General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Log/syslog forwarding to Microsoft Azure/Sentinel

Entire company uses log analytics and Sentinel for logging. Found this excellent article below on how to accomplish this task.https://davicruz.com/en-US/azure-sentinel/2021/03/rsyslog-sentinel-log-forwarder Has anyone done this before? I have stand-alone PA's that are now dumping sylog to Splunk.Splunk is being replaced with log analytics. Th...

Resolved! APP ID impact

Can some one answer this? A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified byApp-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, whichwill be de...

BNSRIKAR by • L1 Bithead
  • 6388 Views
  • 3 replies
  • 0 Likes

TCP 3 way handshake success (telnet) but data doesnt flow through

InformationSource : 10.1.1.1Destination (example) 202.181.200.188Destination Port : 8443Client is running on port based firewall Issue (Technical not an issue just the firewall behavior) :3 way hand shake success which mean telnet port 8443 is success but the actual data doesnt go through and with deny log record at traffic log. Client is questi...

VLim by • L2 Linker
  • 6437 Views
  • 4 replies
  • 0 Likes

Resolved! Creating an Authenticated Tunnel from One Internal Zone to Another Internal Zone

I would like to create a secure internal tunnel such that a user requires authentication (ideally MFA, or a cert, or at least a PW, etc) to get from one internal zone to another internal zone (ie user zone to the management zone). What are my options? Is anyone doing this sort of thing with Okta? Is there a certificate based way to do this? ...

Active/Passive PA with Dual ISP in eBGP and private owned /24 ASN

Hi, Looking for some guidance on our setup. I am looking to establish pure ISP failover without having to take action on my / my team's side. Presently when there is an outage, we need to do manual intervention to get connectivity back up. Here is an overview of our network, internet facing. ISP A (/30) -> Cisco ASR Router 1 (I control) (/24 ...

system2 by • L0 Member
  • 2883 Views
  • 1 replies
  • 0 Likes

multicast test

PA is using cisco switch as external RP. Over a system I start the stream on VLC but I don't see the multicast address in multicast FIB. System is connected to network that is directly behind firewall. I use this tool multicast test tool (https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=21729) I see the entry of add...

raji_toor by • L4 Transporter
  • 3034 Views
  • 1 replies
  • 0 Likes

IPSEC s2s VPN between VM-50 and PA-3220

We've done plenty of s2s IPSEC VPN tunnels between our DC firewalls and branch offices. I have a new branch office which we are configuring the same way as the others, yet the IPSEC VPN is not operating as expected. The tunnel is showing as up and the IKE Phase 1 & 2 are successful. However, on both firewalls, when I go into Tunnel Info all ...

popeja by • L2 Linker
  • 2948 Views
  • 3 replies
  • 0 Likes

MS Active Directory Security Group Changes Not Applying over VPN w/ prelogon

Our organization has been struggling with getting MS AD security group changes to apply over VPN w/ prelogon enabled for a long period of time now. I have had support tickets in with Palo support and MS support. Palo support has determined via Globalprotect logs, prelogon appears to be functioning properly and no traffic for this function is bei...

Palo Alto blocks legitim applications

Hi everyone,We have defined Risk App block rule which contains the app by risk category, characteristics and vice versa.After upgrading PA to 10.1.5-h1 version it starts to block ssl, web-browsing, google-base, whatsapp and other apps which are not among apps which is blocked by my defined rule.I'va looked for matching apps in app filters, but t...

OGasimli by • L0 Member
  • 2628 Views
  • 1 replies
  • 0 Likes

Okta has 400+ IPs that are all /32. Looking for an EDL solution

Has anybody figured out an edl to allow communications to Okta without manually entering the whole list? My customer is using Okat for MFA and the Okta Portal uses a whitelist so they have policies that anything hitting Okta should use ip x.x.x.x. This is legacy config from a newly replaced firewall. FQDN Address objects are only reporting 2 I...

No change in retention of summary log after the log storage allocation update

Current panorama and log-collector issuesPanorama – mgmt. server only – SW-version: 9.1.12-h3Log-collectors :PAN02- – PAN03 – same SW version as Panorama 1.The summary log retention days did not change after the log storage allocation updatePAN02> show log-diskquota-pctcfg.diskquota.pct.config: 25.000cfg.diskquota.pct.detailed: 80.000 --à...

Pras by • L4 Transporter
  • 3230 Views
  • 3 replies
  • 0 Likes

Cortex XSOAR search "contains" instead of "equals"

Hello Is there a way to search a Domain in Minemeld with "contains" instead of "equals"? As example: We have entered *.blabla.com" in one of our Nodes. I would like to search for blubb.blabla.com - which of course does not match. Also "blabla.com" will not work... Does anyone have any Idea about? thanks

Apply QOS for a particular Server published to internet

Hi Team, We have a SFTP server behind our firewall and its NATed to one of the interfaces of the firewall , we need to restrict the bandwidth to the SFTP server from Internet. When clients from internet connects to the server for downloading files they will be restricted to use 10 Mbps only. The generic KB is not helping in this case Thanks,Sam

  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels