General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Inline ML always shows "unknown"

I'm trying to figure out if the "Inline ML" feature is working. A quick search of my logs for "dynamic-classification-verdict neq unknown" returns zero results. I found a support article with a sample file, but it says I have to host it on my own webserver. Does anyone have another way I can test it?

Maxstr by • L1 Bithead
  • 2267 Views
  • 1 replies
  • 0 Likes

Block from old Browser Version

Hi Community, I work to create a role that should block old browser versions. But I have not found out this special point how you can say from a certain version that these are blocked and only allowed from the safe status. Is there a solution? Many thanks for your help

holmegan by • L0 Member
  • 4936 Views
  • 1 replies
  • 0 Likes

Resolved! Wildfire performance lag

Hi All, Can you advise on any current known issues or bugs pertaining to wildfire performance lag?We've encountered an issue where the Wildfire instance seems to be lagging by approx 2.5-3 hours - file submissions from 11:46 till 14:36 still in "pending" state. Cheers,Robyn

RobynLee by • L0 Member
  • 3194 Views
  • 2 replies
  • 0 Likes

decryption error - response page not displaying to user

HiWe have set a new decryption profile that is hardened to a new 10.0.6 PA 3250.Most things seem ok however when we go to the guardian website we just get a this site cant be reached page. It would be great if the user got a response page saying decryption error. Is there a way to get this? There could be others (lots of General TLS protocol er...

krisfraser_0-1632918966451.png
krisfraser_1-1632919018039.png
krisfraser_2-1632919039675.png
krisfraser_3-1632919374577.png

Regarding logrcvr during commit in PA box.

PAN os 10.1.0 has been installed and deployed in HA(Active/Passive), while making commit after new policy creation or modifying existing policy, I got error as "client logrcvr phase 1 failure, configuration is invalid".

Log space

Hi - I know there are plenty of discussion about log size - but I don't think anything answers my query.We installed out Palo Altos (2x 4050s) at the weekend. They sit between our internal datacentres and the rest of the customers network - so they are not internet facing. We log traffic (at start and end) and threat logs (alert on AV/Spy/Vulner...

fmd by • L3 Networker
  • 8224 Views
  • 7 replies
  • 0 Likes

Resolved! A customer has a question about the pa-5220 they are using.

1. Customers want to use nat. How many ips can be assigned to snat and dnat respectively?https://www.paloaltonetworks.com/products/product-comparison?chosen=pa-5220,pa-3260According to the address above, pa-5220 can use up to 6000 nat rules, I wonder if this is correct.2. Customers want to use snat and dnat in the same band. At this time, I want...

No packet capture files are generated on pa-3060 that customers are using.

Hello.I have been contacted by a customer that there is a problem with packet capture.I know that executing a packet capture command triggers packet capture, and generating a pcap file containing captured packets is generated when the traffic you want to check is generated.However, looking at the attached screenshot, the customer executed the pa...

capture01.PNG

Resolved! PAN-OS GP SSL Cipher Selection

PAN-OS 8.1 seems to lack the capability to perform fine-grained configuration of cipher suite selection and prioritization for GlobalProtect VPN functions. I ran a fairly detailed SSL functionality assessment on a configured TLS v1.2-only GP gateway and found that RSA encryption-based ciphers are selected by default by all simulated clients. Thi...

  • 24455 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels