General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 928 Views
  • 1 replies
  • 8 Likes

Resolved! troubleshooting SSL decryption

We've been using SSL decryption for a while now.

Where for the most websites, this is not an issue, once in a while a user complains that certain https website doesn't load at all. Browser just keeps loading indefinitely.

We can't find a reason in the

...

dieter_b by L4 Transporter
  • 10417 Views
  • 7 replies
  • 0 Likes

Minemeld - New Install - Advice

Hi Mindmeld Community

 

I wonder if you could kindly offer some 1st steps advice ?

 

Can anyone offer any tips and quick hits I can setup to show Managment it working, Id like to show them that the threat intel we can pull down is actually being used

...

DewarD by L0 Member
  • 2798 Views
  • 1 replies
  • 0 Likes

Resolved! PAN-OS 9.0 -go live?

Hiho,

 

has anyone 9.0 already on production units?

I´d like to have your feedback regarding the release.

Wait for first hotfixes / minor patches or go productive?

 

Greetings

FQDN refresh failed

We have 4 PaloAlto clusters and a FQDN refresh works on 3 of the clusters but not the 4th. All objects are shared on the 4 clusters. I have tried:

 

Scheduled refresh of FQDN fails

Manual refresh of FQDN fails

Changed the FQDN refresh time.

I can ping the

...

Resolved! The Rule is allowed but hit policy-deny?

Hi,

Recentely the firewall upgraded from 6.1.5 to 8.1.6 but after upgrading there is something strange, there is a allowed rule but in monitor tab it hit deny, i tried to move it to top but still the same issue ( Session End Reason: policy-deny ).

 

Any

...

DPWorld by L1 Bithead
  • 10166 Views
  • 4 replies
  • 0 Likes

Resolved! ssl decrypt exempt and C2C

 

we need to do do ssl decrypt exempt for number of domains.
this we are doing as per vendor requirement so that application can run without ssl decrypt 

 

1>Need to know if traffic is not decrypted and end user pc gets infected
can c2c in url filtering p

...

MP18 by Cyber Elite
  • 3458 Views
  • 5 replies
  • 0 Likes

Default superuser CLI access via TACACS authentication

Have auth profile setup to use a TACACS server.  VSA is passing "superuser" as the admin profile, but it is not giving me access to the CLI as superuser, only GUI.  I know I could create another admin profile and grant access that way, but it locks o

...

cdwing by L1 Bithead
  • 2603 Views
  • 3 replies
  • 0 Likes

Resolved! Paloalto 6.1.15 cannot download dynamic updates

The Paloalto firewall stop to download the dynamic updates since 28 Jan for Antivirus and 6 Feb for Applications, is that beacuse of the PAN-OS, should i upgrade 8.1.6.

 

Appreciate your help

 

 

Thanks

 

 

DPWorld by L1 Bithead
  • 2772 Views
  • 2 replies
  • 0 Likes

2 ssl inbound certs on single IP?

I have a public facing server with 2 apache instances running on it. 
www.example.com and www.examplepartner.com
I have a wildcard cert-key pair(*.example.com) imported onto firewall and it is decrypting traffic to example.com but I am unable to decryp

...

Resolved! PAN-OS Version Numbering

I saw a strange PAN-OS version on the support site software updates and wanted to know what this version is. What does the "h2" designation mean?

 

8.1.6-h2

 

 

New to Palo Alto from Juniper SSG

I was wondering if someone could enlighten me on how to replicate the Mapped IP functionality from Juniper SSG to Palo Alto.

We have a number of services on our current Juniper SSG.  The way we firewall these services is using MIP's on the Untrust Zon

...

Resolved! PA support SVTI

Hi @reaper 

 

Do palo alto support SVTI like Cisco.


SVTI configurations can be used for site-to-site connectivity in which a tunnel provides always-on access between two sites. The advantage of using SVTIs as opposed to crypto map configurations is that

...

Resolved! Mac OSX HIP check based on processes

I've recently turned on HIP profiles for our windows users, checking to see if our patch management and AV is running by looking at processes.  I need to do the same thing for some of our Mac users, but I'm striking out.  What is the best way to veri

...

Antivirus/Anti-Spyware Response Page not working

Hey Community!

 

I noticed that our Firewall (PA-3020, PAN-OS 7.1.6) does not serve an Antivirus/Anti-Spyware block page.

When I use http://www.eicar.org/85-0-Download.html to test it, I can see that it is blocked.

ThreatLog shows action "reset-both" but

...

Resolved! 8.1.5 BGP question

Hi

 

I have some inserted routes into my BGP for redistribution.

firstly I have a NAT address associated with a loopback. I had a redis rule saying connected and added in the interface.

 

That didn't add the ip address into the BGP tables, tried just the

...

Top Solution Authors
Top Liked Authors