General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 238 Views
  • 0 replies
  • 0 Likes

PA4050/Panorama Log Archive Strategy help

We have one of our new PA4050s running in TAP mode listening to our datacentre firewalls (the firewalls they will replace - these are ASFs running Checkpoint FW1). We are also running Panorama on test machine in our testlab. The PA4050s are logging l

...

fmd by L3 Networker
  • 4360 Views
  • 6 replies
  • 0 Likes

About regular expression at data filter for Korea SSN

Hello.

I was able to test function of data-filter for credit card number and social security number. so I created custom signature of data patterns for Korea social security number but I could not apply custom data pattern as a data filter.

PA box said

...

ttongfly by L3 Networker
  • 2004 Views
  • 1 replies
  • 0 Likes

Port Scan/Host Sweep settings...

What is everyone using for their Port Scan/Host Sweep settings in the Zone Protection profile?

Mine are at...

TCP Port Scan

5 secs

800 events

UDP Port Scan

5 secs

800 events

Host Sweep

2 secs

200 events

...I may have to fine tune it some more to lower the amoun

...

jambulo by L4 Transporter
  • 4644 Views
  • 1 replies
  • 0 Likes

Users With Two LDAP Accounts

Hi All,

Our domain administrators have two Active Directory user acounts; a standard 'username' for normal day-to-day tasks, and a 'username_a' for administrative work.  Occasionally, PA will pick up the '_a' account when checking group access instead

...

sclarke by L0 Member
  • 1705 Views
  • 1 replies
  • 0 Likes

How to configure Captive Portal NTLM auth?

I have a customer who has AD and is using the UserAgent sucessfully.

However, many users are not always logged in, or are using corporate hardware, so aren't logged in.

I want to configure Captive Portal for non-logged in users that uses NTLM to authen

...

User-ID Detection fails after install a second Terminal Server Agent

After installing 10 terminal server agents and 1 PAN-agent on a PA-2050 the appliance cannot connect to any agent.

admin@mi2-pan2> show user pan-agent statistics

Name             IP Address      Port    Vsys        State             Users  Grps  IPs   

...

mhuels by L3 Networker
  • 3427 Views
  • 5 replies
  • 0 Likes

Resolved! Multiple categories in Brightcloud

I've come across a few websites, when I run the URL in Brightcloud, can contain anywhere from 2 to 5 categories.

When a URL has multiple categories in Brightcloud, which one does Palo Alto Networks choose?

Here is a good example.

www.coffeed.com (coffee

...

Deploying SSL decryption with Public CA

I am trying to figure out how to deploy SSL decryption. I have it working in a test environment using an in house CA and by importing the cert. into my browser. As we have Firefox users and can't export the Trusted Root CA with a GPO, I am looking fo

...

IPSec Tunnel to Windows Server

I have learned, PAN will only build route based and not policy based IPSec tunnels.

We need encrypted communication between several Windows Server 2008 systems in the outback and a lot of them in the central office. Till now, we build a site-to-site V

...

mhuels by L3 Networker
  • 5586 Views
  • 8 replies
  • 0 Likes

User Identification Agent

Hi,

I have a question concerning the User Identification Agent.
Yesterday we had  a problem with wrong user identification. The problem is solved in the meanwhile  but it would be nice for me to understand how the agent works.

To solve  the wrong identi

...

Virus: use of the packet capture

Hi,

  I wanted to know what you usually do when you see a Virus detected on the PA.

  How do you check that it is not a false positive?

  Do you use the packet capture in the case of a virus?

  Does the name/id of the Virus help you to find more details

...

  • 23623 Posts
  • 107 Subscriptions
Labels