General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Traffic pattern of threat ID 38643

Wavelink Emulation License Server HTTP Header Processing Heap Buffer Overflow Vulnerability' generated by PAN NGFW detected on host 10.10.10.1. " Vulnerability Exploit Detection (hostname:8081/)"

We have customer asking what is the traffic pattern tha

...

Resolved! PanOS CLI show tags?

I can tag a rule via CLI, but how can I ask Panorama to show me rules tagged with tag-name?

 

set device-group DG-Name security rules "Existing-rule-name" tag tag-name

BoDollis by L2 Linker
  • 2277 Views
  • 1 replies
  • 0 Likes

Whitelisting messenger-app

Hi guys,

 

Goal: Whitelisting messenger app in mobiles but deny facebook

Do you have any problems in whitelisting messenger app in a mobile? It seems creating a policy and allowing facebook-chat is not working.

But if i included facebook-base it will wor

...

RemusDV by L1 Bithead
  • 1152 Views
  • 2 replies
  • 0 Likes

gridmeld for User to IP Mapping

Has anyone successfully used gridmeld alongside minemeld to get User to IP mapping data?

 

I've successfully setup minemeld and gridmeld to talk to a Cisco ISE instance and I've configured the 'dagPusherNg'

 

I can see from the gateway that it is receivi

...

Useless PBF warning

Hi All,

 

That's not an issue.. I just want to share with you this thought

 

Starting from the fact that the egress interface is NOT a matching criteria.. But I have to configure around 80 VPN tunnel (with their own backup tunnel using pbf option "disabl

...

PBF_warning.JPG
Warning_Rule.JPG

Block traceroute

Hi all,

is there a way to block IP source if I match traceroute App-ID? Maybe with a custom vulnerability?

s_quasar by L3 Networker
  • 4262 Views
  • 7 replies
  • 0 Likes

FreeIPA LDAP group mapping

UPDATED:

The LDAP package FreeIPA uses , 389-ds-base, had some security vulunerabilities and has been updated. This update has caused the PA to fail checking users within groups. Here's is the latest configuration that works with 389-ds-base (1.3.8.4-

...

FreeIPACapture1 (1).GIF
FreeIPACapture2 (1).GIF

can't login to web console

I have just instaled MM on Ubunto 16.04. Using these instructions:

Howto on Ubuntu 16.04

$ sudo apt-get update $ sudo apt-get upgrade $ sudo apt-get install -y gcc git python-minimal python2.7-dev libffi-dev libssl-dev make $ wget https://bootstrap.p...

Mattk by L2 Linker
  • 7930 Views
  • 8 replies
  • 1 Likes

Resolved! Firewall upgrade/replacement

What is the easiest way to replace old hardware(5050) with new(5520), that are in HA pair. Can i add 2 new firewalls to the HA group and failover. Or do i have to replace passive with new, make it active then remove the other.

raji_toor by L4 Transporter
  • 4518 Views
  • 4 replies
  • 0 Likes

Miner for IBM X-Force exchange Taxii in Minemeld.

Hi there,

 

I am trying to connect IBM x-force taxii with minemeld. 

I am using https://github.com/PaloAltoNetworks/minemeld-taxii-ng.git. prototype.

After configuration like user/password, discovery service url. and creating a node, I am having followin

...

clipboard_image_0.png

URL Response Page for SSL without decryption

Hello everyone,

 

we have PA7050 managed by panorama. We dont have SSL decryption but we want to serve users a block url response page for https traffic. For that I followed following link:

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/Ho

...

Report mismatch

We are facing issue with mismatching of bandwidth statistics between our weekly report and custom total bandwidth report.

 

For example, on 11 Nov the bandwidth shown on the weekly report is around 2000GB but the one shown on the custom total bandwidth

...

Report.jpg
Top Liked Authors