General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How do I run multiple commands?

How do I run these commands with one command/automation?? (instead of one by one manually) !taskComplete id=7!taskComplete id=33 input=no!taskComplete id=138 input=Spam!taskComplete id=237 input=Spam/incident_set phishingcategory=Spam incidentcategory="CAT 7 - Non Incident"!closeInvestigation closeReason=Resolved closeNotes=Spam

Stuefen by L0 Member
  • 3059 Views
  • 1 replies
  • 0 Likes

Device State from Multiple Devices

I have a question and I am hoping I am not the first person to have asked it, and that there is a script out there somewhere. I am trying to get the device state from multiple firewalls and need to somehow put it in a script. I do leverage the scheduled config export from Panorama, but that only gets me so far in a complete disaster. If the...

PA220 and IoT Security Policy Recommendations

Hello everyone.I am trying to get the policy recommendations from IoT Security to work.After following the detailed onboarding instructions, everything seems to be properly set-up on both the firewall and the IoT Security portal. All licenses are activated, all logs are being sent to CDL and IoT Security for processing. The issue is; when openin...

LarsPS_0-1642407559759.png
LarsPS_1-1642407652985.png
LarsPS_2-1642407711012.png
LarsPS by L0 Member
  • 2559 Views
  • 1 replies
  • 0 Likes

Alert on Policy Rule Modification

Hello Everybody, I would like to know if there is a possibility to be alerted in case of modification of a rule.For example: if a rule is modified, an email is automatically sent to a specific person Thank you Valentino

GWLB AWS - HA what to do if both appliances go down?

We are deploying two PA on AWS using GWLB and we are wondering what would happen if for any reason both aplliances go down , since all traffic (inbound , outbound and inter-vpc) is going through the FWs , do you know a quick bypass or fail-open solution to this? I configured a couple of linux2 machines with hairpining nat so they can send the tr...

Cgca1620 by L0 Member
  • 2174 Views
  • 1 replies
  • 0 Likes

management interface & service route configuration

HelloI am new in palo alto, I did a self-trainingI would like to have more details about the relation between the management interface and the service route configurationI have a little bit stuck on when to use the route configuration serviceI think there are some webgui ways to manage the AP:-directly connect a pc to Mgmt interface-connect mgmt...

Toufik by L0 Member
  • 8127 Views
  • 2 replies
  • 0 Likes

Azure Tag in Security policies

Hi There, How we could create dynamic security policies from Azure tag. In the Azure Market place I do see this statement."policies that are dynamically updated based on Azure tags assigned to workloads, allowing you to reduce the attack surface area and achieve compliance" Is that only for the model Active/Passive scenario or how and what shou...

Session end reason: tcp-fin and aged-out?

Hi all, I am using PA-850. I am having the problem. sometimes the internet is blocked. and I see in the monitor, the sesson end is: tcp-fin and aged-out. but after refresh some times, then I can access to internet. Please help to advise how to fix it. please let me know if you need more information for this issue

Chivas by L2 Linker
  • 86038 Views
  • 7 replies
  • 0 Likes

Resolved! Unable to get internet from inside host

Hello Guys,Hope all are good.I have official PA version 10.0.0.8 image which i have installed in VMware Workstation 16 , I have done all the network level things , Security policies and NAT policies however one of the host from inside zone is not able to connect to internet using the PA firewall. I don't know what;s wrong on host side i can see ...

Migration from 5250HA to 3250HA

Hi Everyone We plan to migrate 5250HA to 3250HA. See if anyone has past experience. 5250HA Policy and objects tab are managed by Panorama, All rest is still on local. Main change is interface on 5200.e.g internet or DMZ zone includes 1G and 10G interface 1/4 and 5 and On 3200 It will be changed to interface 20 and 21 for example.If modify the in...

Resolved! How to make upstream connected devices learn that downstream core switches are down

Hi all, We have active passive setup of firewalls in both DC and DR site. The scenario I am trying to work on is, if my downstream connected core switches are down in primary DC, how can make ISP and MPLS connected devices on my upstream learn that all traffic should be routed to DR site firewalls. Basically, How can we make ISP and MPLS router...

Sukhmeet by L1 Bithead
  • 5353 Views
  • 3 replies
  • 0 Likes

dual catergory url checking

hello community. I notice that this site https://www.pokmi.com/ is in dual category for Adult and catagory low Risk. I made an url filtering rules that allow low risk category but that block adult category. when I apply this rules to my traffic I have access to this site. off course as my site category is adult I want's that the firewall block ...

fcorfdir by L2 Linker
  • 2101 Views
  • 1 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Labels