General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 413 Views
  • 0 replies
  • 2 Likes

Resolved! AlienVault taxii miner versus prebuilt reputation data miner

AlientVault has the OTX with a taxii feed configuration which looks like it could be handy. However the miner for the alienvault reputation has a link which 404's. Does anyone have any idea if this overlaps?

 

Also the AlienVault taxii feed would req

...

chirss by L3 Networker
  • 20389 Views
  • 21 replies
  • 0 Likes

Allow techblog.netflix.com without allowing netflix-base?

Good day,

 

if you try to open http://techblog.netflix.com our PA currently recognize it as netflix-base.

Is there a way to declare it as normal web-browsing if they try to open the techblog page since we don´t want to allow netflix-base for our users?

 

...

TZwoll by L0 Member
  • 2791 Views
  • 1 replies
  • 0 Likes

Palo Alto - TCP Normalization

Hi !

 

We are migrating to Palo Alto from ASA Where ASA TCP normalization is enabled for option 28. 

 

How we can achive the same in Palo Alto ?

 

gpsriram by L1 Bithead
  • 7125 Views
  • 8 replies
  • 0 Likes

Global Protect pass OpenVPN traffic?

We have deployed GP full tunnel VPN across the enterprise. We have some departments using OpenVPN, 

My question is why can't users use OpenVPN without having to disable GP first. 

 

 

thanks,

URL Filtering Response Page

Hi All,

 

I have created a custom response page for a vsys but I need two of these within a VYS so they are served depending on the source IP address.

 

Example, if user comes from within 10.10.10.0/24 I want to serve a response page with policy details

...

a.jones by L3 Networker
  • 2056 Views
  • 2 replies
  • 0 Likes

Security Policy Actions- Vulnerability

Dear All,
 
Kindly help me understand below query - 
 
We would like to configure Security Policy Action "Block IP" for Critical, High and Medium level Vulnerability signatures for 3600 sec. As per understanding traffic from source-destination pair; Conf
...

Resolved! Global Protect Windows 10 issues

Hi folks.

 

I'm running into an annoying issue with some Windows 10 workstations and Global Protect.

 

Global protect will install, and run for an unspecified (and variable) time on a given workstation. Connected, working, no problems.

 

After some period

...

darren_g by L4 Transporter
  • 18824 Views
  • 2 replies
  • 0 Likes

Resolved! Implicit Applications with cotp/ms-rdp in security policies

Hello everyone,

 

Been testing some PA firewall functionality and noticed that ms-rdp has the implicit use of "cotp" defined, but the cotp application matches to a rule further down the policy list. When I review the logs, it looks like this

 

Am I misun

...

PAFWRDPCOTP.PNG
MathewRD by L0 Member
  • 6425 Views
  • 1 replies
  • 0 Likes

Up gradation of PANOS 8.0 to 8.1

We have PA-820 deployed in Active-Passive HA mode running PANOS 8.0. Today i received a notification that PANOS 8.0 will be End of Life on 31st Oct 2019. Hence I have to upgrade the PANOS of both firewalls, preemption is enabled on both firewall. Ple

...

Resolved! RADIUS MFA Enrollment Message

I have successfully deployed MFA for my Global Protect users using PingID. Using RADIUS and LDAP I am able to have a user challenged every time they want to fire up the Global Protect gateway. However, this functionality only happens when a user has

...

  • 23695 Posts
  • 110 Subscriptions
Top Solution Authors
Labels