General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Tool to generate 'phash' style hashed passwords?

We have a need to create password hashes offline, is there a tool or script available to take a cleartext password and generate a phash?For example, the audit team wants to be able to select a password and generate the hash, so we can later paste into a firewall when provisioning the 'audit' user, even though I would never know what their passwo...

snocc by L0 Member
  • 21917 Views
  • 6 replies
  • 0 Likes

Resolved! Can I have a static bi-directional NAT rule and a PAT rule working together?

Hi, I currently have a static NAT bi-directional policy, number 6 in the screenshot, that publishes an internal server (LAB-Skype) on Internet using a public IP (LAB-Skype-pub). This works fine. Now I need to add an exception for port 443 for that public IP, which needs to be redirected to port 4443 towards the same internal server. I tried ...

Commit Warning for Antispyware

Hi guys,Trust all is well. After the firewall upgrade to version 10.2.1/ 10.2.2, we are getting the following errors after each firewall. Changes/commits are executed successfully. And everything seems to be working without problems. Warning: spyware-profile AntiSpy-Alarm-Only(id: 251) is considered duplicate of AntiSpy-D(id: 258)Warning: spyw...

The existing DNS servers and LDAP server is reachable by the management interface. The additional set of DNS servers and LDAP server setup will have t

Hi Team, The existing DNS servers and LDAP server is reachable by the management interface. The additional set of DNS servers and LDAP server setup will have to access via an interface other than the management interface. Could someone please assist me on this (PA-5220s in a HA configuration). Thanks you

Custom App-ID for Tinder

Good morning all,We have had a situation occur where students and teachers are 'liking' each other on the Tinder dating application (www.gotinder.com), bit of a strange one but surprisingly looking on our PAN the firewall doesn't recognise it as an application?Has anyone created it as a custom application and can share the app-ID for it or give ...

Merging two Palos Config

Hello everyone I have two Palo PA-850s with software version 10.2.2 that are running in different locations. To merge all the services to one location, I must merge two Palos configurations from ACLs, NATs, and Interfaces to a single device (or the HA pair). As far as I know, I can export the .xml config, edit it, and then import it to Palo, but...

SCP Import returns Server error : Failed to import logdb

When exporting logdb file using SCP to different linux machines there would be no errors but when importing the same file we receive the error: Server error : Failed to import logdb, the files would list during importing but the error would appear near the end after a pause, and the original logs are all deleted from the firewall, the test is d...

Resolved! VM series firewalls not sending logs to Panorama

Hello again all, My next hurdle is figuring out why my VM-Series firewalls aren't getting their logs to the panorama server. I've checked the following soo far: Network path between the firewalls and panorama look good. it's allowing ICMP and all TCP. Managed collectors (local to this panorama an an HA panorama) show green, in sync, green...

Verac22 by L2 Linker
  • 4238 Views
  • 3 replies
  • 0 Likes

shadowed rules not showing in cli commit

I need get the shadowed rules name list and remove them, my firewall OS version is 10.1.11, the shadowed rule warning is not there any more in commit, is there a switch on command to show this warning?

RedHat IPA authentication on Palo Alto

Hi, When using RedHat or CentOS IPA authentication on Palo Alto firewall, we may ran into challenges when adding LDAP Server Profile and GP Clients functionality related issues.LDAP Server Profile - On a traditional RedHat or CentOS IPA server there will be multiple ou under the Base DN, In order to work properly along with Palo Alto Server prof...

vjbennet by L0 Member
  • 4711 Views
  • 3 replies
  • 0 Likes

Palo Alto Firewall - Exporting Log Database via FTP/SCP is not working

Hello All, We are currently doing a POC with Palo Alto firewall in a customer network. The POC got successfully completed. But while exporting the log database from the appliance we are hitting we issues. After checking the admin guides, found the logs can be exported via FTP on the "Scheduled log export". Via GUI:Provided the FTP path, credenti...

Resolved! masterd: restart exhausted, rebooting system | Palo Alto's process

Hi all, I'm trying to understand better Palo Alto's proccesses analyzing tech-support file with dedicated PANTS tool. I can clearly see that, this pa2020 with 6.0.9, reboots due to masterd process: -------------------------------------------------------------------------------------- ----------------------------------------------------------...

Masterd_exhausted.JPG

Update of Default Trusted Certificate Authorities?

I am just curious - in which way is the list of trusted certificate authorities (WebUI: Device > Certificate Management > Certificates Default Trusted Certificate Authorites) updated? By firmware update or by dynamic update? Regards,Sylvia

sylvia by L1 Bithead
  • 7268 Views
  • 4 replies
  • 1 Likes

PSE software firewall associate

Dear all, I need your help to find my exam question, I am really confussed some question about PSE software firewall associate. Please help me to find right answer. 1. What is the preferred way to analyze traffic logs generated from multiple data center firewalls? a)Use Palo Alto Networks Prisma Access console to view all firewall logs. b)Log ...

Tugsbold by L0 Member
  • 3467 Views
  • 1 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels