General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Cannot log into firewall if authentication profile specifies an AD group instead of AD username

So last Thursday we upgraded our PA-5220s from 9.1.10 to 10.1.5-h1 and everything went incredibly well - absolutely no issues during the upgrade. About 15 hours after the upgrade was complete, we suddenly could not log onto the firewalls with our LDAP credentials. Typically we have an AD group specified in the Authentication profile we use for ...

WinCo by L0 Member
  • 5105 Views
  • 1 replies
  • 0 Likes

PAN-OS 10.2 : filter incoming OSPF routes

Hi, We are trying to setup OSPFv2 between a PA-5220 in 10.2 and a Cisco ACI Fabric with "Advanced Routing" enabled.For now, we are able to advertise routes to our ACI Fabric, we can filter outgoing advertisement but we are unable to filter incoming routes. We tried with RIB Filter - OSPFv2 without success (https://docs.paloaltonetworks.com/pan-o...

EmilienRichard_1-1652344524666.png
EmilienRichard_3-1652344694867.png
EmilienRichard_4-1652344728564.png

Upgrade PA stuck

Hi All, We try to upgrade PA5220 and it has been stuck quite long time. We tried to upgrade to 10.1.5h2 from 10.1.0. Any possible reason might cause of it?

403 Forbidden

I've run into a strange issue with the following website https://dvir-prod.aws.drivecam.net. When Users attempt to access it they are getting a 403 Forbidden. I'm not seeing an drops in the logs, and the packet captures don't point to anything either. I have to two 5520's in an HA pair and I forced the Active to Standby in the hops that it migh...

Remove a site from from Palo Alto's blacklist

My client's site, a Canadian site that prepares school supply kits, edupac.ca was hacked badly a few months ago. But we manually removed all malware files. We abandoned the original infected file base, restoring from backups, and now the code base is a clean version from before the hacks. EduPac is an established company for over 20 years. I am ...

Resolved! Palo Alto rejecting one route

I'm having trouble seeing one route in my RIB and FIB. My BGP peer shows it is advertising the route to the Palo Alto, however I see the following when showing the peer at the PAN:sstadmin@200-PFW-01> show routing protocol bgp peer peer-name DMVPN-RouterPrefix counter for: bgpAfiIpv4 / unicastIncoming Prefix: Accepted 49, Rejected 0, Policy R...

Resolved! Security policies not matching traffic

Hello! I am having quite a few strange behaviors from the Palo Alto firewalls. I have a rule for an entire subnet (10.209.82.0/24) to be allowed from inside to outside zones via any port to any IP address yet there is still somehow traffic being denied. Obviously, this isn't the greatest from a security perspective, but I arrived there out of fr...

Resolved! Possiblility of getting locked out of web interface?

Currently, I'm using a local administrator account on the firewall (no Panorama), but I want to configure authentication between it and active directory. I went through Palo's guide for setting up Kerberos (I read that this is preferred over LDAP due to its increased security, but please chime in if you disagree), but I'm worried about the chanc...

JanayE by L0 Member
  • 3278 Views
  • 1 replies
  • 0 Likes

An active Wildfire license is required for this feature

Hi everyone!Every 15 minutes i get an email notification: opaque: Retrieving Content 'WildFire' info failed with error 'An active Wildfire license is required for this feature' but the license is valid till October 2022. Could someone help me with this issue ?My device is PA 850 Thanks in advance

Firewall rules for update Palo Alto´s firewall content on Check Point!

Hi Guys!My Check Point firewall rule for Palo Alto fw update its contents, so im not confortable with the destination part (all_internet)PA fw (x.x.x.x) to all internet on service https (tcp.443) accept...! So instead of put ALL INTERNET on destination, i think PA should have documentation on it, about the destination for updates and also about ...

Aftermath_0-1653903851018.png

Resolved! Minemeld static url/ipv4/md5 list

Hi everyone,we have installed minemeld in our facility and it's great, but we are having trouble implementing a solution that takes lists internally, our current goal is to update the list manually based on the ipv4 / url we get from our security team. Is there any guide that explains how this can be done? Thanks , Angelo.

porq91 by L1 Bithead
  • 5362 Views
  • 6 replies
  • 0 Likes

Resolved! Expedition import of Cisco ASA

Hi, new to Expedition and have just installed (Ubunto 20.4 and latest Expedition packages) . Imported a running config from a Cisco ASA 5525X without issue but when I move away from the dashboard to look at the 400+ address objects I see no objects and then returning to the dashboard they are gone as are a lot of other objects. Appreciate and gu...

AndyH64_1-1653868101698.png
AndyH64_2-1653868171663.png
AndyH64 by L0 Member
  • 2666 Views
  • 1 replies
  • 0 Likes

Resolved! Routing issues on PA410

I cannot get traffic to go out my outside interface - it will only go out the Management interfaceI have a PA-410 with several Inside interfaces / Outside (connected to an ASA) / Management (connected to my Inside network)Note: I changed the Outside IP's first 3 octets from the real to 3.3.3. in this post to protect the future public IP for this...

sos66sos by L1 Bithead
  • 5137 Views
  • 4 replies
  • 0 Likes
  • 24427 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels