Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall
Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall - SANS Internet Storm Center
Subscribing to the DShield Top 20 on a Palo Alto Networks Firewall - SANS Internet Storm Center
Is it possible to detect dual homed hosts connected to two or more security zones at the same time.
Looking to set up multiple data center redundancy for GlobalProtect and I'm unsure if Palo Alto would support a global load balancer (GLB) for the solution. We have global load balancer DNS servers that detect the status of our DC internet connections and will remove the IP's from the DNS entry if an ISP is down. The TTL on the DNS entries is ...
I now have GP connected automatically with a certificate pushed out via InTune. This is on a Surface Laptop running Win 10. I typically log in with face recognition. After I log on and notice that I have TCP/IP access through the GP connection and internal DNS is working - I am trying to then go to a file share. \\whatever\sys$\whichever say. I ...
I am looking to block TOR IPs inbound and outbound on my perimeter firewalls. Do any of you know of any trusted list of TOR nodes which I can use in EDLs? Thanks.
Hi, I know that there are many threads here about this. We would like to show the response pages for https. We saw this link but i have several doubts:https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0This command is enabled globally: "set deviceconfig setting ssl-decrypt url-proxy yes". So, is this command decrypt...
Hello everyone,I have a problem with allowing wetransfer to download and blocking the download,Wetransfer is part of the 'Online-storage-and-backup' category.The choice is to block this category and create a bypass just for downloading on wetransfer,On my side, I tried to create a URL whitlist category:we.tl/*wetransfer.com/downloads/*Do you hav...
Hi Team, We need our PA devices to block bulk mails from our trust zone.We have an email relay in our organisation.Can we achieve it through custom vulnerability signature by creating an signature and applying threshold value
NAT translation goes like this:Destination NAT and Security Policy:https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping.htmlPolicy Based Forwarding:Polices > Policy Based Forwarding >Under General Tab > Name "Incoming"Under Source Tab > Zone "Out...
Hello, can anyone please help me for the below request? site to site vpn setup for oracle cloud using palo alto CPE. Can someone please tell me recommend setting for Phase 1 (ISAKMP) and Phase 2 (IPsec)?? thank you!
Anyone ever seen a one way audio when mitel phone configured for telework mode is on the inside trusted network? The mitel border gateway is in the dmz nat'd to an outside public ip, and works fine with all phones but telework enabled phones when on the inside lan. Thanks, Jeff
Greetings to all,I have problem to recognize MacPaw 1.2.5 malware by GlobalProtect 5.1.5-20 agent. (Host Profile)Does anyone have any idea ?Thank you very much.Raul.-
Good day, I have a trouble creating an account for customer support, I don't know where can i find the customer id or sales id. Hope you help me with this problem. Thank you
Does anyone know if there is a way to see what traffic, or if traffic, is hitting decryption policies for Prisma traffic? I have some policies I would like to clean up if I can, but unlike security policies, I can't seem to filter traffic that may be utilizing decryption policies. Thanks.
I am looking for creative ways to get my VM-300 instances to syslog directly into an S3 bucket for pickup by our logging systems. Given the PAN only has the ability to send syslog TCP to an endpoint I am not sure this is possible without some middleware.Has anyone else figured something out to achieve this?
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

