General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 441 Views
  • 0 replies
  • 2 Likes

Resolved! Where to Write Security Policies with a Site-to-Site VPN

Hello,

We have a pair of 3200s on our main site, and have added an 820 at a remote site to bring up an IPSec tunnel between the two.

When I initially set the remote site up, I decided to have all the security policies controlling what access the remote

...

Does NAT64 works for inbound NAT

Currently we have configured inbound NAT for DMZ application which is on ipv4. Public ip used for it is  ipv4.

Due to some requirement client from outside network will be coming from ipv6 public ip to access the application. In this case our nat is no

...

Deepak25 by L3 Networker
  • 4107 Views
  • 3 replies
  • 0 Likes

Is my firewall hacked already ?

I have a PA3020 with 7.0.5-h2 PAN-os version.  I noticed that it have a lot of DNS traffic sent to strange IP address. 

when I running 

show system resources command. 

I found  strange process nginx and two syslog-ng there.  Is it normal, how to get rid

...

banny6 by L1 Bithead
  • 3634 Views
  • 5 replies
  • 0 Likes

Something aking to | sort | uniq -c | sort -nr

Like the title says, is there a way to run a filter for a period of time, pull out a list of IPs, sort them, remove the duplicates with a count, and sort them by most popular?

This is a common omegle thing to do with syslog data, say you have a very p

...

Jack45 by L1 Bithead
  • 1892 Views
  • 1 replies
  • 0 Likes

Allow redirect URL with decrytion on.

Hey guys one of my customer I not able to access the Redirecting URL's This Error display (err_http2_inadequate_transport_security)

I checked the logs the traffic  URL shows alert but the decryption is done.

We are able to Access the URL without decryp

...

3rd party managed minemeld feed to local

We have a service provider(SP) with authenticated minemeld feed and we want to pull feed from the SP minemeld which asks for authentication into our local minemeld instance, instead of directly into our firewall. How can we do that.

raji_toor by L4 Transporter
  • 2808 Views
  • 4 replies
  • 0 Likes

ALERT WHEN VPN DESTINATION STOP WORKING

Hi everybody

Currently  have a vpn connection to a remote site , and now we are transferring many info along the day

But sometimes connection closes and transfer interrupts

So we want to sent alerts when this connection o transfer interrupts to be able

...

SD-WAN Hardware Change / Migration

We have been running SD-WAN since release a year or so ago, regular PAN-OS SD-WAN not Prisma SD-WAN.  All the sites were deployed with PA-220 at the time, but we are rolling more sites in and I need to swap a couple of the PA-220s with a PA-440.

 

Anyo

...

bschaper by L2 Linker
  • 2757 Views
  • 2 replies
  • 0 Likes

Resolved! Static Destination Nat issue

In static Destination Nat I have configured 172.16.0.10 IP in private IP.

 

But when I checked the logs in monitor it is showing 255.255.255.0 in Destination IP Column of log & packet was dropped with aged out error.

 

Can anyone please explain what is w

...

Replacing the Revoked QuoVadis Intermediate Cert

For the benefit of anyone else who was using a QuoVadis certificate for their GlobalProtect portals/gateways (or presumably decryption), the process of replacing that intermediate is surprisingly easy.

 

Just import the new intermediate certificate usi

...

  • 23700 Posts
  • 110 Subscriptions
Top Solution Authors
Labels