General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Data filtering - email issue

Hello all, i was configure data filtering and it works.But i face problems with the mailing. When the the fw match pattern it blocks it, but the email stuck in outbox queue , and the user can not send/receive other emails until the mail is deleted from the queue. Can we achieve some kind of silent drop, so for the client to look like the email ...

stef by L2 Linker
  • 2151 Views
  • 1 replies
  • 0 Likes

Resolved! PA 3050 web Gui access

I am working with PA-3050. I can log in using ssh, but i can not login via web Gui.http/https service are enable though.Can someone share some thoughts on how to proceed?

FIDELE by L1 Bithead
  • 3918 Views
  • 2 replies
  • 0 Likes

Minemeld Crashing, miner tab not loading, RPC timeout exception

Hi, we have an issue on our Minemeld instance in production. Similar to the issue reported in https://live.paloaltonetworks.com/t5/minemeld-discussions/minemeld-crashing/td-p/289998, minemeld randomly crashes with the following results: - the green loading bar keeps running across the screen - the nodes page won't load - TAXII output prototype i...

VCiverra by L1 Bithead
  • 5766 Views
  • 4 replies
  • 0 Likes

Different Actions for Security Rules

Hi Guys,I would like to know what are the difference between the following actions in the security rules for PA.1. Deny2. Drop3. Reset-client4. Reset-server5. Reset-bothWhich of these are the most preferred to use? Is deny or drop action also resets the connection for both server and client? Thanks

Nikko by L1 Bithead
  • 3887 Views
  • 4 replies
  • 0 Likes

Two IP address from same subnet on an 1 Aggregated Interface

Hello All, I am pretty new to Palo Alto, wanted to check if the an aggregated port in PA can be assigned with 2 IP addresses from same subnet, say 1.1.1.2/29 and 1.1.1.4/29. The Idea is the ethernet interfaces 1 & 2 that are be bonded to ae will be connected to the two core switches (port 1 to switch 1 and port 2 to switch 2). After configu...

Aithal by L0 Member
  • 3483 Views
  • 1 replies
  • 0 Likes

SMB URL File Logging acheivable or not?

Hi Palo Alto Experts, I want to know if we want to log SMB URL Blocked events then can we do in Palo Alto or not? Basically, the requirement is as below: Example URL if typed by compromise system is: smb://www.example.com/fileshare/malware.exe Right now I am only able to see Source IP, destination IP and Port, NAT information but full logging wo...

Add network to address group via CLI?

I am trying to add a network to an address group via CLI on PAN OS 9.1.X # set vsys vsys2 address-group XXXXXXXX static 108.61.41.0/24 Server error : static '108.61.41.0/24' is not a valid reference What is the valid syntax?

jsogla by L0 Member
  • 2265 Views
  • 1 replies
  • 0 Likes

Outside interface listening on HTTPS "502 Bad Gateway"

I have this odd issue whereas one of HA Pairs seems to be listening on 443 on its outside interface for GP but I don't use GP and never had. I have a interface profile that allows HTTPS but not from any IP and when I disable that it still shows that page. no GP portal configured either. How can I stop it from listening on 443 for any source IP?

drewdown_0-1612816320888.png
drewdown by L4 Transporter
  • 3265 Views
  • 2 replies
  • 0 Likes

Resolved! Is JSON Based URL is configurable in Security Policy as EDL.

Hi Team, Please confirm us can we configure JSON based URL as a EDL in Security policy on Palo Alto Firewall. Herewith, I have provided you with the sample JSON Website for your reference. Please refer and share us with your valuable inputs. https://snat.f5silverline.com/api/v1/snat -->> JSON Website I have also tried to configure EDL with...

SahulH_0-1613372205367.png
SahulH by L3 Networker
  • 7997 Views
  • 3 replies
  • 0 Likes

URL wildcard Pattern

Hello everyone, I need to block URLs that have a word pattern/string, It is possible to restrict certain strings inside the name of a URL?? for example the word "good" inside the website "www.goodwill.com" to be blocked ? I already try with Wildcards, any ideas on how to achive this ? block keywords for web browsing is this possible and how to d...

Destination NAT for Route base VPN

We have an requirement to set up a route base VPN, but remote proxy IP subnet clash with an existing remote subnet. We are planning to use destination NAT, but not sure, how the routing will be controlled. Please help to solve this problem.

Gurupada by L0 Member
  • 2019 Views
  • 1 replies
  • 0 Likes

Resolved! 5260 Z MGMT PROCESS AND APP/THREAT MISMATCH

Hi, I am upgrading os for some 5260 this weekend however, just realised its showing app and threat mismatch. Upon t-ahooting I realised the management process on active firewall is showing Z defunct. My understanding is that it is a Zombie process and I probably need to restart mgmt process. However, as I will be failing over and firewall will b...

qasim02 by L2 Linker
  • 3321 Views
  • 2 replies
  • 0 Likes

Incompatibility Acrobat-GlobalProtect

Hi, Customer upgrade Adobe to versión 21.001.20135 and Global Protect stopped working. Issue is th esame like this:https://community.adobe.com/t5/acrobat/adobe-acrobat-reader-21-001-20135-preventing-users-to-connect-to-global-protect/td-p/11823885?profile.language=es Do you know if there is anything to do in Global Protect for this?

BigPalo by L4 Transporter
  • 2925 Views
  • 1 replies
  • 1 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels