General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

DNS queries - custom signatures

Hi all,does anyone know how can I identify (if possible) DNS queries from client toward particular web sites. The aim is to see and eventually block some DNS queries that try to resolve forbidden sites. I can't use URL filtering license.Thanks

PAN as a monitoring device vs NetFlow

Hi, we have a customer that needs to have more visibility about the traffic in their network (applications, ports, bandwidth, vulnerabilities and virus) and will like to use PAN instead of activating NetFlow at the switch level.This will imply that each access switch in each floor will have a span port that will mirror traffic to a tap port in P...

SSL VPN - Client sees no gateway?

Excuse what is probably a very novice problem.I've gone through the guide on setting up a SSL VPN (1.3.0) on PAN 4 for our new PA-500, and I can successfully log into the NetConnect client and receive an IP from the VPN pool, etc. However, I cannot ping or otherwise reach any internal systems. When I run traceroute to an internal system, it time...

emccrea by L1 Bithead
  • 12857 Views
  • 11 replies
  • 0 Likes

MacDefender Signature

Has anyone seen a lot of activity around the MacDefender Command and Control Traffic (event ID 13104 and 13108) spyware threat since the introduction of these signatures? I believe first add of these signatures was 248-993 and then updated in 249-1005. I am trying to get a handle on the numerous daily "blocked" events we are seeing for these c...

MGoodnow by L4 Transporter
  • 2418 Views
  • 1 replies
  • 0 Likes

Upgrading SSL VPN client - is it automatic?

Hi.I've noticed that the SSL VPN client 1.3.0 has been released.Currently, I have 1.2.0 active on my PA's.If I activate the 1.3.0 release, what impact will this have on the clients? Will the upgrade be seamless and automatic, or will it require interevention (especially in the case of 64 bit Windows clients).Anyone done this and can shed some li...

dagibbs by L4 Transporter
  • 4412 Views
  • 4 replies
  • 0 Likes

Reason to upgrade to 4.0.2 ? ! ?

Just recently upgraded to 3.1.8Like others here, wondering the REAL advantages of upgrading to 4.0.2I don't want to run into the issues missed by QA in version 4.0.1 that I have seen heremanagement console not working via httpsQos issuesIPSEC Tunnels not workingwould like everyone's feedbackThose who have upgraded for a specific feature setThos ...

mthomasson by Not applicable
  • 11507 Views
  • 17 replies
  • 0 Likes

Error parsing pdf file

Using PAN OS 3.0.8 on PA-4060, I got the normal correct report Daily_hfw_Reports_20110511.pdfBut when upgraded to PAN OS 4.0.2, the first page incorrectly changed to Error parsing pdf file as shown in 1-20110518Daily_hfw_Reports.pdfPlease kindly give me any solution for correct report.(^_^)Songkrant

songkrant by Not applicable
  • 20207 Views
  • 5 replies
  • 0 Likes

Resolved! More info needed on a virus named JS/Trojan-Clicker.agent.cobte

We have a website which is not functioning properly because a javascript menu named quickmenu.js is being flagged as having the virus JS/Trojan-Clicker.agent.cobte. I get not search results ion the web for this, and in the threat database, all I have is a name and number. Please provide more details surrounding this virus so that we can ascerta...

edrabek by Not applicable
  • 4525 Views
  • 4 replies
  • 0 Likes

Injecting a default route into OSPF

I have an OSPF virtual router configuration with two interfaces. One interface (int1) is part of the default area (0.0.0.0) whereas the other one (int2) is not. There is a static default which points to the next hop on the non-OSPF interface network.I want to announce or generate a default route into the OSPF area and have clicked the "Allow ...

quist by Not applicable
  • 14773 Views
  • 2 replies
  • 0 Likes

IKE pre-shared key: is there any forbidden character?

Hi Everybody,when configuring an IPSec VPN between our PAN appliance and both Cisco and CheckPoint devices, we had problems with using a long pre-shared key, which included special characters too (e.g. more than 30 letters, both small and lower case, numbers, "!", "$").Is there any constraint with the key lenght, or any forbidden character?Thank...

Bucche by L2 Linker
  • 8129 Views
  • 2 replies
  • 0 Likes

Resolved! Upload page for tech support

I am really suprised that the SSL cert for the web page used to upload tech support files doesn't have a trusted cert. Is that by design, because uploading my firewall config to an untrusted SSL site makes me feel a little weird... Especially when I am sending the config to a security based company ?

PDFs and MS-updates

Hi PAN Experts,Has anybody faced problem of MS-updates and PDFs not able to go through a PAN in vwire mode ? policy is allow all in either direction. Version is 4 0 2.BR

Problem with IPSec and GRE

HelloI have a bg problemThe need is to create such a configuration: external IPSec tunnel and next GRE tunnel inside the previous one. IPSec tunnel must be created between my PA device and external gateway. GRE tunnel mus be created between my cisco router inside my network and other cisco router behind external gateway. Then there must be allow...

  • 24431 Posts
  • 125 Subscriptions
Top Solution Authors
Labels