General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4229 Views
  • 0 replies
  • 0 Likes

U-NAT Double NAT - DNAT

Good morning, first of all thank you very much for your support.I have the following case scenario:FQDN: Dyndns ( paloalto01xxxalias.dynalias.net )Modem/router/ADSL dynamic IP PublicModem/router/ADSL LAN IP 192.160.1.254Modem/router/ADSL NAT1-1 to Palo Alto Wan External InterfacePalo Alto Wan Interface 192.168.1.74 Gateway: 192.168.1.254Palo Alt...

Metgatz by L4 Transporter
  • 4596 Views
  • 1 replies
  • 0 Likes

Accessing a specific website triggering Spyware THREAT signatures

Accessing following website is generating Spyware THREAT signatures. Does this means website is compromised and access should be blocked? Website: www[.]51qiti.comwww.51qiti[.]com/faq/Faq1217.htm Triggered signatures:Suspicious PHP Command and Control Traffic Detection(85633)Steganographic Webshell File Detection(85633)

Tanmoy by L0 Member
  • 2894 Views
  • 1 replies
  • 0 Likes

How are unused objects calculated

I couldn't find a definitive answer to a question regarding the discovery of unused address objects found by Expedition. According to the manuals, unused address objects are those not referenced in a security or nat rule. However, an address object may be contained within an address group object and that group referenced in a security rule. B...

Import/export settings

Hi everyone there is an export to csv/pdf option for rules/objects. is there an import button ? I would like to export these setting to another firewall surely I don't have to mess around in the CLI for this ? if it can read from the config location it can write to it surely ?

BPSoftware_1-1628736372029.png

Login issue for TACACS user in Palo Alto NGFW

We are not able to login into Palo Alto via TACACS user.PA NGFW is asking for reset password before login.We are not able to reset password.We have reset password complexity by login with another local user.We have not assigned any admin roles for TACACS user on firewall.So, how to mitigate the issue, if PA NGFW is asking to reset password.

Resolved! DSL PPoE IPv6

I use a PA-220 with PANOS 10.0.4. At the location the internet provider arrives with DSL (FTTH) where the modem is configured in bridge mode. The only option option available is using PPoE. Provider sends both a IPv4 and IPv6 addresses.On cheap home routers it is possible to use both IPv4 and IPv6.On the PA-220 IPv4 works just fine. But IPv6 is ...

fabeele by L1 Bithead
  • 3449 Views
  • 2 replies
  • 0 Likes

Resolved! SNMP monitore system message critical

I would like to know if is possible some OID MIBs palo alto send me a message that have critical, high or medium severity.Whem i filtering messages in Monitor>system like a "critical" a see some messages like this and I want receive some alert in my Zabbix with this alarms.So, someone know if via snmp it is possible ?

felcor by L0 Member
  • 3498 Views
  • 1 replies
  • 0 Likes

Azure VM cannot access the Internet

Hi there, We have deployed Hub and Spoke technology in Azure. All VM traffic is going through the FW. Settings of Spoke VM is same as Hub VM. NSG set to allow all traffic. FW is configured with 3 VR static routes (one route to the internet, one from Hub to Trusted Interface of PA and another route from Spoke to Trusted interface of PA), SNAT and...

Resolved! Inbound decryption working/not?

2 web servers, inbound decryption for both, one working and other does not and are using same wildcard cert.Bold are the only differences I see between 2. I don't know why working server without decryption shows the root instead of intermediate SHA2 certificate or vice a versa. However if i see the cert in browser it looks the same for both serv...

image.png
raji_toor by L4 Transporter
  • 3857 Views
  • 2 replies
  • 0 Likes

File Blocking not recognizing .docx or .xlsx files.

I just created a new file blocking profile and added xlsx, pdf, docx and multi-level-encoding. I set the action to alert. I want to monitor the found traffic prior to implementing a block rule. When I download a PDF file from the Internet, the vent is logged in the Monitor/Data Filtering. When I download a .docx or .xlsx file, it is not logged...

TI automation - Foundation: custom prototype and SOC integration [part 2]

Hi again, after good feedback received on the first post on MineMeld architecture and hardening I wrote a new post on how I built the foundation of near-real-time integration of MineMeld with our Information Security Operation Center (i-SOC) custom SPLUNK application. You can read the new post here Feedback welcome, tks Giovanni

soc_enav by L1 Bithead
  • 10983 Views
  • 2 replies
  • 6 Likes

Different data in ACC reports and custome created report

Helo Everybody,I have created a custom report in Panorama to generate the same data that we get in ACC - Application usage report, for last one month. But it looks like the data in the custom report is always different than that which is genereated in acc widget/report.

Pre-defined reports only useful for Last24 hours?

Hi,I wanted to use the pre-defined reports for a summary of the last 7 Days (or Last week) but as I see, these pre-defined reports only work for the last 24 hours / last day, even though I send the Email with all pre-defined reports only every sunday.Is there a possiblity to use the queries of the pre-defined reports for duration longer then 24 ...

Filter Policies by Target "Device-Tag" not possible with 9.1.x (Feature Request)

Hi,since we are changing policy targets from "device name" to "device tag" (device-Tag defined in Panorama > Summary), we still have the need to filter for special devices (device-tags) within the policy sets.But what I have seen with 9.1.6, filtering policies list by device tag is not possible.E.g.(target/devices/entry/@name eq '<device-t...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels