General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect Enforcement Bypass

Hi All,

 

I understand that this is a Microsoft related matter however I'm interested to see if anyone else has come across this issue.

 

With Global Protect Network Enforcement in place (through the Portal Config), it is still possible for local admins

...

Josh990 by L2 Linker
  • 5009 Views
  • 5 replies
  • 0 Likes

Configuration checks against CIS security benchmarks

Hello All, Do any of you compare local firewall or Panorama configurations against CIS benchmarks for security compliance checks ?

Either using an existing tool to check Firewall compliance with the CIS (Centre for Internet Security benchmarks) recomm

...

User-ID Agent 8.1 help needed

Hello.

 

AD integration using the User-ID agent.  We were on 8.0.7-2 and things were working fine.

 

I tried upgrading to version 8.1.0-66 and had several problems with wrong user-id being reported.  I saw in the release notes for 8.1:

• Since multiple us

...

dannon by L3 Networker
  • 4735 Views
  • 5 replies
  • 0 Likes

GlobalProtect issue with Enforcer Network Access

Hello,

 

We enabled a week ago the feature enforce network access on our environment.

We are using internal host resolution to detect if user is inside or outside corporate network.

In a random way, we're experiencing issue with users worldwide. We have

...

Block Psiphon App

Hi,

 

Is there any way to block this psiphon app? is it needed ssldecrypt?

This app uses many apps (ike,ssh,ssl) so we can not block them. How do you block this app psiphon?

BigPalo by L4 Transporter
  • 2001 Views
  • 2 replies
  • 0 Likes

Emailed SAAS report missing report, run locally is fine?

Hi Everyone -

I have a10x Firewall that runs SAAS reports fine when run locally. 

However when I use a scheduler, I get and email with NO REPORT  and only the following in the email message:

 

Content-Type: text/html; charset=utf-8
Content-Transfer-Encodi

...

dbrenipc by L3 Networker
  • 1611 Views
  • 0 replies
  • 0 Likes

Find disabled administrator accounts

Across a large environment, what would be the best way to audit Palo administrator accounts?  That is accounts found at Device > Administrators.

 

For various reasons we all end up with lots of AD accounts, service accounts and so on there, what I'd li

...

Ping log with 0 bytes sent

Hi Guys,

 

I noticed some strange logs on one of our 5200 firewalls.

There is device behind the firewall that is running constant ping to google dns, traffic is allowed and working normally.

I noticed a some logs that bytes sent is zero... I can explain

...

AlexanderAstardzhiev_0-1623937334598.png
AlexanderAstardzhiev_1-1623937505092.png

Deny PSiphon

Black Psiphon

Dear All, Psiphon was blocked for a long time but this week, we detect it has been working again. i have tried to block it again but without any result, it was blocked for 2 hours and working again after that. I have been checking the tr

...

User-ID Connection Security Won't Work

UserID Agent version 9.0.5-8
Firewall 9.0.8

Windows Server 2016 UserID Agent Servers x2

 

I've tried following this guide and numerous others (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGFCA0)

 

Keep getting 'Failed to vali

...

TylerHay by L0 Member
  • 12905 Views
  • 5 replies
  • 0 Likes

Query on MineMeld setup for Azure Sentinel

We would like to add a miner to input nodes in our Minemeld portal.

And we followed the below article to setup as per our requirement but we couldn’t see the “git” icon to add the extensions.

https://live.paloaltonetworks.com/t5/minemeld-articles/send-

...

  • 24304 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors
Labels