General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How are unused objects calculated

I couldn't find a definitive answer to a question regarding the discovery of unused address objects found by Expedition. According to the manuals, unused address objects are those not referenced in a security or nat rule. However, an address object may be contained within an address group object and that group referenced in a security rule. B...

Import/export settings

Hi everyone there is an export to csv/pdf option for rules/objects. is there an import button ? I would like to export these setting to another firewall surely I don't have to mess around in the CLI for this ? if it can read from the config location it can write to it surely ?

BPSoftware_1-1628736372029.png

Login issue for TACACS user in Palo Alto NGFW

We are not able to login into Palo Alto via TACACS user.PA NGFW is asking for reset password before login.We are not able to reset password.We have reset password complexity by login with another local user.We have not assigned any admin roles for TACACS user on firewall.So, how to mitigate the issue, if PA NGFW is asking to reset password.

Resolved! DSL PPoE IPv6

I use a PA-220 with PANOS 10.0.4. At the location the internet provider arrives with DSL (FTTH) where the modem is configured in bridge mode. The only option option available is using PPoE. Provider sends both a IPv4 and IPv6 addresses.On cheap home routers it is possible to use both IPv4 and IPv6.On the PA-220 IPv4 works just fine. But IPv6 is ...

fabeele by L1 Bithead
  • 3517 Views
  • 2 replies
  • 0 Likes

Resolved! SNMP monitore system message critical

I would like to know if is possible some OID MIBs palo alto send me a message that have critical, high or medium severity.Whem i filtering messages in Monitor>system like a "critical" a see some messages like this and I want receive some alert in my Zabbix with this alarms.So, someone know if via snmp it is possible ?

felcor by L0 Member
  • 3559 Views
  • 1 replies
  • 0 Likes

Azure VM cannot access the Internet

Hi there, We have deployed Hub and Spoke technology in Azure. All VM traffic is going through the FW. Settings of Spoke VM is same as Hub VM. NSG set to allow all traffic. FW is configured with 3 VR static routes (one route to the internet, one from Hub to Trusted Interface of PA and another route from Spoke to Trusted interface of PA), SNAT and...

Resolved! Inbound decryption working/not?

2 web servers, inbound decryption for both, one working and other does not and are using same wildcard cert.Bold are the only differences I see between 2. I don't know why working server without decryption shows the root instead of intermediate SHA2 certificate or vice a versa. However if i see the cert in browser it looks the same for both serv...

image.png
raji_toor by L4 Transporter
  • 3924 Views
  • 2 replies
  • 0 Likes

File Blocking not recognizing .docx or .xlsx files.

I just created a new file blocking profile and added xlsx, pdf, docx and multi-level-encoding. I set the action to alert. I want to monitor the found traffic prior to implementing a block rule. When I download a PDF file from the Internet, the vent is logged in the Monitor/Data Filtering. When I download a .docx or .xlsx file, it is not logged...

TI automation - Foundation: custom prototype and SOC integration [part 2]

Hi again, after good feedback received on the first post on MineMeld architecture and hardening I wrote a new post on how I built the foundation of near-real-time integration of MineMeld with our Information Security Operation Center (i-SOC) custom SPLUNK application. You can read the new post here Feedback welcome, tks Giovanni

soc_enav by L1 Bithead
  • 11059 Views
  • 2 replies
  • 6 Likes

Different data in ACC reports and custome created report

Helo Everybody,I have created a custom report in Panorama to generate the same data that we get in ACC - Application usage report, for last one month. But it looks like the data in the custom report is always different than that which is genereated in acc widget/report.

Pre-defined reports only useful for Last24 hours?

Hi,I wanted to use the pre-defined reports for a summary of the last 7 Days (or Last week) but as I see, these pre-defined reports only work for the last 24 hours / last day, even though I send the Email with all pre-defined reports only every sunday.Is there a possiblity to use the queries of the pre-defined reports for duration longer then 24 ...

Filter Policies by Target "Device-Tag" not possible with 9.1.x (Feature Request)

Hi,since we are changing policy targets from "device name" to "device tag" (device-Tag defined in Panorama > Summary), we still have the need to filter for special devices (device-tags) within the policy sets.But what I have seen with 9.1.6, filtering policies list by device tag is not possible.E.g.(target/devices/entry/@name eq '<device-t...

PAN Security Advisory (11-AUG-2021)

Thought I would just put this notice out since I know a lot of people don't actually subscribe to security advisories directly. If you haven't already, I highly recommend that you sign up for notifications via https://security.paloaltonetworks.com/ and the 'Subscribe' feature at the top right.As a general statement, you should ensure that you ar...

BPry by Cyber Elite
  • 4116 Views
  • 3 replies
  • 1 Likes

User id not fetching for same ip in traffic logs.

User id not fetching in traffic logs.we created user base rule on that basis mapped ip address shows user id for same rule .but some time user is not authenticated from that user base policy rule and it is moving from next any any rule. if it is moving from any any rule that time it is not showing user-id mapping.

SurajN by L2 Linker
  • 2107 Views
  • 1 replies
  • 0 Likes
  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels