General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

How to find ALL the links related to a website.

Looking for the better idea. User reported xyz.com site is not working, When I look at the firewall logs xyz.com was allowed in firewall. And I filtered the logs with source IP for 5mins time frame and found deny logs for particular IP address 1.1.1.1 I am not sure what is the url for 1.1.1.1, In such case what you will do to find the URL for 1....

Resolved! QoS - Guaranteed bandwith

Hi Team! I'd like to ask about QoS Guaranteed Egress, because I'm not sure I understand the topic well. (used devices PA-220 and VM-100) Here's what I need to do: My branch office bandwith is limited by the ISP to 30Mbit/sec (ethernet1/1 WAN interface). I need to shape traffic to guarantee some bandwith to different kind of traffic classes...

Resolved! How to configure per-client certs on GlobalProtect?

NOTE: the freeware pfsense firewall can configure a working VPN with user passwords and user certs (2FA) inside of 20 MINUTES. With Palo Alto Networks, I'm on WEEK 6. Where I am at:1) I have GlobalProtect working with password auth. (Had to call tech support, who knew what steps were missing from the documentation.)2) I want to have 2FA: so, I s...

dannyman by L2 Linker
  • 14257 Views
  • 14 replies
  • 0 Likes

PAN-DB URL Filtering Categories list for PAN-OS 10.1.x

Does this document below apply to PAN-OS 10.x.x or just for <9.1 Where Can I Find a Complete List of PAN-DB URL Filtering Catego... - Knowledge Base - Palo Alto Networks We are trying to block URLs on both 9.1.x & 10.1.x, but it seems there are URL categories on the document that are not available for all versions of PAN-OS. We implem...

Resolved! ctd-agent-connection error

Dear Team, The following error is occurring in the firewall type : ctd-agent severity : high event : ctd-agent-connection description : Failed to establish GRPC connection to service : failed to start grpc connection with address ----- I would like to know what causes this error and how to fix it If anyone has had a similar experience, p...

Paloalto cannot resolve specific FQDN through Nslookup & "fqdn refresh" is not working on CLI console

Hello all, Our client company uses FQDN A and B that Nslookup the same IP, and the firewall has a DNS access policy applied with these FQDN.Recently, the customer deleted the DNS of B, and if it is normal operation, it should be normal service with FQDN of A, but DNS blocking issue occurred. In addition, entering FQDN refresh from the CLI does n...

Hip profile cannot check process

Hello all,Hope you are doing well!Currently, we are checking the process through Hip profile setting.
However, some PCs are facing an issue where the Process Check information list is not displayed. I checked the HIP Object settings and found that they are using the same settings and that the same program is running on the PC.In addition, I trie...

XML API response for predefined EDL only returns 1 value instead of the entire list

Hi there,Has any one been able to successfully use the XML API to query the predefined EDL lists and have the ENTIRE list returned back in the response? When I attempt to query say the panw-torexit-ip-list, the XML response only returns using this command: https://<firewall>/api/?REST_API_TOKEN=**********&type=op&cmd=%3Crequest...

mslavens by L1 Bithead
  • 1599 Views
  • 1 replies
  • 0 Likes

Failed to update threatss&apps

I have a Paloalto cluster and in the active FW I get the following error when trying to download and install the dynamic updates. Anybody can helps me? Regards

Alpalo_0-1669278366702.png
Alpalo by L4 Transporter
  • 2003 Views
  • 1 replies
  • 0 Likes

Mobile device traffic - source users

Mobile users connect to wifi through to active directory authentication but in log-trafic- source users name not showing.(For laptop/desktop source users showing perfectly- this authentication also through AD)

PDF Report outlook missing attachment

Hi, my firewall is set to send PDF reports daily, attachments are usually not visible when receiving emails using Outlook. I tested sending reports to Gmail, but I can't see attachments when I use Outlook to receive emails. But you can see in the web version of Gmail Studying the source code of this email found that Outlook can display attac...

PNG File Chunk Length Abnormal

A strange trend we're seeing the application ms-update return a threat of: PNG File Chunk Length Abnormal It's been occurring since June and the png files related to the threat are named: sw_saber_rey.png sw_saber_luke.png sw_saber_vader.png Anyone else come accross this threat and application/file reference?

jr_dot by L0 Member
  • 6003 Views
  • 1 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels