General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Palo alto 8. - keep booting after migrating to ESXi6.7

Hi Palo alto 8.- was installed EVE--NG at wmware Workstation. and it worked very well. But after migrating to ESXi 6.7, it keeps booting without stopping. 

Please see the below error message. 


Booting from Hard Disk...
Welcome to the PanOS Bootloader.


Hi

...

PAFrank by L2 Linker
  • 2883 Views
  • 3 replies
  • 0 Likes

BGP RIB Out AS Path

I am using BGP between two ISP's. On one of them my AS number is listed one time by each prefix. On the other ISP my AS number is listed 6 times by each prefix. The ISP with 6 AS numbers is a lower preference.

 

Anyone know why?

GFN182 by L2 Linker
  • 1694 Views
  • 2 replies
  • 0 Likes

PAN site to site VPN to AWS

We had a site to sit VPN between on premise PAN going to AWS.

The tunnel was established and does not show any downtime but the issue we encounter is that when the Tunnel Monitor IP(169.254.2.x/30) and (169.254.3.x/30) is not pingable/unreachable PAN

...

Putty cursor is stuck there after PA-VM starts

Hi, Palo-alto PA-VM-KVM-9.1.0.qcow2 is installed into GNS3 version 2.1.21 based on the below link. I try every configuration is same as the link. Two vCPU, 4G RAM and 8 interface. but after it start, it shows below message and then stop at the end of

...

PAFrank by L2 Linker
  • 3038 Views
  • 3 replies
  • 0 Likes

Resolved! IPSEC ikev2-send-p2-delete

Hi all, I have a IKEv2 IPSEC from PA to PA Firewall with tunnel monitoring enabled on one end. The tunnel suddenly went and the peer with no tunnel monitor is sending every 4 seconds a ikev2-send-p2-delete. 

 

What could be the reasons behind this beha

...

Uninstall Global Protect 5.2.5 via Intune Scripts

Good day,

 

I need to uninstall Global Protect from bout 100 user devices.

 

We deploy and remove application using Microsoft Endpoint Manager (Intune).

 

I have created a script using this uninstall command:

This command reported that it ran successfully o

...

Jabulani15_0-1639402078994.png

Vulnerability wrong action Palo

Hi,

 

We are having a weird issue in Palo. We have a FTP server and we can not access because Palo detects this vulnerability: 

Name: SSH User Authentication Brute Force Attempt

Unique Threat ID: 40015

The Palo action is "alert" for this vulnerability but

...

pic1.JPG
pic2.JPG
BigPalo by L4 Transporter
  • 1724 Views
  • 1 replies
  • 0 Likes

Resolved! JSON Miner with basic auth and an API key

I would like to have a miner to connect to the Pingdom API to pull a list of their US node addresses.   The Pingdom API uses basic auth and requires an "app key".

 

Their documentation references two HTTP headers, authentication and app-key:

> GET /c...

Resolved! GlobalProtect portal data collection available in logs?

Starting with PAN-OS 9.0 there is the ability to assign specific agent configurations based on software and app settings on GlobalProtect portal configuration.

It's possible to collect registry data from Windows endpoints under the new tab "Portal Dat

...

portal-data-collection-custom-checks-windows
Tobi by L2 Linker
  • 5321 Views
  • 6 replies
  • 0 Likes

Encryption mode between 6.0 and 9.1

My company are going to migrate upgrade one firewall from 6.0 to 10.1.

And I found below KB points out the supported payload options above and below PANOS 7.0.

Several IKE/IPSec profiles are using aes128 for ESP encryption, is it aes128 equal to aes-12

...

TonyTam by L1 Bithead
  • 1852 Views
  • 3 replies
  • 0 Likes
  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels