General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4222 Views
  • 0 replies
  • 0 Likes

Resolved! Wildfire without SSL Decryption

We are looking at Wildfire for our PA firewalls however, we are not doing any SSL decryption. Going into it I figured we only be and to use it on unencrypted traffic. But looking at the Wildfire datasheet under file support it lists TLS and SSL files. I'm confused how that would work at the firewall itself couldn't actually read it. Is it saying...

bafergel_1-1627663836266.png
bafergel by L2 Linker
  • 3363 Views
  • 1 replies
  • 0 Likes

Resolved! You don't have permission to access "http://www.costco.com/" on this server.

There are certain websites that I cannot visit behind the firewall, and get errors saying You don't have permission to access XYZ on this server. In this case, I cannot visit www.costco.com I am accessing with https/ Has anyone figured out how to resolve the issue? Do you have to disable SSL decryption for these sites or something else? I do...

fhewiufhwefhwe_0-1627664109981.png

Resolved! PAN routing IPv6 traffic to UnTrust with default route pointing elsewhere

I have a PAN on the internet with only IPv4. I have an ASA dual stacked that I want to send IPv6 traffic from hosts connected behind the PAN to the ASA via the LAN. All the interfaces on the PAN in the path have IPv6 configured. However, when the pan receives IPv6 packets that need to route it simply sends it out the UnTrust zone vs the Trust ...

drewdown_1-1627585916395.png
drewdown_0-1627587532904.png
drewdown by L4 Transporter
  • 5281 Views
  • 4 replies
  • 0 Likes

Resolved! Regarding sinkholed hosts

Hello Bros, We have subscribed to palo alto dns-security and the license has been applied to the device.Rules with anti-spyware "dns-security sinkhole action enabled".Now regarding the hosts with sinkhole action, that means these hosts trying to connect to a malicious domains.These trials blocked but is these another recommended actions to be...

Verify pdf report sent via email scheduler

We have configured email scheduler to send reports in pdf format.I'm able to receive the email. But attachment is missing.I can see from system logs that the files are created and email is sent.How can I verify whether the PDF report was attached to the email when it was released from firewall. Model - PA-820PAN-OS - 10.0.5

Paloalto don t send log correctly to logstash

Hi evrey one,I'am new to Paloalto and I have a problem with the threath log. I am currently using ELK stack to store and visualize all log from paloalto. When I send the traffic log to logstash there is no problem (there are all field explained in the documentation), but when i send the threat log all the field explained in the documentation are...

Betorov by L0 Member
  • 2816 Views
  • 1 replies
  • 0 Likes

Global protect not working

Hi Team, We have faced our GP not working 26/07/2021 around 09:15 pm. After the firewall restarts its started to work. When I analyzing TSF I got the ssl vpn below error. "The PID for this process changed indicating it was restarted" 2021-07-26 21:17:33.573 +0530 --- processesTotal num processes: 39Name PID CPU% FDs Open Virt Mem Res+Swap Statep...

VishnuPS by L3 Networker
  • 3220 Views
  • 3 replies
  • 0 Likes

New 5220 non-functional state

New HA 5220 active-active and non-functional status.HA-1 and HA-2 cable attachedSet up box boxes direct mode and then created templates via PanoramaPanorama doesn't display to parameters defined in direct config statusHow to ensure configs are dumped into template correctly

Default MTU of 1496B in interfaces of VM platforms?

Dear community! We have couple of VMs deployed in MS hyper-v and I realized that all interfaces have a MTU of 1496 bytes even though no value was configured. Checked this with "show interface XXXX" command Shouldn´t the interfaces have MTU of 1500 bytes if no value is assigned or for VMs the MTU is different? Kind Regards!

Carracido by L4 Transporter
  • 3103 Views
  • 1 replies
  • 0 Likes

Simple policy not working?

Outbound communication to the following IP addresses must be allowed:- 64.58.49.24- 64.58.49.25- 64.58.49.26- 64.58.49.28- 64.58.51.56- 64.58.51.57- 64.58.51.58 text router will attempt to communicate with the above IP addresses over the following protocols and ports:- UDP 500- UDP 4500- IP Protocol 50 for ESP- ICMP SourceRule I have set up is Z...

Resolved! Internet video UDP-range - STUN?

Our HR uses Interview from Indeed https://interviews.indeed.com/demo/video/I've tried to open firewall ports with application STUN, service ANY.But that did not work (error message because of missing "network connection").For testing I've opened all ports for my user, that worked. So I knew it's the firewall.I've ended up with trial and error.At...

ChrisCon by L2 Linker
  • 4472 Views
  • 2 replies
  • 0 Likes

PA will not update malware signature from sample malware files (http://wildfire.paloaltonetworks.com/publicapi/test/apk)

the customer want to test pa wilfire feature .my test step:1: from http://wildfire.paloaltonetworks.com/publicapi/test/apk, download the sample malware.the traffice throught the pa2: when we can find the wildire log from firewall and theck the log report ,know the malware files sha256------------------------------------------------log: 33, ...

Felixcao by L3 Networker
  • 3707 Views
  • 4 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels