General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! DOS profile for critical servers

Hi Guys, I want to create the DOS profile for critical servers. I read that I can use classified type so connection count toward only one IP address.My question is can I add multiple servers IPs in same DOS Rule or I need to create multiple DOS rules. Also, I might need to tune threshold base on servers so is it better to create new DOS rule?If ...

shafi021 by • L2 Linker
  • 4597 Views
  • 3 replies
  • 0 Likes

External BGP Static Route Advertisement, with Path Monitoring an inside net

I have an existing LAN with two data centers. The firewalls at each are not in a cluster, and have different internal/external connections and tunnels, so changing to active/active it not possible. They each have separate DMZ's right now.We need to build a new redundant DMZ.I've implemented static routes with next hop of none for my Public IP's ...

Have you heard of the Cyber Elite?

In case you missed it, the LIVEcommunity team has just introduced the LIVEcommunity Cyber Elite program. What is the Cyber Elite program you ask? This is a program that we have helped create to recognize the Expert members of the LIVEcommunity. We in the LIVEcommunity know that a community is only as good and strong as our members (and boy d...

pan_live-community_cyber-elite_v3.png
jdelio by • L7 Applicator
  • 6953 Views
  • 3 replies
  • 11 Likes

HL7 Traffic / Unknown-TCP traffic gets denied.

We are standing up some new PA firewalls and have been testing with some HL7 servers. Testing has been going well until recently where "unknown-tcp" traffic gets denied. It seems that it only happens when the transfer of a specific file/message is being transferred. I spoke with our the HL7 Interface/Server guy and he shared this bit with me....

rkoenig by • L3 Networker
  • 15396 Views
  • 11 replies
  • 0 Likes

Resolved! Public to Public RFC 1918 blocks

Hi, I am looking to block the RFC 1918 blocks coming from internet to our LAN zone. So, Policy will be Source zone: Public , IP: RFC1918 blocks, Destination zone: LAN, IP : any .Can you guys please confirm that creating this policy will fulfill my requirement? @OwenFuller can you please give your input? Thank you

shafi021 by • L2 Linker
  • 8252 Views
  • 2 replies
  • 0 Likes

Primary and Secondary SSL VPN global protect

One question that comes in my mind, can we use fallback URL or IP in Global Protect client? Like in Cisco AnyConnect, if the primary VPN Server or internet source is down then client connect with the secondary internet source automatically.

aneeqzia by • L0 Member
  • 4286 Views
  • 3 replies
  • 0 Likes

Resolved! x-forwarded-for header in traffic log on AWS VM

Hello, My FW is behind ALB, so I want to see original Src IP. I enabled "use x-forwarded-for header in user-id" setting and user-id on the zone.But there is no info on source user column in traffic log. I can see the information in url filtering logs using, but I want to see that in traffic log too.It seems to be possible when I look into manual...

yhlee1 by • L2 Linker
  • 7682 Views
  • 5 replies
  • 0 Likes

Qos statistics tab does not show class for multicast traffic

I have a customer case where they have enabled QoS for layer 2 interface. There is a Qos rule in place for classifying multicast traffic as class 3.multicast traffic from zone LAN is hitting the right QoS policy and from the session details, I have verified the QoS class as class 3 which is what suppose to be. However, When I check QoS statistic...

snimshad by • L1 Bithead
  • 2413 Views
  • 1 replies
  • 0 Likes

Assigning a template to a specific vsys within a Template Stack?

Most of our FWs are multi-vsys. Our stacks basically consist of one template - the entire FW config. Now we are trying to create more global templates that we can apply to multiple Template Stacks. But when creating a new template configs, the config sections only gives you the option of assigning it to "Location: None" or "Location: vsys1" ...

rolinger by • L2 Linker
  • 4759 Views
  • 1 replies
  • 0 Likes

Resolved! Empty EDL PA220 PANOS 10.0

HelloIm doing some tests on PA-220 test unit.Some story - im using windows 10 with installed debian on WSL.I've installed apache2 and doing some IP pulls from internet and then hosting it on:192.168.7.131/steamip2.htmlI can access this from my internet browser and i see list of IPs.After adding edl to palo alto it sais that source is avaible but...

wjt82918 by • L1 Bithead
  • 15261 Views
  • 7 replies
  • 0 Likes

Resolved! New Install Checklist

Hello -Has anyone seen or created, that they'd like to share, just a general checklist of information to collect and steps to do a new install?

Resolved! Problem URL-Filter onedrive urls

Hello everybody, I use url-list from urlhaus. If I test some entries, I got a problem with onedrive-urls like this: onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fiThis url should be blocked by urlfilter on the firewall. But it was not blocked. I can download the file. Also I can not se...

  • 24456 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels