General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Simple IPsec tunnel interfaces not passing MAC address

Good afternoon, I've got a simple site to site IPsec tunnel in non production that I'm having a problem with. Currently I have the mgmt interface up. I also have my trust/untrust interfaces connected to a Cisco switch on the appropriate VLAN's for the subs I have programed on my PA-440. For some odd reason, I cannot see the MAC addresses of...

danoman2 by L3 Networker
  • 4136 Views
  • 4 replies
  • 0 Likes

"Warning! authentication for output feeds is disabled", again

Hi Team, we installed Minemeld a few days ago and we are fighting with the old issue "Warning! authentication for output feeds is disabled". Our MineMeld instance runs as a docker Installation on Ubuntu 16.04 LTS. Installation was done with the documentations, which we are found here at PaloAlto LIVEcommunity (Minemeld using docker). MineM...

PEnzenmueller_0-1626259603605.png
PEnzenmueller_0-1626264985332.png
PEnzenmueller_3-1626260194258.png

Blocking ChatGTP

Hi Guys, @BPry @kiwi How do you go an blocking ChatGTP ? Seems like has not been defined in the list of apps yet (applipedia) Thanks, Pkarki

Pras by L4 Transporter
  • 17664 Views
  • 5 replies
  • 1 Likes

Resolved! security policy in monitor mode only

Hi, This is a new Palo Alto deployment. We used to have Cisco FTD as IPS and now we are replacing with Palo Alto. We have 3 devices (router and SDWAN) that we configured using vwire so all traffic to the DC would pass through the Palo Alto inspection as IPS. I would like to deploy the security profiles/group (vulnerability/antivirus/spywar...

ismailsh by L1 Bithead
  • 4460 Views
  • 3 replies
  • 0 Likes

API - Fetching URLs from Custom URL object

Hi all, we have a Custom URL category object, WL-URLS, which contains a number of URLs for a whitelist policy. I am looking to find some information on how to go about retrieving the URLs from this object via the XML API. My preference is the XML API as I am working with the Python PAN-XAPI library, however I'm struggling to find what I'm look...

365 tenant restrictions problem with office365-enterprise-access

Noticed that a few of our enterprise logins that were previously identified as "office365-enterprise-access" are now being identified as "ms-office365-base". I've found an article explaining some of the issues. I know that this was working flawlessly about 2 years ago, but something must have changed with MS or with palos enterprise access ap...

Sec101 by L4 Transporter
  • 3672 Views
  • 1 replies
  • 0 Likes

GlobalProtect and multiple AAD tenants

Hello - We've set up a GlobalProtect portal and gateway to connect third-party individuals to our VPN. We've configured it to use SAML for authentication, leveraging an Azure Active Directory Enterprise Application that we have configured per the Microsoft guide (https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-netw...

Entries in User-ID table show info pushed from XMLAPI never timeout

Hi guys,My customer previously used XMLAPI to push User-ID info to Palo Alto but they now have an Aruba Clearpass appliance which will be handling all User-ID information via Syslog.Due to software issues they cannot currently use XMLAPI between Clearpass and Palo Alto as the system has multiple vsys. Now the issue is that there are a lot of ent...

MelLi by L2 Linker
  • 8353 Views
  • 6 replies
  • 0 Likes

Resolved! New Anti-Spyware Signatures, false positives?

Hello, The latest application and threat content update this week added a couple of new anti-spyware signatures: medium 86759 AndroxGh0st Scanning Traffic Detection spyware alert medium 86760 AndroxGh0st Scanning Traffic Detection spyware alert These are being described as python malware exploiting your aws keys t...

axemte by L0 Member
  • 7660 Views
  • 1 replies
  • 0 Likes

Resolved! Certificate based Site to Site VPN (IKEv2)

Hello Folks, I am trying to build a site to site vpn between a Palo Alto firewall running 8.1.7 and a Checkpoint firewall. Settings are configured to use IKEv2 only with certificate based authentication. While the logs below are from lab setup, but the actual client problem are the same. PA and Checkpoint firewall certificates are signed by the ...

Udupi by L1 Bithead
  • 31549 Views
  • 12 replies
  • 1 Likes

SSL Inspection and SSL Labs

Outside of minimum and maximum supported tls versions and ciphers what are some things to look for on SSL Labs that would be breaking decryption. In the Palo decryption logs if it shows error "Early close notify" what would be something to look for as the root cause?

Claw4609 by L5 Sessionator
  • 6281 Views
  • 7 replies
  • 0 Likes

GP Compatibility on Windows Server

Hello, everyone. Does anyone know if you can install the Global Protect agent, on Windows servers, such as 2012, 2016, 2019???? Is there a documentation that tells me and confirms this? I see in the Palo Alto Firewall, that the computer does not give me the option to select a HIP OBJECT criteria, based on OS for example, for the Windows Servers,...

Matlu_NN by L2 Linker
  • 6301 Views
  • 6 replies
  • 0 Likes

Resolved! Is PA capable to scan for malware in Activesync/Outlook365 traffic?

Hi, We have PA-850 appliances with Wildfire and AV licenses. Recently we enabled the decryption of email traffic and now we are dealing with the data protection officer, he is asking us to detail what exactly is being inspected. At first I thought all attachments and URL were inspected. But then I found some information about link analysis only...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels