General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

The PA-VM eval is crashing after minutes since reboot

Hello, I've created this discussion because I've downloaded PA-VM eval for ESXi [.ova] and tried to launch this using VMware workstation PRO [latest version]. I found on the LIVEcommunity some threads like so: https://live.paloaltonetworks.com/t5/general-topics/pa-vm-10-0-4-trial-gets-shutdown-after-a-minute/td-p/501973 however, once I followed...

Adam_D by L1 Bithead
  • 2824 Views
  • 6 replies
  • 0 Likes

Resolved! TCP fast open and Palo Alto

as far as I could test there is no way to make TCP fast open work through a Palo Alto fw (at least, since 9.1 which seemed to work. It tried 10.2 and 11.2 and all my tests fail there). Whenever a client sends a SYN packet with data, it is transmitted, no matter the zone protection profile, no matter whether the "TCP SYN with Data" option in the...

frigault by L1 Bithead
  • 5805 Views
  • 3 replies
  • 0 Likes

Several Medium Alerts from NGFW on : " Virus/Win32.WGeneric.eolzov(705362387)" This morning

Has anyone else seen any alerts for this Generic Threat ? It triggered on a few .LNK files that could not be located on the machines identified in the alert. This threat ID is new as of today, we have opened a support case, but was curious if anyone else was see'ing the same thing. False Positve ? Very little information on the web on these ...

TroianoF by L0 Member
  • 1219 Views
  • 2 replies
  • 0 Likes

syslog server connection failed

Hi, I have a PA VM setup and a syslog server to forwards the logs to. I have done all the configurations needed and syslogs server are receiving the logs. But on the system log there's still an error showing "syslog connection failed to server[x.x.x.x] Is this expected?

No upgrade but new applications

Hy everyOne, I've a PA-500software version 8.1.2 Application Version : 8536-7270 (03/02/22) Threat Version : 8536-7270 (03/02/22) Anti-Virus version : 4008-4519 (03/01/22) As you can see, no upgrade since March 2022 But if i make a backup and look into the XML file, i can see application : BING-AI-BASE for example or AZURE-AI Those applicat...

info by L0 Member
  • 2182 Views
  • 2 replies
  • 0 Likes

Not able to login into the firewall using admin account

Hi Folks, We are having PAN-OS:9.1.10 installed on our environment. We are able to login into the firewall using our admin accounts which are locally created on the firewall with authentication profile set as "None" Suddenly we are not able to login into the firewall and we got the below message even the account Authentication profile set to "No...

CobaltStrike.Gen Command and Control Traffic(18005) spyware

So I am fairly new to the PaloAlto brand. We installed 2 PA460's without Panorama and they replaced our Cisco ASAs. Loving what I have seen so far and it feels like I have more insight into what is going on with regards to the firewall. My issue is in recent months we have seen this CobaltStrike.Gen Command and Control Traffic(18005) spyware a...

Block Brave Borwser

Hello,I have noticed that some of our employees are using a brave browser and can easily open blocked websites like Facebook, crypto, games etc. what's the way to block brave browsers. Thanks:

application showing as incomplete + ipsec tunnel issue

Hi, I have an IPSec tunnel to a 3rd party, which we have some intermittent issues with. at the time that 3rd party lose its connection to us, under monitor> traffic I can still see traffic flowing but with application showing as incomplete. as I understand, incomplete could mean that source start a 3-way handshake but doesn't get a syn ack b...

AY_FASAR by L1 Bithead
  • 2197 Views
  • 3 replies
  • 0 Likes

Upgrade with High avaibility

Hi everyone, i've 2 PA-500 with no contract since 2022. Now i've to made change but the commit doesn't work because error duplicate application name "Bing-Ai-Base" i can make an upgrade but we didn't make that since march 2022. How can i make an upgrade on one of the two PaloAlto without impacting the other one (in case i've a upgrade issue, ...

info by L0 Member
  • 886 Views
  • 1 replies
  • 0 Likes

Resolved! Export/Import Named Configuration Snapshot

Hi everyone! Can someone confirm that the subject can only be done by "superuser" account? I can't find any documentation that says so. I'm wondering because "export device state" is visible for superuser account, when using a "device administrator" (dynamic role), "export device state" is not visible. Both Export and Import named configuratio...

RVizcarra by L4 Transporter
  • 7288 Views
  • 7 replies
  • 0 Likes

Resolved! Changing priority between eBGP and OSPF learned routes

I have an interesting problem that I haven't found a satisfying solution for. I have various remote sites connected via private circuit with OSPF, and then IPSec VPN with eBGP learned routes. The administrative distance of eBGP is 20, and the administrative distance of OSPF is 30. I believe these are the defaults. Right now, if there are two pa...

khsieh by L2 Linker
  • 16498 Views
  • 10 replies
  • 0 Likes
  • 24411 Posts
  • 125 Subscriptions
Top Solution Authors
Labels