General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

Help Explaining Interface Counters

I have a couple of ports on different PA's showing various interface errors. Just looking for some help deciphering and find a solution for the interface. PA-7000 series running PAN-OS 9.1.13. Output for the "show counter interface" command is below for each interface. Thanks!! Interface: ethernet2/7------------------------------------------...

Devices managed through Panorama - Unable to export entire device config

Hi, When I have a firewall managed through Panorama, I am unable to figure out a way to export the devices complete config file in xml. I have tried Export Panorama and devices config bundle but I only get a few basic settings in the XML. No policies, or Interface settings. Even when I log into a PA manually and export the config I only ge...

Skype Stun Not Allowed due to incorrect UDP Port in APP-ID

Hi, One of my customers is having an issue where by Skype is not being allowed through despite the Stun and RTP applications being allowed through: Previously we'd used the 'skype' and 'skype-probe' but this was not matching with the traffic. Looking through the traffic logs the traffic is being denied because Stun is running on a high level po...

skype-allow-rule.png
skype-traffic-deny.png
Gukaaran by L1 Bithead
  • 13235 Views
  • 8 replies
  • 0 Likes

Credential agent crashes LSASS

Setup a 2016 RODC so I could use the Credential Agent.As soon as I try starting the agent as system, the server pops a message that I will be force restarted in 1 minute. It non-gracefully reboots in 1 minute. I tried agent v10 and v9. Perms and settings appear fine afaik, and suppressing a/v didn't help. Palo sent me a suggestion to roll back p...

HA - Path-monitoring - VLAN-TAG-Vwire environment

HA - Path-monitoring - VLAN-TAG-Vwire environmentHello good afternoon, as always thanks for the support and for the good will as always, it is much appreciated. I have the following question: Environment detail: HA firewall, Vwire, with Vlan Tags by subinterfaces of a portchannel ( Ae1 ). Is it possible to apply some kind of Path monitoring,...

Metgatz by L4 Transporter
  • 1985 Views
  • 1 replies
  • 0 Likes

Common Criteria EAL4+ with AVA_VAN.5 / Advanced methodical vulnerability analysis

#AVA_VAN.5 #CommonCriteria ##AdvancedMemethodicalVulnerabilityAnalysi I'd like to know if the newer firewalls with PAN-OS 10.X are AVA_VAN.5 certified regarding common criteria Advanced methodicalvulnerability analysis? Other vendors disclose e.g. EAL4+ with AVA_VAN.5. Found nothing at: https://www.paloaltonetworks.com/legal-notices/trust-cen...

I can't change password for Active Directory in VPN with Client Palo Alto (Global Protect 6.0.3), PAN-OS 10.2.2-h2 and RADUS Server Windows 2019.

Hello for all, I'm with problem in Palo Alto Firewall Model 3260 with PAN-OS 10.2.2-h2. One week ago, I had a Firewall with PAN-OS 10.0.8-h4 and in this version I change my password of Active Directory in VPN with Global Protect (Global Protect 6.0, 6.0.3, etc....), but now! I have a Firewall with PAN-OS 10.2.2-h2, and in this version a can´t ...

Resolved! Home use Licensing

I recently had a PA220-R's license expire and in the past PA was trying to charge 10k+ for getting a new support contract for a small home-use firewall. Has this changed at all? Would be nice to get a new support contract+licenses for a decent home-use price.

SubZ3r0 by L0 Member
  • 2855 Views
  • 2 replies
  • 0 Likes

USER ID Lateral Movement reported

We have USER-ID Agent installed on 2 Domain Controllers, using a Service account to authenticate to the Domain referencing the Workstations (Laptops) We use Rapid7 InsightIDR for our SEIM solution and USER-ID on a DC to authenticate/identify Workstation details. The SEIM is flagging USER-ID traffic from a Workstation to another Workstation as ...

Windows Update feed in minemeld

I'm trying to find out if there's already a miner that someone's created for windows update URLs/IPs. I am using the O365 one with reasonable success, so I'd like to incorporate the windows updates into minemeld and take advantage of the dynamic list functionality for some of my rules. Thanks!

Resolved! VM for the Palo alto firewall

Will take a backup from the VM (NVA) for the Paloalto firewall that exists in the Azure environment, The query, is whether taking a backup will *affect/not affect* the services or interrupt the network traffic managed by the Paloalto NVA during and after the backup of the NVA?

Resolved! PaloAlto failing communication for Kali Linux

Kali, Windows and RHEL installed in a lab behind Palos on a directly connected Vlan. Windows and RHEL have no issue communicating to internet or ping firewall interface. But for Kali, Palo captures show only receive and no transmit or even drop packets. All 3 are getting IP from DHCP on Palo interface, and share common NAT/security policies, ...

image.png
image.png
image.png
image.png
raji_toor by L4 Transporter
  • 4133 Views
  • 2 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels