General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Intermittent sites not loading

Having issues with palo alto pa-820. Some times when users try to load sites they just don't load. Wait some time and site usually loads. Some times it is fine, loads fast, users not getting any errors. No changes made to cause issue. Thinking it is something with dynamic updates? This started on the morning of 12-04-2022.

IT_Fleet by L1 Bithead
  • 4998 Views
  • 7 replies
  • 0 Likes

HA Cluster Topologies and experiences

Has anyone had some hands on experiences with the new clustering features? I've read a bit on them, but like the post below, am struggling to make sense of the actual functionality/workability of the finer details needed for this setup as to how it exactly functions for multi data center scalability. Curious as to how the addressing scheme wo...

Sec101 by L4 Transporter
  • 5798 Views
  • 5 replies
  • 0 Likes

Default security rules, hit count and Apps Seen

Hi, I'm noticing a weird behaviour with default security rules "intrazone-default" and "interzone-default": For "intrazone-default" I can see how many apps have been seen by the rule, but if I click on the "Apps Seen" link nothing happens;For both "intrazone-default" and "interzone-default", if the firewall is connected to Panorama, I can't see ...

emyl_79 by L2 Linker
  • 3462 Views
  • 1 replies
  • 0 Likes

DNS Query Enchancement

Running PANOS-10.0.9. In GP Network>GlobalProtect>PortalsUnder App -Resolve All FQDNs using DNS servers assigned to by the tunnel(Windows Only) is Yes by default.I cant see these dns logs in Traffic logs?

isingh by L0 Member
  • 2276 Views
  • 1 replies
  • 0 Likes

Global Protect monitor

Good afternoon, I'm trying to understand the behavior of the global protect client as it pertains to session expirations. I'm getting a message "remove previous user" message. I'm trying to determine what that means as I'm used to seeing the "user session expired" message in the logs. What triggers the "remove previous user" flag? Is this u...

danoman2 by L3 Networker
  • 2656 Views
  • 2 replies
  • 0 Likes

SSL decryption issue with PIP

I have added the URL to the exception list with no luck. Any suggestions? C:\Users\Steven Williams\AppData\Local\Programs\Python\Python38>pip install Flask-SQLAlchemyWARNING: Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY...

Allow one Youtube Channel but block all other Youtube video

Hi , I have searched the available articles, I couldn't find a proper solution perhaps LIVE member could help me on this There's online learning platform which I need to allow all videos from this site, the training videos are embedded with Youtube linksANDin the current firewall we have block all Youtube videos. I have found the Youtube channel...

webserver service stopping

webserver service in palo alto stopping after certificate renewal and trying to access GUI. CLI is working. Tried restarting webserver service and management plane. But its stopping as soon as we try to access GUI and unable to access

Resolved! Palo Alto firewalls alerts

Hello, Recently we have started working on enabling email alerts for our Palo Alto firewalls. One of the alert is for interface and HA status change alerts. Could you please let me know what can I do to enable same? Do I need any external tool for it? Any sort of help would be appreciated.

Resolved! Vulnerability protection profile change symptoms

Dear Team, When the firewall checks the policy, the Vulnerability protection profile is displayed as an Exclamation mark. The OS is using 10.0.4. I searched all bug-ids from 10.0 to 10.2, but couldn't find anything matching the symptom. If you have any causes and solutions for the above symptoms, please share with me. thanks in advance...

CHOEKyungJun_0-1649222204704.png

Tenable Scan on Palo Alto firewall / Panorama

Hi All, Are Tenable vulnerability scans (see below) on Palo Alto firewalls / Panorama resource intensive for the PA devices? Does this cause high DP or MP issues? https://community.tenable.com/s/article/How-to-perform-a-compliance-scan-on-a-Palo-Alto-Firewall Thanks in advance.

Ben-Price by L4 Transporter
  • 10290 Views
  • 6 replies
  • 0 Likes

Resolved! http/2 connection session id

Dear Team, I have a question while checking the traffic log. In general, we know that each id is created when the session is created. However, the http/2 connection session id is identified as the same id. I know that when the session id is input according to the link below, it is input as the parent session ID. (The ssl session is displayed as ...

traffic.jpg
  • 24431 Posts
  • 125 Subscriptions
Top Solution Authors
Labels