General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1911 Views
  • 0 replies
  • 0 Likes

OKTA SAML panorama authentication?

Trying to get this working and I am able to authenticate using OKTA SAML  via the button on the login screen but when I do (after entering u/p on the OKTA page) it redirects me back to the Panorama login page.  I see PAN_AUTH_SCUESS SAML on the CLI b

...

drewdown by L4 Transporter
  • 5677 Views
  • 5 replies
  • 0 Likes

Resolved! 1:1 destination nat mapping

Hi everybody,

 

  does anybody know if it is possible to write a single destination NAT policy in order to map ip addresses from a given range/network to a corresponding range/network of the same size preserving the host portion of the address? I try t

...

grenzi by L3 Networker
  • 5848 Views
  • 3 replies
  • 0 Likes

Custom Snort Signature

creating a custom snort signature on Palo alto Firewall but didn’t found the concern context operator for match pattern.

Shall we create a context operator or how it can add the pattern if the context operator is not available?

 

For example:

alert tcp $

...

Snort.jpg

Resolved! Global Protect Split Tunnelling

We are enabling split tunnelling for O365 traffic. I have added a object for a known website so I can test this. I can see the IPs in the PANGPS logs so the configuration is pushed to the client. I have also enabled the Split Tunnelling in the APP fo

...

a.jones by L3 Networker
  • 3303 Views
  • 2 replies
  • 0 Likes

Unable to export ACC last-60-seconds stats

Hi,

I'm looking for a way to export regular per-IP bandwidth usage stats in a human-readable format. I have found out that it's possible to get this in .xml via REST API. I'm trying to create a top-src-summary for the period of last-60-seconds. This h

...

Capture1.PNG
Capture2.PNG
DuzyGl by L0 Member
  • 2499 Views
  • 3 replies
  • 0 Likes

SWIFT ISAC TAXII Feed

Hi guys

 

 

I’m’ just curious – SWIFT has offered recently for all members TAXII interface to poll IOCs via  https://taxii.swift.com/taxii

Feed is not open for everybody – each member must request access to it individually, so it’s not easy to test i

...

Resolved! Can Panorama managed devices be configured via the CLI?

Hey folks.

 

I'm adding a Panorama server into my infrastructure to enable zero touch SDWAN provisioning, and since I've never done Panorama before, I've got a question.

 

Can panorama managed devices be configured via the CLI?

 

The reason I ask this is t

...

darren_g by L4 Transporter
  • 6444 Views
  • 4 replies
  • 0 Likes

GlobalProtect IOS split tunnel routing incorrect traffic

PanOS 9.1.4, GP client 5.2.7-6. 

We have a split tunnel configuration with only 2 internal /32 addresses added to the access route include list. We regularly see traffic from GP clients destined for Internet IP addresses hit the Palo over the client t

...

Andy123B by L0 Member
  • 2850 Views
  • 1 replies
  • 0 Likes

Need assistance with fixing weak Ciphers via Panorama cli

Hi 

I wanted to update weak ciphers on a PA-VM using the document below, I wanted to apply the change via Panorama but I don't see the correct config to apply.

I have tried the following:

 

>set cli config-output-format set

#set template "template name" c

...

Amin2 by L2 Linker
  • 2001 Views
  • 1 replies
  • 0 Likes
  • 24258 Posts
  • 117 Subscriptions
Top Liked Authors
Labels