General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 646 Views
  • 0 replies
  • 0 Likes

Global protect on MAC, with proxy settings

In our company, we do not allow split tunneling and access to Internet(while on VPN) happens via only proxy. We are using on-demand mode. 

 

Once MAC users connect to GP,proxy settings apply. Only browser which works in this setup is Mozilla Firefox. 

I

...

SuryaR by L3 Networker
  • 7361 Views
  • 5 replies
  • 1 Likes

Resolved! weird file in device with TRAPS

Hello,

We have devices with TRAPS and we has found files with strange names as !!!!!!!!* and zzzzz*.

I we try to modify or execute we get anti-ransomware alert.

this files are normal? could be a bug? 

 

 

Capture.JPG
Marivi by L2 Linker
  • 9731 Views
  • 7 replies
  • 0 Likes

PA-220 DHCP with reservations

I have this weird issue where if my wireless clients lose connectivity to my meraki AP and then have to rejoin after the AP reboots, the DHCP server on the PA-220 stops handing out DNS servers that are inherited from the untrust port. I have all clie

...

Suspicious DNS Domain addition

Hello, is there a way to report suspicious DNS domains to Palo Alto for inclusion on the Palo Alto suspicious DNS query list?  we have a domain which various threat intelligence sources report as suspect/risky but it does not appear in the Palo Alto

...

new CA Sectigo(formerly Comodo) not trusted

Hello. 

We are having a minor issues on one of our customer firewalls performing decryption. 

it seems certain sites. that have a certificate issued by sectigo. 
chain

root: Sectigo

intermediate: Sectigo RSA Domain Validation Secure Server CA

site certific

...

SSL Certificate for Global Connect

Hi All,

 

I have a users who plan to connect their phones (To use a soft phone app for the PABX) and laptops to the internal network from outside, i have setup the global connect gateway and portal and tried to use self signed cert but it is not workin

...

Resolved! CLI URL filter, change Site Access?

I am trying to determine how to change the Site Access of the new URL categories (cryptocurrency and grayware).  By default, they are Allow, and I want them to be Alert.  I can do this via CLI w/ the command from config mode below. 

set shared profile

...

BoDollis by L1 Bithead
  • 3215 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrade to PANOS 7.1

I'm looking at getting a Palo Alto used.  A lot of the units are pan os 4, 5 or 6.  For a PA-500, for example, can I get a 5.x OS and upgrade it to 7.1?  Does this require a support contract to upgrade it?

RustyPA by L1 Bithead
  • 9817 Views
  • 7 replies
  • 0 Likes

Resolved! The sporadic syslog sender

I recently adding a new syslog destination at this new to me site and noticed something I hadn't seen before. That is that the sending of syslog data according to PAN Monitoring is send sporadically and in big bursts. For example when I added the new

...

palomed by L3 Networker
  • 4471 Views
  • 4 replies
  • 0 Likes

Dynamic updates constantly failed

Hi there

 

Is there any known issue with Dynamic Updates? Our firewall can't get updates in the last 4 hours. The last update we got was around 4pm (GMT+10). The traffic log is showing incomplete. 'show url-cloud status' shows Cloud connection: not con

...

myocella by L0 Member
  • 3536 Views
  • 4 replies
  • 0 Likes

Resolved! financial-services is exempt from decryption still decrypt error

PA running 8.1.9  we have rule from any source any zone do not decrypt financial-services category.

CLI  test 

 

test decryption-policy-match source 10.x.x.x  destination 23.249.200.33 category financial-services

Matched rule: 'No_Decrypt' action: no-dec

...

MP18 by Cyber Elite
  • 4657 Views
  • 7 replies
  • 0 Likes

Identify syslog type for User-ID parse

I'm in the process of implementing User-ID and want to parse syslog logs. the predefined parse profile don't appear to be a match, as I'm looking to pull syslog from my domain controller. However, my Active Directory team can't provide me with a samp

...

  • 23945 Posts
  • 113 Subscriptions
Top Liked Authors
Labels