General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Application dependency Warning

Hello, We implemented the blocking policy for the custom URL categories however now once committed we receive commit warning like the following: Application 'dropbox-base' requires 'web-browsing' be allowed, but 'web-browsing' is denied in Rule 'outbound-advertisement-block'Application 'google-drive-web' requires 'google-base' be allowed, but 'g...

Farzana by L4 Transporter
  • 8697 Views
  • 6 replies
  • 0 Likes

BGP show Local RIB before Import filters

Hello, After applying Import filters in BGP the Local RIB is reduced to a filtered set of routes advertised by peers. However it seems to be impossible to see what the original set of advertised routes is. The peers are still advertising these routes, but there seem to be no methods in the GUI or CLI (show routing, debug routing ...) to see thos...

Resolved! Panwdbl.appspot.com unaccessible

Hi All, Looked at my nodes today and it looks like https://panwdbl.appspot.com is down or decommissioned. Tried going to this URL and I get a 404 error? Has this page moved and I missed a notification, down for good or just an outage? Obviously impacts some of the DBLs I have. Regards Adrian

a.jones by L3 Networker
  • 19063 Views
  • 8 replies
  • 0 Likes

Failed to setup Local log collector on Panorama VM

Hi community, I want to setup new panorama VM to replace old panorama M-100 and accept new devices.I have deployed a vm on ESX with one disk of 81Gb and second disk of 2Tb.Panorama running version 8.1.13,you can see partial output of show system info to understand system mode and ressources allowed to VM.**********system-mode is panoramaoperatio...

vmplayer_ih9AGwttKU.png

Mac OS Big Sur support

I have accidentally upgraded to Mac OS Big Sur, since then Global Protect app is not able to connect to VPN. Should I expect Global Protect to work on Big Sur already? Or is it on the way? Thanks

Resolved! Meraki and Palo side by side with Palo using BGP

We currently have this setup in our datacenter. The Meraki HA pair is the VPN endpoint for our 120+ remote sites. In a DR situation the datacenter has IP mobility, where our current static IPs will failover. This setup uses BGP through the Palo. With BGP enabled on the Palo HA Pair and datacenter’s internet the Meraki HA pair is inaccessible, wh...

setup.jpg
Screenshot 2021-03-02 132554.jpg

Resolved! *Urgent* SSH Protocol Version 1

Hi Peeps,I got technical query regarding how to change SSH v1 to SSH v2 in PA firewall, Because one of our customer got an alert from VAPT tool like as follows,. Description :- KPMG test team observed that the Secure Shell protocol version 1 support was enabled on the tested devices.Secure Shell is typically used as a cryptographically secure ...

Resolved! Data Filtering not sending to syslog

I've configured a data filtering profile and have been testing sending the data filtering detections to syslog, then to Sumologic. From what I've read, these detections are Threat Type, Data subtype in the logs. I have a log forwarding profile created to send all Threat logs regardless of severity or app to syslog and can see types like vulnerab...

DZhang by L1 Bithead
  • 4756 Views
  • 3 replies
  • 0 Likes

Can PA log a address of spoof attack?

Hi all.I wonder PA can log a IP and mac address of spoof attack such as ip spoof, arp spoof, dns query spoofing attack.Sometimes, customer want to know above information from PA.I think PA only drop a wrong packets. isn't it?Thanks.Regards.Roh.

ttongfly by L3 Networker
  • 6849 Views
  • 5 replies
  • 0 Likes

Resolved! Do websites get rescanned once flagged as Malicious?

We are starting to see valid websites showing up as malicious due to them being hacked or for some other reason. Once the site is cleaned up however, is it up to someone in the Palo Alto community to request a URL Category change manually, or is there an automated process that checks the website to see if it is still malicious? or another way to...

Block YouTube/Instagram Mobile app

Hello There, What is the best practice to block YouTube, Instagram for mobile apps? So far I tried to create an application base and custom URL policy to deny YouTube, Instagram. It works (deny access) if you access the site via HTTPS (Chrome, Firefox), but it won't work if I access YouTube, Instagram on mobile app. Thank you in advance

KurdTech by L1 Bithead
  • 9004 Views
  • 5 replies
  • 0 Likes

Resolved! NAT, Routing and license requirements

Hello Bros, I have an unlicensed and out of support single paloalto 3220 appliance, and this device is not licensed now as we have upgraded to paloalto ha.my question is I wanted to re-use this appliance for some network services such as nat and routing within the network. is this possible to accomplish without any licenses?TIA

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels