General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Syntax for security policies without security profile

Hi all, in my security policies on a PA-firewall (or in panorama) I want to be able to filter out all the security policies which have no security profile(s) . I tried a few combinations in the line of (profile-setting/profiles eq 'none') but alas, no joy 😕 Is it even possible?

KenVaBr by L1 Bithead
  • 3834 Views
  • 1 replies
  • 0 Likes

macOS Big Sur 11.6.2 - Global Protect 5.2.8-23 - Connected but Internet is not actually working

Hello all,I received from work a MacBook Pro with macOS Big Sur 11.6.2, I've installed the GlobalProtect 5.2.8-23 which is the only one that I had access to, and it seems like whenever I connect the GP, the connection is successful but there is no Internet Connection.As soon as I disconnect the GP, everything is working.I searched on the live co...

alberaru by L0 Member
  • 2495 Views
  • 1 replies
  • 0 Likes

Blocking Torch browser

Hi All, I would really appreciate if some one can help me on this. I am planning to block Torch browser through a firewall rule, using App-ID. But as per information in the community we cannot entirely block the functionality of Torch browser using App-ID. Once we block from the security rule, normal web traffic will go through the firewall. Ple...

Log Forwarding

Hello everyone, Before the question, the context.I have a panorama wich managed a lot of devices groups. we have a lot of rules for them. Which all these rules uses the default profile for log forwarding.I have a new syslog server and i need to forward the logs from all the devices and not from panorama. I created the new syslog server and i man...

Maryan by L0 Member
  • 3296 Views
  • 3 replies
  • 0 Likes

Custom Vulnerability Signature to block older versions of Chrome

After reviewing this KB article: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSOCA0 It looks like you can create custom vulnerability signatures for named browsers. Could you also do that to limit browser access via a security policy based on a minimum version number? For example: create a vulnerability signature...

Match next line at cli

Is there a way to match the next "X" number of lines when piping to match at the cli?I am entering:show zone-protection zone outside | match udpand would like to show the matched line and the next three.This would be analogous to grep -A 3Cheers!

Resolved! Reconnaisance Protection - Action Alert

Hello,I configured zone protection, (reconnaissance protection), and enabled the tcp\udp port scan and host sweep and chose the default as action "alert".Afterwards, I noticed in the monitor logs this vulnerability appeared, "ZGrab Application Layer Scanner Detection". The severity is medium. Where do I change the action? I can change it in the ...

vp.JPG
vun2.JPG
roma by L2 Linker
  • 19766 Views
  • 5 replies
  • 0 Likes

Need example of Configure IPSec VPN with Source NAT

Hello, I'm attempting to setup a few remote sites to a Hub site all sites have a Palo Alto 3260 firewall. All remote sites have the same internal IPs and subnets on the Trusted side and I'm needing to connect all sites using a IPSEC VPN. I would like to Source NAT but cannot find the documentation to assist in setting this up using IPSEC. Als...

Issues when installing Cortex on Debian

Hello, Currently, we are installing the Cortex XDR agent on Debian servers. We have followed the steps as the documentation says. But, when the services are gonna be started it shows an error: "sbin/service: not found". All the services show "Stopped" status. If I check the "/opt/traps" directory and if I run the command "dpkg -l | grep corte...

Cortex XDR.png
iscott by L2 Linker
  • 4469 Views
  • 3 replies
  • 1 Likes

Changing ethernet interfaces

We will be upgrading our internet connections from 1GB to 10GB. What is the process to change from a 1GB copper (eth 1/2) to 10GB sfp+ (eth 1/14). I've run through the configs and I'm assuning any specific reference to that interface will need to be changed. I'm assuming this will need to be done for Interface, Zones, Router, ipsec tunnels, GP g...

cmerrick by L0 Member
  • 4013 Views
  • 3 replies
  • 0 Likes
  • 24453 Posts
  • 125 Subscriptions
Top Solution Authors
Labels