General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Question on getting started with Reconnaissance Protection thresholds

I know the question about how to set Reconnaissance Protection thresholds has been asked dozens of times. The answer is always "it depends on your environment and situation". I understand that there can't be a one-size fits all best practice. It seems as though a trial-and-error approach is how you should dial in the thresholds and intervals.B...

ready only access to Logs

Hello - Will enabling any of the logs like traffic, url etc in the web UI in admin role profile give more than read-only access to the users with the profile? Asking because I don't see read-only option, just enable and disable. Thanks - Jisha

JJoseph by L1 Bithead
  • 2796 Views
  • 2 replies
  • 0 Likes

Policies with any zone in source and destination

While migrating from checkpoint to Palo Alto after defining zones and interface.Can I simply use any in source and destination zone and create policies with specific objects in source/destination address.Will it work, for replicating same policies while migrating from checkpoint to Palo Alto.

Alarm Log Forwarding

Instead of seeing alarms when I login to the web GUI, how can I get alarms forwarded? I'd like to send to SysLogs and also receive via email.

Palo URL Categorisation process

We have been attempting to use URL Filtering to block access to web based email using the Palo Alto URL Category web-based-email.We have found however that there are many web based email services that are not included in this category, including one of Australia's Largest ISP's telstra. The url for this service is email.telstra.com. I though i...

DaMonk by L0 Member
  • 3555 Views
  • 2 replies
  • 0 Likes

Resolved! UUID and HA - dashboard running config not sync'd with peer

We have updated an PA-220 HA pair to 9.0.7 and as expected see Policy Rule UUIDs. We also manage a separate population of FWs by Panaorama 9.07. From the release notes for HA deployments: policy rules sent by Panorama with apply to both HA member firewalls so they have the same UUIDpolicy rules applied not applied by Panorama with have different...

Carbon Black Threat Feed

Hi, I noticed in the code that if you use the v=carbonblack parameter on a feed node it spits out a Carbon Black Response formatted feed which works to the point you can load it into Carbon Black Response (ie CB accepts it and it appears with the Minemeld logo etc). However only one of my feeds shows any indicators (I have a Domain, IPv4 and URL...

mpg300 by L0 Member
  • 3013 Views
  • 1 replies
  • 0 Likes

Resolved! VLAN Palo Alto

Hi, I am fairly new to this firewall PA-220R. I have a workstation that has 5 NIC's. One is on a 192.168.100.0/24 range and the other is on a 192.168.130.0/24 range. The 100.0 range can reach the firewall. I have a device plugged into port 4 of the firewall with an IP of 192.168.130.100. How can I setup a route or access the device in the 192.16...

Resolved! DSCP TAGING

Hi could you confirm me, if the tagging DSCP is not flushed via the Palo Alto.I need to use an avaya VOIP solution and a dscp tag 46 is added to the packet.thank's

Gregoux by L4 Transporter
  • 9258 Views
  • 4 replies
  • 0 Likes

Global protect missing routes in clients

Hi, We are having a strange GP issue. We have two users in the same AD group and same configuration. userA: when this user connects to GP, everything is working fine, all the GP access routes are in his route table.userB: when this user connects to GP, not all the access routes are being imported in his routing table. We have tried both users in...

BigPalo by L4 Transporter
  • 5657 Views
  • 3 replies
  • 0 Likes

Resolved! What is a Master Device in Device Groups?

What role does a Master Device in a Device Group play?Is there special communication with the Master Device, as a dependency? If the Master Device goes down, is there a re-negotiation?Is this Master Device affected with the standup of HA?

erantanen by Not applicable
  • 14227 Views
  • 3 replies
  • 1 Likes

Recaptcha in websites work intermittently - Palo Alto

For all the websites, the recpatcha seems to give an error but works when we keep trying.We have tried different browsers and machines and seems to be same issue.We isolated bypassing palo alto and seems to work correctly. Can this be a issue related to Palo alto? Below are the website that they use for the recaptchahttp://patrickhlauke.github.i...

recaptcha.JPG
  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels