General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4225 Views
  • 0 replies
  • 0 Likes

Block from old Browser Version

Hi Community, I work to create a role that should block old browser versions. But I have not found out this special point how you can say from a certain version that these are blocked and only allowed from the safe status. Is there a solution? Many thanks for your help

holmegan by L0 Member
  • 4770 Views
  • 1 replies
  • 0 Likes

Resolved! Wildfire performance lag

Hi All, Can you advise on any current known issues or bugs pertaining to wildfire performance lag?We've encountered an issue where the Wildfire instance seems to be lagging by approx 2.5-3 hours - file submissions from 11:46 till 14:36 still in "pending" state. Cheers,Robyn

RobynLee by L0 Member
  • 3052 Views
  • 2 replies
  • 0 Likes

decryption error - response page not displaying to user

HiWe have set a new decryption profile that is hardened to a new 10.0.6 PA 3250.Most things seem ok however when we go to the guardian website we just get a this site cant be reached page. It would be great if the user got a response page saying decryption error. Is there a way to get this? There could be others (lots of General TLS protocol er...

krisfraser_0-1632918966451.png
krisfraser_1-1632919018039.png
krisfraser_2-1632919039675.png
krisfraser_3-1632919374577.png

Regarding logrcvr during commit in PA box.

PAN os 10.1.0 has been installed and deployed in HA(Active/Passive), while making commit after new policy creation or modifying existing policy, I got error as "client logrcvr phase 1 failure, configuration is invalid".

Log space

Hi - I know there are plenty of discussion about log size - but I don't think anything answers my query.We installed out Palo Altos (2x 4050s) at the weekend. They sit between our internal datacentres and the rest of the customers network - so they are not internet facing. We log traffic (at start and end) and threat logs (alert on AV/Spy/Vulner...

fmd by L3 Networker
  • 7588 Views
  • 7 replies
  • 0 Likes

Resolved! A customer has a question about the pa-5220 they are using.

1. Customers want to use nat. How many ips can be assigned to snat and dnat respectively?https://www.paloaltonetworks.com/products/product-comparison?chosen=pa-5220,pa-3260According to the address above, pa-5220 can use up to 6000 nat rules, I wonder if this is correct.2. Customers want to use snat and dnat in the same band. At this time, I want...

No packet capture files are generated on pa-3060 that customers are using.

Hello.I have been contacted by a customer that there is a problem with packet capture.I know that executing a packet capture command triggers packet capture, and generating a pcap file containing captured packets is generated when the traffic you want to check is generated.However, looking at the attached screenshot, the customer executed the pa...

capture01.PNG

Resolved! PAN-OS GP SSL Cipher Selection

PAN-OS 8.1 seems to lack the capability to perform fine-grained configuration of cipher suite selection and prioritization for GlobalProtect VPN functions. I ran a fairly detailed SSL functionality assessment on a configured TLS v1.2-only GP gateway and found that RSA encryption-based ciphers are selected by default by all simulated clients. Thi...

Resolved! MS Autodiscover Flaw - Vulnerability

Hi All, A design issue in the Microsoft Exchange Autodiscover feature can cause Outlook and other third-party Exchange client applications to leak plaintext Windows domain credentials to external servers Domains that we need to block are listed here: https://github.com/guardicore/labs_campaigns/blob/84d8423335bf72ea078b5286db647580fb7f6a58/Autod...

Qui by L2 Linker
  • 5163 Views
  • 4 replies
  • 0 Likes

Resolved! Template Variable IPv6

Hi All,Does anyone know how to configure an IPv6 address as a template variable? As soon as I put a : in the CSV it throws a fit when importing it.Thanks,Kev

KevinJB by L1 Bithead
  • 3170 Views
  • 2 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels