General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Issue with Connection being Categorised as a Threat

For the past 5 or 6 days I've suddenly started getting a connection to a Palo GUI categorised as a threat, this worked previously without issue. When I've looked at the traffic logs it shows source and destination as correct but under the PCAP it says that the URL - 90.4.19.156 is blocked as medium risk\unknown, see below. I'm a bit flumoxed as ...

JonHill_0-1697793461251.png
JonHill by L1 Bithead
  • 1048 Views
  • 1 replies
  • 0 Likes

Virtual Adapter problem due to WMI error from windows 10 Update

GP client having issue with virtual adapter due to a windows upgrade can be fixed by running the following commands as an administrator via the cmd prompt. cd c:\windows\system32\wbemregsvr32 /s %systemroot%\system32\scecli.dllregsvr32 /s %systemroot%\system32\userenv.dllregsvr32 cimwin32.dllmofcomp cimwin32.mofmofcomp cimwin32.mflmofcomp rso...

Resolved! Link Group and Subinterfaces

Dear all,I'm trying to set up our link monitor configuration in our 440, and I ran into an issue. Each of our physical interfaces has many subinterfaces, so the question is:If I set up a Link monitor for a physical Interface with many subinterfaces, and only one of those subinterfaces fails, does it trigger a failover? Or do all of them have to ...

mR00t_s5 by L2 Linker
  • 2372 Views
  • 3 replies
  • 0 Likes

Configuring Incoming SSL Inspection for email

So, We have an on-premise Exchange server that is inside our firewall, so incoming and outgoing external email goes throught the firewall. We are having issues with file blocking on emails. We do have SSL inspection set on the traffic from outside to inside for email, but right now it is set to Forward Proxy and we receive no errors, the email i...

How do I block BBC iPlayer

I'm trying to block BBC iPlayer on our firewall, but still unable to block it. I need help to block it as soon as possible. I've checked online but no luck, please help.

TARAWA by L0 Member
  • 1938 Views
  • 1 replies
  • 0 Likes

Resolved! GP Client Download

Hi Team, Is there any way that we can download the GP Client? Apart from connecting to the GP Portal and downloading it? We need to test the new version by using it for few days on few machines before we get it into prod. So what is the best way, any suggestions please. In Cisco Anyconnect we have option in the Anyconnect Profile setting to st...

Resolved! Security Profiles

Hi All, I am bit new to this; may I know if the Security Profiles added in the ACLs works only if we create Decryption rule for that traffic? First it will decrypt the packet then start checking for the AV, URL, File Blocking, VP, Anti-Spyware and WF? Is my understanding, right? If we do not have Decryption rule in place the above profiles added...

Resolved! URL Category/Category List block and allow behaviors

I'm having an interesting issue where I've set up block action on almost all of the URL categories on a specific filtering list, including the risk categories. I've allowed three specific categories such as education, computer and info, and training and tools. Looking at the logs, I'm still seeing blocks. What I've noticed is the main catego...

jsalmans by L4 Transporter
  • 15862 Views
  • 2 replies
  • 0 Likes

Resolved! SSL routines::unsafe legacy renegotiation disabled

Hi, We are getting an increasing number of users reporting issues connecting through the Palo Altos when using OpenSSL3. Here is the information I have: "We've got someone working on moving to Node-18 from 14. We're getting issues in the build pipeline where OpenSSL3 is failing to connect through the proxy. We get the error unsafe legacy reneg...

Resolved! Issues with CHATGPT

I'm experiencing an issue where the CHATGPT login page is not loading everything in correctly and it's preventing our internal users from being able to sign in. I checked the network tab under the dev tools for my browser and saw that there were several items that were erroring out with the " 503 service unavailable" error. Could someone please ...

jthomasmccd_0-1697556174203.png
Google chrome network stats.png

Palo alto network HA link monitor failover Monitor Fail Hold Up Time

Palo alto network HA link monitor failover Monitor Fail Hold Up Time Hello good afternoon, thank you very much for your usual collaboration. I have a question, regarding HA Links monitor timers. When one has configured a track or HA Link Monitor, some interfaces, checking the HA timers, the one that corresponds is: Monitor Fail Hold Up Time ...

Metgatz by L4 Transporter
  • 5358 Views
  • 2 replies
  • 1 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels