General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

Resolved! Global Protect Split Tunnelling

We are enabling split tunnelling for O365 traffic. I have added a object for a known website so I can test this. I can see the IPs in the PANGPS logs so the configuration is pushed to the client. I have also enabled the Split Tunnelling in the APP for Network and DNS. When I am connected to Global Protect and visit the test website it is incredi...

a.jones by L3 Networker
  • 3555 Views
  • 2 replies
  • 0 Likes

TS Agent - System Source Port Allocation Range Registry Key

Hey, the following text you can find on this page:The System Source Port Allocation Range and System Reserved Source Ports fields specify the range of ports that will be allocated to non-user sessions. Make sure the values specified in these fields do not overlap with the ports you designate for user traffic. These values can only be changed by ...

J.Schoen by L0 Member
  • 7812 Views
  • 3 replies
  • 0 Likes

Unable to export ACC last-60-seconds stats

Hi,I'm looking for a way to export regular per-IP bandwidth usage stats in a human-readable format. I have found out that it's possible to get this in .xml via REST API. I'm trying to create a top-src-summary for the period of last-60-seconds. This however generates a blank report (see the first screenshot). There is no issue, if I generate a re...

Capture1.PNG
Capture2.PNG
DuzyGl by L0 Member
  • 2741 Views
  • 3 replies
  • 0 Likes

Resolved! Global Protect Always On and stopping local network access in event of failure

Hi All, Is it possible to stop a device from connecting to the local network if the Global Protect Gateway fails? I have a question from a customer that has an Always On Pre-Logon environment and wants to ensure the connection defaults to a fail-closed mode with no access to the local netwok - although it must allow for initial connections to ne...

a.jones by L3 Networker
  • 3033 Views
  • 2 replies
  • 0 Likes

SWIFT ISAC TAXII Feed

Hi guys I’m’ just curious – SWIFT has offered recently for all members TAXII interface to poll IOCs via https://taxii.swift.com/taxii Feed is not open for everybody – each member must request access to it individually, so it’s not easy to test it. Has anybody already tried it? My simple attempt to use “minemeld.ft.taxii.TaxiiClient” class t...

Resolved! Can Panorama managed devices be configured via the CLI?

Hey folks. I'm adding a Panorama server into my infrastructure to enable zero touch SDWAN provisioning, and since I've never done Panorama before, I've got a question. Can panorama managed devices be configured via the CLI? The reason I ask this is that I do a fair bit of work with AWS and VPC's - and configuring a new VPC into AWS is mostly don...

darren_g by L4 Transporter
  • 7417 Views
  • 4 replies
  • 0 Likes

GlobalProtect IOS split tunnel routing incorrect traffic

PanOS 9.1.4, GP client 5.2.7-6. We have a split tunnel configuration with only 2 internal /32 addresses added to the access route include list. We regularly see traffic from GP clients destined for Internet IP addresses hit the Palo over the client tunnel. This is from several IOS clients - we don't have any other client O/S'es to test with. Is ...

Andy123B by L0 Member
  • 3503 Views
  • 1 replies
  • 0 Likes

Searching for rule with empty "description" field in the ruleset

Dear community I am looking for a way to filter all rules without any value in the description field. We use this filed to reference the incident number which has been raised to request a security rule. And by policy we are not allowed to have any rules in our set where there is not reference in the description field. So i have tried to use the...

TiborNad by L1 Bithead
  • 5889 Views
  • 4 replies
  • 0 Likes

Need assistance with fixing weak Ciphers via Panorama cli

Hi I wanted to update weak ciphers on a PA-VM using the document below, I wanted to apply the change via Panorama but I don't see the correct config to apply.I have tried the following: >set cli config-output-format set#set template "template name" config vsys vsys1 Is this the correct format? I am not sure where I can reference system ssh ...

Amin2 by L2 Linker
  • 2190 Views
  • 1 replies
  • 0 Likes

After upgrade Panorama from 8 to 9 Panorama stopped sending GP-logs to Qradar syslog server.

Before the upgrade everything was working just fine, now after upgrade still I can see the GP-logs sent from the Firewalls to Panorama, but Panorama still unable to sent those logs to Qradar syslog server. Connectivity between the 2 devices is good.I found the below document to review the configuration to see if anything is missing but the docum...

Data filtering - email issue

Hello all, i was configure data filtering and it works.But i face problems with the mailing. When the the fw match pattern it blocks it, but the email stuck in outbox queue , and the user can not send/receive other emails until the mail is deleted from the queue. Can we achieve some kind of silent drop, so for the client to look like the email ...

stef by L2 Linker
  • 2168 Views
  • 1 replies
  • 0 Likes

Resolved! PA 3050 web Gui access

I am working with PA-3050. I can log in using ssh, but i can not login via web Gui.http/https service are enable though.Can someone share some thoughts on how to proceed?

FIDELE by L1 Bithead
  • 3975 Views
  • 2 replies
  • 0 Likes

Minemeld Crashing, miner tab not loading, RPC timeout exception

Hi, we have an issue on our Minemeld instance in production. Similar to the issue reported in https://live.paloaltonetworks.com/t5/minemeld-discussions/minemeld-crashing/td-p/289998, minemeld randomly crashes with the following results: - the green loading bar keeps running across the screen - the nodes page won't load - TAXII output prototype i...

VCiverra by L1 Bithead
  • 5860 Views
  • 4 replies
  • 0 Likes

Different Actions for Security Rules

Hi Guys,I would like to know what are the difference between the following actions in the security rules for PA.1. Deny2. Drop3. Reset-client4. Reset-server5. Reset-bothWhich of these are the most preferred to use? Is deny or drop action also resets the connection for both server and client? Thanks

Nikko by L1 Bithead
  • 3938 Views
  • 4 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels