General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PAN-OS 3.17 - High Availability - Not Sync Properly

I am configuring 2 PA 2020's for a customer and am having the following problems w/the HA pair once built. Has anyone came across this issue?***** Text below was sent to my internal technical team *****I have HA setup, configured and the failover active/passive tested okay w/no issues. However the synching of the running config is having issue...

jpeadro by Not applicable
  • 6322 Views
  • 6 replies
  • 0 Likes

Response page with button continue?

Hi,Is it possible to make in response pages the button "continue"? I want to make a response page warning that this url it's not permitted, but if the user wants to continue press this button.Thanks

COMIP by L2 Linker
  • 3269 Views
  • 4 replies
  • 0 Likes

About Data-filter function for Korean language.

HelloI tested Data-filter function that can recognize English character with regex.But Korean language with regex was not recognized by Date-filter function.I think PA cannot recognize double bytes character such as Korean, Japanese and Chinese at Data-filter function right?We need PA to recognize 2 bytes character at Datafilter function.Can you...

ttongfly by L3 Networker
  • 2806 Views
  • 2 replies
  • 0 Likes

about FAST FLUX attack for BOTNET and spreading malignant code.

HelloNowadays BOTNETs are using FAST FLUX technic that makes change regularly their Hyper Link, URLs and IPs interval about 2-5 minutes. Also I guess you known kind of above attack. so It could not be prevented denying IP address, URLs and others.I wonder that PaloAlto device how protect and prevent fast flux attack for BOTNET activity and sprea...

ttongfly by L3 Networker
  • 2614 Views
  • 2 replies
  • 0 Likes

QoS Profile Classes - Maximum Egress (Mbps)

In looking at the documentation for configuring QoS, I'm not clear on the QoS Profile Classes/Maximum Egress value. Is this PER SESSION or TOTAL? We're playing around with limiting (before we block it entirely) P2P traffic. I would like to knock the user down to something low (like dial-up speeds). So do I set this at Class 8 and .05Mbs or s...

bhelman by L2 Linker
  • 6915 Views
  • 5 replies
  • 0 Likes

Resolved! Default Wire Policy Question

We're putting in a 4020 in Wire mode and to start I dont want to block anything. I just want traffic to pass through so I can gather stats. I am assuming my policy will be something like this:TRUST UNTRUST Any Any Any AcceptUNTRUST TRUST Any Any Any AcceptLook right ?Thanks,Justin

jhickey by L3 Networker
  • 3711 Views
  • 1 replies
  • 0 Likes

Resolved! Disable logging for specific users

Is it possible through rules to disable logging for specific users? We have a child protection devision in our police dept that uses peer-to-peer and bittorrent -- which makes our threat level sky rocket. Is there a way to prevent that traffic for those specific users from showing in ACC?

Regexp case sensitivity

I'm trying to create case insensitive regexp for data filtering, however couldn't find any standard regexp way which would work.Also when I tried to workaround and created following data pattern [Vv][Ii][Dd][Ii][Nn][Ii][Aa][Mn] (which is perfectly valid regexp in my opinion) I received data-object-patter-validation error.Any suggestions how to ...

SimasK by Not applicable
  • 4646 Views
  • 2 replies
  • 0 Likes

Scheduling PANOS command using ssh?

I'd like to have a command run on our PAN at a scheduled interval.I know this can't be done "on-box" but I should be able to schedule a job to connect to the PAN and run the command.I've been experimenting with plink and whilst I can make it connect and give me an interactive shell, I simply cannot get it to connect and then run the command I wa...

allow icmp type 3

Hello,How to configure policy to deny all icmp types, but only allow icmp type 3. Is it possible at all?Thanks!

ahtiakel by L1 Bithead
  • 3748 Views
  • 2 replies
  • 0 Likes

SSL VPN Problem

Hi All,I'm having teething problems with our SSL VPN client. The client installs fine on Win7-64 and XP. I've followed the recommendations for Win7-64 and the installation all seems fine. Everything works fine when establishing the tunnel. My policies and LDAP auth are working as I would expect. However, after a random time (usually no longer ...

PA cannot recognize a filename that base64 encoded from SMTP

HelloI checked PANOS 3.1.x that could recognize double bytes character for Korean language.When using file-blocking profile, PA could recognize a filename using 2 bytes character, Korean language, from web-browsing, kind of web-based-mail application. but PA wrote encoded string, that used by BASE64, from SMTP application.I know that SMTP have u...

ttongfly by L3 Networker
  • 3564 Views
  • 1 replies
  • 0 Likes

URL Filtering - Changes in 3.1.7?

I have a PAN that has been running 3.1.6 quite happily.We have an internal Exchange/OWA server so we have rule in place to allow inbound access to it, and the rule uses a URL filtering profile that allows only the IIS virtual directories needed to access the OWA services.Yesterday I upgraded to 3.1.7 and noticed this morning that immediately aft...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels