General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! User ID Agent - Monitoring logs

We've noticed errors in the Monitoring logs of our Windows servers running the PAN Agent ID software.

The User ID is working fine but the error is continually filling the logs. (error screenshot attached)

 

PAN o/s 10.1.6 h3 and the Agent ID versio

...

Screenshot 2022-12-22 151042.jpg
vij by L1 Bithead
  • 2384 Views
  • 1 replies
  • 0 Likes

Resolved! threat log and traffic log time not match

Hi All, 

 

Same session id, see 37 entries in threat log at 9:28 and only 1 entry in traffic log at 11:16
Session ended reason is tcp-rst-from-client

There is a threat log before there is a traffic log
How to explain such a long time difference? Does a

...

Hsinyu by L1 Bithead
  • 1314 Views
  • 1 replies
  • 0 Likes

Resolved! dashboard session expire time

Dear Team,

 

If I look at the bottom of the dashboard, I can see 'session expire time'.

 

I think that option refers to the last time I logged out.

 

But the date info doesn't seem to fit

 

I would like to know what the setting is and why the time i

...

CHOEKyungJun_1-1671788957044.png

A way to correlate the logs for DNS Sinkhole?

Dear and valuable Live Community Members,

 

One of our customers came to us with some questions in regard to the issues he is facing to correlate the logs for DNS Sinkhole, and we are wondering if there is a solution to it.

 

The customer currently h

...

RMA replacement

Hi All,

 

We will doing a RMA replacement for PA-3220. The faulty unit is cannot access anymore from GUI or CLI and it's managed from Panorama. We only have the backup configuration and not the device state. So, what we should?

1)Do we replace the fa

...

Momoj by L2 Linker
  • 3437 Views
  • 13 replies
  • 0 Likes

RFC1918

Basic trust to untrust policy I see internal address sending snmp to addresses like 10.0.0.1, 192.168.1.x.

 

Do people create a policy to block internal traffic going to RFC1918 on the untrusted interface?

How to set 2FA to local superuser

Prerequisites

Currently,  user has two admin accounts.

  1. Default local admin account(Superuser)
  2. New local admin account synchronized with Cisco Duo(Superuser)

End user has to consider how to treat “Default local admin account”.

As a result of considerat

...

Config Change Tracking

Looking for suggestions of how others track config changes: who made the change and what changed; similar to config audit but for every change made over time. The goal is training and accountability.

 

I’m aware of Rancid, which may or may not work a

...

No "Apps Seen" / Policy Optimizer data on Panorama

Hi,

We have a new deployment of Panorama using Datalake storage.

Log data from the firewalls is successfully coming through to Panorama, however, there is no "Apps Seen" or info shown for apps under Policy Optimizer.

Rule Usage data is available, and

...

SARowe_NZ by L3 Networker
  • 3066 Views
  • 4 replies
  • 0 Likes

Management interface dropping packets

Hi,

My monitoring system is detecting packet loss on my panorama device. When pinging the DG there is no packet loss. When checked the interface stats on the cli I can see the below.

 

admin@MANPANORAMA01(primary-active)> show interface management


--

...

Is the IP on any EDL?

Is there any place that I can put in an IP address and see if it is on an external dynamic list somewhere?  Going to this site:https://docs.paloaltonetworks.com/resources/edl-hosting-service and clicking around hoping to hit the right one (such as Az

...

How to implement BGP and eBGP on Palo

Hi,

I am migrating WatchGuard to Palo and there seems to be a lot more configuration options on the Palo. 

 

WatchGuard configuration is below. What is the best way to configure this within Palo?

Where is the option to set default-originate?

 

router

...

  • 23582 Posts
  • 103 Subscriptions
Top Liked Authors
Labels