Likes

[botnet] some url filter out.

Hello all.

on the firmware 4.0.1, we have botnet monitoring function here,

but on the report, I can see some of normal url(false positive) that trigger the botnet module.

like ..

"211.234.239.48/upload/notice/polling40_v.ipml"

can you please tell me how I

...

bhlee by Not applicable
  • 2660 Views
  • 1 replies
  • 0 Likes

How to Manage External Users via UIA/PAN

If the organization has Users who are contractors/sub-contractors (deskless workers); how can you manage these Users via the PAN if they are not members of the Domain?

Would AD deskless worker objects need to be created AD-side for them to be prompted

...

Pan OS 4.0.1 and searching

I've noticed that after updating to 4.0.1 when searching for user Traffic everyone keeps showing up.  I am clicking the apply filter.

Its also happening on the Threat, URL and Data Filtering.

Is anyone else seeing this problem?

We already have a suppor

...

HTTP Brute Force Attempt

I was contacted by a major government entity about an HTTP Brute Force attack/attempt coming from my institution.  Their IDS triggered on a researcher in my organization attempting to login to one of their training websites.  The user forgot their p

...

rule shadows

I'm trying to clean up our rules, specifically the shadows.  I've run in to one rule that is shadowing 6 others:

- Rule 'rule208' shadows rule 'rule211'

- Rule 'rule208' shadows rule 'rule212'

- Rule 'rule208' shadows rule 'rule292'

- Rule 'rule208' shad

...

bhelman by L2 Linker
  • 2271 Views
  • 1 replies
  • 0 Likes

Resolved! Routing IP address range through firewall

As somewhat of a newby to PAN, I need to ask how do I go about passing an internal public IP range outbound through the firewall and NOT natting it.  This certain range of addresses will only connect to one other public IP address (different, externa

...

global Protect

Hi All,

I tried to configure Global protect on my PA500. According to docuementation available on site, I configured Global Protect Cert Auth but If I try to create a Global Protect server cert signed by GP Cert auth, I have an error (Failed to genera

...

VinceM by L5 Sessionator
  • 3042 Views
  • 2 replies
  • 0 Likes

Resolved! Reach Management Interface via SSL-VPN

Hi all,

I have a little problem, I've installed a PA-500 and configured SSL-VPN, it works fine, I can reach the internal network correctly but I can't reach the management Interface.

This is the scenario:

VPN Clients:

IP: 10.31.31.10-10.31.31.254

Manageme

...

triitech by L1 Bithead
  • 3248 Views
  • 3 replies
  • 0 Likes

youtube won't work with web-advertisements being blocked

Does anyone know how to get around this?  We have enable web-advertisements to be blocked within our URL filering.  When going to www.youtube.com and some other sites, the site is there but will not play content.

Any ideas how to get the best of both

...

kamish by L3 Networker
  • 9763 Views
  • 13 replies
  • 0 Likes

Palo Alto Dev Adapter for BBNA

Hi,

does anybody know whether there is a working device adapter for Palo Alto Firewalls (Version 3.1.7) for integration into BBNA (BMC BladeLogic Network Automation)?

If there's none, I'll probably have to write a simple adapter myself.

Thanks!

  • 23745 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels