General Topics
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics

Discussions

New Product mention feature

Hey everyone, We just enabled a feature on the LIVEcommunity that allows for products to be linked inside of discussions or articles.. this helps cross link information throughout the site, especially useful if you are looking for specific informatio...

jdelio by Community Team Member
  • 556 Views
  • 2 replies
  • 4 Likes

Resolved! GlobalProtect, Working from Home, Prisma Access and Covid-19

To all, Just wanted to post a message about the Hot Topic right now, which is Covid-19. With all of this going around, everybody's health and safely is the utmost concern. Keeping your hands clean, washing your hands (A LOT), using hand sanitizers, a...

jdelio by Community Team Member
  • 24213 Views
  • 43 replies
  • 33 Likes

Resolved! Panorama Shared Policy Zones

Hi all,I want to understand before I deploy shared policy in Prod I have 2*2 firewalls in HA (2 For DMZ, 2 For LAN) - I want to create a shared policy to both firewalls (LAN and DMZ)For example,In LAN I have 3 zones (Users, Servers, DMZ) In DMZ I Hav...

Resolved! zone protection issue.

Hi to all!I have such kind of problem.I have applied Zone Protection profile on my outside(untrust) interface.The problem is, that PAN is behind IBR(is configured as virtual wire), where are configured all our public ip.What can we do in this case?Th...

Re: configure airgapped miner for on premise minemeld

Hi guys, we recently setup a minemeld server meant for a airgapped environment and we are trying to figure out how to setup a airgapped miner with the other information found here on customizing a miner. https://live.paloaltonetworks.com/t5/MineMeld-...

Resolved! Traffic using unintended Security Rule?

Hello folks, We have recently installed Cisco Nexus switches and UCS system. All of our routing has been through our PA firewall and continues to be, except for a new Management network created on the Nexus switch. We are trying to use this managemen...

pasecurityrule3.jpg
pasecurityrule2.jpg
pasecurityrule.jpg
OMatlock by L4 Transporter
  • 960 Views
  • 5 replies
  • 0 Likes

Query on HA pair upgrade

Hello, We are using PAN-OS 7.0.2 which is end of life and wanting to upgrade to 7.1.17. Can we upgrade one firewall through all the versions 7.0.2-->7.0.19-->7.1.0-->7.1.17 before moving on to another in the pair or do we have to bring both firewalls...

Farzana by L4 Transporter
  • 1032 Views
  • 4 replies
  • 0 Likes

Miner shows 422 Unprocessable Entity

Hi, I am trying to configure a miner that downlods a stream of IP addresses via HTTPS request. Data stream looks like this1.1.1.12.2.2.22.2.2.33.3.3.3etc. I created the following protype NSFOCUS_ip-v2: class: minemeld.ft.http.HttpFT config: attribute...

otto38dd by L0 Member
  • 1635 Views
  • 3 replies
  • 0 Likes

SSL Decryption breaks certain website functionality

So I’ve enabled SSL decryption and as expected some sites or applications fail when it’s turned on. No problem I can exclude the domain from decryption.I have a special case though, in the fact that one of these web applications is a service that my ...

welly_59 by L3 Networker
  • 920 Views
  • 3 replies
  • 0 Likes

Resolved! Route specific traffic out backup ISP?

We have dual ISP (ISP-A and ISP-B) and utilizting PBR which works just fine. Now I have use case whereas I have a NAT configured on ISP-B (1 to 1) and I want to force traffic to a specific destination out the backup interface. I want to do this to en...

drewdown by L4 Transporter
  • 3883 Views
  • 13 replies
  • 0 Likes

Resolved! Upgrading GlobalProtect while on corp network

Hi everyone, I have a client who said every time they try to upgrade globalprotect, they have mixed results. The issue seems to be that they'll set the GP App to "Allow with prompt". However, the users will never get the prompt while they are on the ...

ce1028 by L4 Transporter
  • 1566 Views
  • 9 replies
  • 0 Likes

Resolved! Adding app depencendies

This might be a dumb question, but I visited 3 clients in the past 2 weeks that did not include application depenendcies in their policy rules For example, they'll have a rule allowing webex-base, but don't add rtcp, rtp-base, or stun. To be fair, at...

ce1028 by L4 Transporter
  • 848 Views
  • 2 replies
  • 0 Likes

SSL Version

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

Resolved! HTTPS URL Filtering without decryption

Hello all, I am trying to implement URL Filtering for HTTPS websites but without decryption. I found a post on how to deliver response pages to Users. (https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-...

Resolved! Untrust to Untrust - Allow

I was working at a customer site and noticed the customer's last rule before their "Catch-All - Deny" rule was "Untrust - Untrust Allow". It was a universal rule with source zone untrust destination zone untrust set to allow. When I asked why they ha...

ce1028 by L4 Transporter
  • 4927 Views
  • 11 replies
  • 0 Likes
Top Liked Authors