General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 442 Views
  • 0 replies
  • 2 Likes

How to reimport a csr via api

Anyone ever tried to import a csr back into config?

 

I generated a csr on panorama the other day and then went to generate a certificate. (I did not commit at this time)

 

when I came back with the csr response someone had reverted the config so my csr

...

reaper by Cyber Elite
  • 3451 Views
  • 5 replies
  • 0 Likes

What does these vaules in dp brdagent logs mean

2021-08-04 03:08:26.800 +0000 PORT4: board_port_autoneg_enabled -> board_port_autoneg, link: 0, mode: 1
2021-08-04 03:08:26.856 +0000 Port 1: DISABLE command received
2021-08-04 03:08:26.856 +0000 PORT1: board_port_autoneg_enabled -> board_port_reset,

...

VPN Site-2-Site both sides with dynamic IP

VPN Site-2-Site both sides with dynamic IP

 

Good afternoon, first of all, thank you very much for your support and help.

Is it possible to configure the following:

 

Site 1: Palo Alto with Dynamic output to the Internet.( already have NAT configured on t

...

Metgatz by L4 Transporter
  • 2446 Views
  • 1 replies
  • 0 Likes

Resolved! Pulling in users directly from ADDS?

I have a requirement to pull in our users from Azure AD (or AADDS depending on the solution) into Prisma Cloud in order to create policy rules based on the source user/group but I'm unsure as to which method I would need to set this up? (Device\LDAP,

...

cra1901 by L0 Member
  • 4183 Views
  • 6 replies
  • 0 Likes

Directing SMTP Traffic to VPN Tunnel

Hello Team,


I am new to this kind of issue and need suggestions as I need to execute the same in my Organisation. I would like to know if we can direct the SMTP Traffic (Outlook Mails) to our IPsec VPN Tunnel without disturbing any other application

...

mkd1995 by L0 Member
  • 2093 Views
  • 2 replies
  • 0 Likes

CIS Control 13.5 - Unauthorized use of encryption

Looking for input on this one. From a Palo Alto perspective, what would be the best way to monitor for encrypted traffic in general? Need a way to make sure we're specifically able to point to traffic that was encrypted and provide a report or show t

...

HTTP Server Profile > Payload Format

Hi Everyone,

 

Device > Server Profiles > HTTP
I created a server profile, however, My curl request is not working, Can you kindly provide any information about how can I fill those fields (Headers, Parameter information and Payload)? How can I translat

...

PayloadFormat.jpg
laelijr by L0 Member
  • 3421 Views
  • 1 replies
  • 0 Likes

Windows Remote Assistance

Hello,

 

I'm fairly new to PAN after years with other  vendors.

We're using Windows Remote Assistance in the network. This requires allowing the ms-rdp application between the network from which we want to assist and the target network. When I try to

...

VPN S2S Site with Dynamic IP and site with FQDN ( DynDNS )

VPN S2S Site with Dynamic IP and site with FQDN ( DynDNS )

 

Good afternoon, is it possible to set up a Site-to-Site VPN between a site with a dynamic Public IP and a site with a DynDNS FQDN.

PaloAlto----IP-Dynamic Public----Internet-VPNIPSEC-----PaloAl

...

Metgatz by L4 Transporter
  • 2101 Views
  • 1 replies
  • 0 Likes

Decryption Log Forwarding

I upgraded to PanOS 10.0.6, and am trying to forward decryption logs via email.  If I go to monitor -> decryption, then I see a bunch of rows where zone.src eq untrust and zone.dst eq untrust and ( proxy_type eq GlobalProtect ), application is incomp

...

GP gateway getting ignored

 

I have one of the users getting the below error in the PanGPS log

 

ignore gateway gateway.####.com , duration time is 0xFFFFFFFF, priority=1
gateway.####.com -1ms

 

This user is located near the mentioned gateway, How to make this work for GP Client not

...

Sambhu21 by L1 Bithead
  • 2029 Views
  • 2 replies
  • 0 Likes
  • 23701 Posts
  • 110 Subscriptions
Top Solution Authors
Labels