General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

File Integrity Monitoring using Cortex via Corelation Rule

Dear all, I'm looking for FIM on Linux (like etc/shadow), I try with previous conversation use this query: dataset = xdr_data |filter event_type = FILE and (event_sub_type = FILE_CREATE_NEW or event_sub_type = FILE_WRITE or event_sub_type = FILE_REMOVE or event_sub_type = FILE_RENAME ) |filter lowercase(action_file_path) in ("/etc/*","/usr/loc...

Resolved! helps generate an XQL to notify when a USB is connected

I am trying to use Cortex XDR so that when a user connects a USB storage device I receive a notification by email. so far I have used this XQL: preset = device_control| filter event_sub_type = ENUM.DEVICE_PLUG which tells me when any USB device is connected to the endpoints, I added this as a BIOC rule so that when the condition is met it ...

Resolved! Zero-Trust Strategy for Prisma

Hi all I have been tasked with providing a Zero-Trust strategy document to management, related to how to implemenet this on our Prisma Access solution. I am looking for some examples that I can pull from that anyone has done this already for. I have gone thru so many Palo documents, discussing all the Pillars etc, there is so much information o...

D.Maas by L1 Bithead
  • 6615 Views
  • 11 replies
  • 0 Likes

Resolved! Retention period for traffic logs on Panorama

Hello Experts What is the rention period for traffic logs on Panorama, I mean how many days it will keep the traffic logs from firewall. Actually I need to do the harden the security rules by looking the traffic logs.

ghostrider by L4 Transporter
  • 33181 Views
  • 12 replies
  • 0 Likes

Anti-Spyware Behaviour and Inline Cloud Analysis

Hello All, I have run into some curious behaviour with Anti-Spyware. High severity threats tagged as threat type 'spyware' are coming through the firewall with an action of alert, despite all configurations pointing to an action that should either be reset-both, or sinkhole. I have confirmed the following: The security policy rule that m...

nohash4u by L3 Networker
  • 3560 Views
  • 6 replies
  • 0 Likes

Redundancy for Global protect VPN

Dear Friends, We have a customer who is Currently configured with GP- Global Protect for VPN is connecting with ISP-1, one Public IP / One ISP-Internet Service Provider. Requirement is, can we configure as backup or as redundant with another ISP-2 ? Purpose : Once One ISP is down, then GP- Global Protect users will not disconnect from remote...

Resolved! Undetected APP dependency?

Hi. So we ran into an issue and we're not sure if there's a missing app dependency in the Palo Alto db or if we're missing something. What happened was, we migrated one Policy from port to APP-based. On the Apps seen it only had one detected app (let's call it app1) with no new apps seen for a long time. This rule is being hit regularly by tr...

mR00t_s5 by L2 Linker
  • 1627 Views
  • 2 replies
  • 0 Likes

Migrate Fortinet to palo alto

Hello, We are planning to migrate from a Fortinet firewall to a Palo Alto Networks firewall. As this is my first time handling such a migration, I would greatly appreciate guidance from an expert on the step-by-step actions required. NGFW

Resolved! HA active/active dual ISP load balancing

Hi all, I am considering network design that have: - Dual ISP (public IP /29 for each) - 2 x PA with active/active HA - PA connects directly to L2 networks (LAN) Requires: Load sharing between 2 ISP Internet links Problems: Is it possible to configure separated nat for each? How session can failover to remaining PA? Do I need Floating IP for...

nw-rogox by L0 Member
  • 8433 Views
  • 4 replies
  • 0 Likes

Resolved! Is the Cloud Identity Engine required for filtering by Group when using Entra without LDAP?

I feel like I've read every document on this forum but I can't seem to find a solid answer to this question. I'm sure someone will link 4 other posts..... 🤦‍♂️ I am using SAML Auth to Entra for GlobalProtect. I can auth to the Portal if I specify the user directly (using domain.com\username - [email protected] does not work). I can also ...

KSaucier_0-1748887583212.png

Shutting down/disabling subinterfaces

I am very new to the PANOS world so I will apologize in advance if this is obvious, however my search of documentation and knowledebase did not yield anything. I have been looking for a way to administratively shut down sub interfaces. Is this possible? While it's easy enough to shutdown a physical interface by assigning it's link-state we're no...

scourge by Not applicable
  • 36363 Views
  • 15 replies
  • 0 Likes

Join RQL query throwing Failed to execute RQL search . Illegal Argument

Hello team, I am trying to execute the below join query in achieve the below output- 1. Only Service accounts that has have elevated roles (e.g., roles/owner, roles/editor) 2. Service accounts that have atleast one user-managed key config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-projects-get-iam-user' AND json.rule =...

Thoughts and experience with the Prisma secure browser

Hello Community, I'm looking for general feedback on those who have or had used the secure browser for DLP. Things that work well, things that didnt, etc. Just looking for non sales honesty on it. The purpose of its use would be to use the DLP feature when users utilize AI prompts etc. To help prevent PII or PHI leakage. Thanks in advance!

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels