General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2054 Views
  • 0 replies
  • 0 Likes

How to reimport a csr via api

Anyone ever tried to import a csr back into config?

 

I generated a csr on panorama the other day and then went to generate a certificate. (I did not commit at this time)

 

when I came back with the csr response someone had reverted the config so my csr

...

reaper by Cyber Elite
  • 4112 Views
  • 5 replies
  • 0 Likes

What does these vaules in dp brdagent logs mean

2021-08-04 03:08:26.800 +0000 PORT4: board_port_autoneg_enabled -> board_port_autoneg, link: 0, mode: 1
2021-08-04 03:08:26.856 +0000 Port 1: DISABLE command received
2021-08-04 03:08:26.856 +0000 PORT1: board_port_autoneg_enabled -> board_port_reset,

...

VPN Site-2-Site both sides with dynamic IP

VPN Site-2-Site both sides with dynamic IP

 

Good afternoon, first of all, thank you very much for your support and help.

Is it possible to configure the following:

 

Site 1: Palo Alto with Dynamic output to the Internet.( already have NAT configured on t

...

Metgatz by L4 Transporter
  • 2951 Views
  • 1 replies
  • 0 Likes

Resolved! Pulling in users directly from ADDS?

I have a requirement to pull in our users from Azure AD (or AADDS depending on the solution) into Prisma Cloud in order to create policy rules based on the source user/group but I'm unsure as to which method I would need to set this up? (Device\LDAP,

...

cra1901 by L0 Member
  • 5101 Views
  • 6 replies
  • 0 Likes

Directing SMTP Traffic to VPN Tunnel

Hello Team,


I am new to this kind of issue and need suggestions as I need to execute the same in my Organisation. I would like to know if we can direct the SMTP Traffic (Outlook Mails) to our IPsec VPN Tunnel without disturbing any other application

...

mkd1995 by L0 Member
  • 2482 Views
  • 2 replies
  • 0 Likes

CIS Control 13.5 - Unauthorized use of encryption

Looking for input on this one. From a Palo Alto perspective, what would be the best way to monitor for encrypted traffic in general? Need a way to make sure we're specifically able to point to traffic that was encrypted and provide a report or show t

...

HTTP Server Profile > Payload Format

Hi Everyone,

 

Device > Server Profiles > HTTP
I created a server profile, however, My curl request is not working, Can you kindly provide any information about how can I fill those fields (Headers, Parameter information and Payload)? How can I translat

...

PayloadFormat.jpg
laelijr by L0 Member
  • 4084 Views
  • 1 replies
  • 0 Likes

Windows Remote Assistance

Hello,

 

I'm fairly new to PAN after years with other  vendors.

We're using Windows Remote Assistance in the network. This requires allowing the ms-rdp application between the network from which we want to assist and the target network. When I try to

...

VPN S2S Site with Dynamic IP and site with FQDN ( DynDNS )

VPN S2S Site with Dynamic IP and site with FQDN ( DynDNS )

 

Good afternoon, is it possible to set up a Site-to-Site VPN between a site with a dynamic Public IP and a site with a DynDNS FQDN.

PaloAlto----IP-Dynamic Public----Internet-VPNIPSEC-----PaloAl

...

Metgatz by L4 Transporter
  • 2508 Views
  • 1 replies
  • 0 Likes

Decryption Log Forwarding

I upgraded to PanOS 10.0.6, and am trying to forward decryption logs via email.  If I go to monitor -> decryption, then I see a bunch of rows where zone.src eq untrust and zone.dst eq untrust and ( proxy_type eq GlobalProtect ), application is incomp

...

GP gateway getting ignored

 

I have one of the users getting the below error in the PanGPS log

 

ignore gateway gateway.####.com , duration time is 0xFFFFFFFF, priority=1
gateway.####.com -1ms

 

This user is located near the mentioned gateway, How to make this work for GP Client not

...

Sambhu21 by L1 Bithead
  • 2524 Views
  • 2 replies
  • 0 Likes
  • 24229 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels