General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SSL Decryption URL and App Filter

Hello everyone,

I have to block some URLs and applications as per our company policies. Since we dont have a general rule from the inside zone to the outside (Internet), we are very restrictive in our access to the internet, and since there are some w

...

joseglez by L1 Bithead
  • 3584 Views
  • 2 replies
  • 0 Likes

SD-WAN policy name not showing for ping application

In our demo SD-WAN setup we have a couple of SD-WAN rules for ping traffic and also a catch-all rule for all unmatched traffic. For most of the tested applications everything is fine. But for ping (and traceroute) the SD-WAN policy name field in traf

...

santonic by L6 Presenter
  • 2285 Views
  • 0 replies
  • 1 Likes

Resolved! Outbound RDP access

I just heard one of my coworkers saying we need to block outbound access to RDP, I didn't have chance to follow up with him what him because of COVID-19.  I am trying to to understand what would be the reason, is that a best practice possibly?

 

 

Amin2 by L2 Linker
  • 5055 Views
  • 4 replies
  • 0 Likes

FIPS 140 and CC enabling?

Couple of questions on FIPS.

 

  1. When you enable FIPS140 on a Palo it wipes the device. Can you just reload your last saved?
  2. Can a FIPS140 enabled device talk to a non-FIPS device over an ipsec tunnel provided the cyphers are compatible?
  3. FIPS disables PAP.
...

HA for 3250 FW throught VXLAN

Hi everyone!

I have an interesting case. My topology is:

PA 3250 HA1------> Nexus 9000---------------VXLAN Overlay-------------------- Nexus 9000--------> PA 3250 HA1

                               vlan 2201                                             

...

Rdp windows

Hi,

is it a good idea giving access to public windowd  rdp ?.

Folks says do not publish outside 

Any good reason for this ?

Thanks

 

simsim by L4 Transporter
  • 6547 Views
  • 11 replies
  • 0 Likes

Resolved! Cleanup Rule

Do you recommend creating a cleanup rule (last rule to deny any any) in PA? As far as I know, PA firewalls only allow traffic explicitly defined, and the last DENY is a built in "known rule"…correct?

 

or will the interzone policy take care of this?

 

 

Anees10 by L0 Member
  • 6381 Views
  • 3 replies
  • 0 Likes

Resolved! Virus/win32.wgeneric.ajgdai id 341892366

Hi Team,

 

I have issue. One user connect to SSL VPN, and cannot ping one IP  192.168.1.11. Only one IP. after i checking at firewall, I found this users got blocking activity Threat Name virus/win32.wgeneric.ajgdai   id 341892366. But when this users

...

Resolved! VmFirewall on Xen?

Hello, good morning.

 

I have purchased the vm300 virtual firewall.

I have seen that no downloads are available for the XEN hypervisor at this time.

There are for vmware, kvm, citrix netscaler, etc.

I finally got the vmware virtual machine running on Xens

...

Resolved! Certification profile in global protect

Hello All,

 

I have configured the GP with authentication of credentials(Username and password) as well as the certificate profile.

When I connect the GP agent it is connected successfully.

My question is how we make sure GP is using a certificate profil

...

Resolved! DNS Proxy feature

Hey guys, I've read about DNS proxy and how it works. My question is, what are the benefits of using DNS proxy on the firewall?

 

This obviously gives the Palo insight into the DNS responses, but if the DNS traffic traverses the firewall it can snoop i

...

  • 23713 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels