General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

Antivirus Signatures

Anyone knows what this new threat is? Name: Virus/Win32.WGeneric.ecphcy Unique Threat ID: 610234284 Create Time: 2023-10-03 18:19:57 (UTC) SHA256: 6bebb1b86738063e72821d2ee0018ff25e60859ec5a6093ad6d548f7e839cc62 Threat ID: 3185372 Current Release: 808871 (2023-10-03 UTC) First Release: 808871 (2023-10-03 UTC)

Monitoring Public Interface

Hi All, We are managing the HA firewall over public facing interface. Now trying to Monitor the same interface by creating the Interface Mgmt Profile and allowing SNMP. But i can ping the interface SNMP polling is not working. Is there anything else i need to configure? I can see 161 UDP is allowed on firewall. Regards, Sanjay S

Python Script For Interface ACL's, feedback

Wrote script to update interface ACL's in batch. User logs in to multiple firewalls, SSH conenctions saved in background, interface profiles are updated in a customized way per user input per firewall. Here's the Github link to the program: https://github.com/hfakoor222/Palo_Alto_Scripting There's a 2 minute video on multiple firewalls being...

hfakoor2 by L2 Linker
  • 4612 Views
  • 5 replies
  • 0 Likes

HA Panorama Active/Standby deployment - Read only access only to standby Panorama´s Server

Hi all, I have an environment with a lot of people wanting to get live traffic logs and policy rules for troubleshooting purposes, audit, etc., so we are thinking about to get all the read only admins connected only to the Standby web GUI and not to the active one and I´m not finding a way to get this done. We want to prevent this active pano...

BondonI by L0 Member
  • 1529 Views
  • 2 replies
  • 0 Likes

Using Regex in Cortex XDR XQL query

I want to extract a particular string from a particular field value from the Cortex XDR endpoint category and use it in XQL query. Is it possible to do that? For example from the below string (it is a field ) arn:aws:ec2:eu-abcd-1:123456789:instance/i-000000000000 I would like to extract the number 123456789 in an XQL query and use it to get the...

Support Portal Account unavailable

Hello, Impossible for me to connect to support portal after creating my account. Tried to contact support but it redirect me to support portal where i'm not authorized to access... Any idea how to unblock it ? Thx!

florianmaenhout_0-1696335667315.png

Sales Material for Clientele

Hi, We are an MSP that is looking for Sales Material or training for Palo Alto. I am having a difficult time finding any of this material on Palo Alto itself, so wanted to see what, if any, the community has to share. Thanks!

Resolved! SCEP on Panorama Error

We're testing SCEP on Panorama and getting an error saying "Unable to generate SCEP certificate, Certificate CA Retrieval Failed". Doing a tcpdumb nothing immediately sticks out, there is not untrusted CA error or anything like that. Is there any indication of what to look for to address this? System logs basically just say sslmgr SCEP certifica...

Claw4609_0-1696269367816.png
Claw4609 by L5 Sessionator
  • 2997 Views
  • 1 replies
  • 0 Likes

Resolved! create GlopalProtect Gateway with xml api

Hi i need to create GlopalProtect Gateway with xml api there is the url i send ---------------------------------------------------------- https://{{url}}/api/?location=vsys&vsys=vsys1&name=new-gw&key={{key}}&type=config&action=set&xpath=/config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/global...

Reset-Both for client/sftp server

I have been noticing lots of traffic between an internal client to one of our Sftp server where the log states SSH User Authentication Brute Force on Port 22 - Action Reset-Both. We have checked the client and has the correct credentials for the destination. What else should I check? The logs on the sftp server do not indicate any errors.

WLC -Radius Communication over Prisma SDWAN

Wireless user Can be authenticated successfully when WLC and Radius in Same LAN network OR WLC Communicate with Radius over MPLS. it is not working over Prisma SDWAN. I have checked from the radius server - No fragmentation issue BUT it gives access-reject to any users try to access via Wireless. ION version : 6.1.3.

MIB Files Download

Does anyone know where I can find the Palo .MIB files? Not the .my or .md5 files. I have already loaded them and well it was useless. Maybe it's my lack of intellect but they are missing the OID numbers. I also can't get them load when creating an SNMP walk.

  • 24357 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels