General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 604 Views
  • 0 replies
  • 0 Likes

Asking for the Cause of Path Monitoring Failure

Hello Team.

 

Through the logs below we found a path monitoring failure and have a question to discuss.

 

#show_log_system.log

2022/05/05 11:03:36 critical routing defaul path-mo 1  Path monitoring for static route destination 0.0.0.0/0 with next hop

...

AmyYoon by L1 Bithead
  • 3464 Views
  • 0 replies
  • 4 Likes

multicast test

PA is using cisco switch as external RP. Over a system I start the stream on VLC but I don't see the multicast address in multicast FIB. System is connected to network that is directly behind firewall. I use this tool multicast test tool (https://com

...

raji_toor by L4 Transporter
  • 2377 Views
  • 1 replies
  • 0 Likes

IPSEC s2s VPN between VM-50 and PA-3220

We've done plenty of s2s IPSEC VPN tunnels between our DC firewalls and branch offices. I have a new branch office which we are configuring the same way as the others, yet the IPSEC VPN is not operating as expected. The tunnel is showing as up and th

...

popeja by L2 Linker
  • 2166 Views
  • 3 replies
  • 0 Likes

Palo Alto blocks legitim applications

Hi everyone,

We have defined Risk App block rule which contains the app by risk category, characteristics and vice versa.

After upgrading PA to 10.1.5-h1 version it starts to block ssl, web-browsing, google-base, whatsapp and other apps which are not a

...

OGasimli by L0 Member
  • 1990 Views
  • 1 replies
  • 0 Likes

Cortex XSOAR search "contains" instead of "equals"

Hello

 

Is there a way to search a Domain in Minemeld with "contains" instead of "equals"?

As example:

We have entered *.blabla.com" in one of our Nodes.

I would like to search for blubb.blabla.com - which of course does not match.

Also "blabla.com"

...

Palo Alto Networks Approved
Palo Alto Networks Approved

Apply QOS for a particular Server published to internet

Hi Team,

 

  We have a SFTP server behind our firewall and its NATed to one of the interfaces of the firewall , we need to restrict the bandwidth to the  SFTP server from Internet. When clients from internet connects to the server for downloading files

...

Palo Alto Networks Approved
Palo Alto Networks Approved

Resolved! DH Group 24 phase 2

Hi all,

could you confirm that pan does not support dh group 24 in phase 2?

I've a peer that (just a test, is an android device with native ikev2 psk vpn configured) asks for that group and I got this error

DH group id 24 != 20, responding with INVALID_

...

N2Z2 by L2 Linker
  • 3154 Views
  • 1 replies
  • 0 Likes
  • 23936 Posts
  • 113 Subscriptions
Top Liked Authors
Labels