General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

url filtering with Alert category

Hi, I have configured the URLs to allow through the firewall with an alert category. The firewall is allowing the URL but user get the "warning: Potential Security Risk Ahead" page with Go Back (recommended) and Advanced option. Is there any technique to allow user directly go onto the URL page instead go to advanced and continue to the websit...

image006.jpg
ChiragP by L2 Linker
  • 10477 Views
  • 7 replies
  • 0 Likes

Export logs from PA7050 to Window Log Server

Hi Guys, Any possibility we can export daily logs from PA7050 to external windows log server through SCP or FTP? Been told there is a limitation for PA7050 to do so because the log database is too large for export or import. Any possible can do it by scripting? Thank you.

Natting to ip address which is not binded to any interface

Hello Everyone,I want to nat traffic going from dmz zone to wan zone. I want to nat ip (172.16.16.16&172.16.17.17-dmz zone) to use nat ip 200.0.0.1 which is not configured to any interface. I am unable to perform this. Please find below snap.1)Interface IP addresses.2)NAT rule3)Security Policy 4)Topology On R2 when i debug ip address i can s...

nitesharbale_0-1583322314964.png
nitesharbale_1-1583322411216.png
nitesharbale_2-1583322611401.png
nitesharbale_0-1583322960961.png

Resolved! Response page variables display as $(url.host) and $(x-exception-category)

Below is the response page. This is being served correctly when the webpage is blocked due to URL category filter.The variables for <url/> and <category/> don't seem to get replaced correctly.PanOS 8.1.10.Webpage text displays as "The requested URL host is: $(url.host) Which has been categorized as: $(x-exception-category)" <html...

Log traffic on Panorama is less than firewall device

Hi everyone,iam using the monitor > traffic on panorama and saw the period logs more smaller than the firewall device, in panorama we have log until 02/14/2020, while in firewall device the log starts on 01/31/2020, i used the command show system logdb-quota, but i cant saw the quota from panorama, is there a way to verify this diference? byb...

bmacedo by L0 Member
  • 3072 Views
  • 1 replies
  • 0 Likes

Resolved! SFP Compatibility for PA-820

Hi All, I would like to know please a compatible Brand of SFP ports 1Gbps MMF for Firewall Palo Alto PA-820, for this FIrewall the SFP model in Palo Alto is: PAN-SFP-SX . I have been told that the brand Finisar model: Ftlf8519p3bnl is compatible with that. I would like to make sure about that please since I am in Bolivia and it is really hard...

PBF rule with src zone 'any'

Does anyone if it is/should be possible to configure a PBF rule with src zone any?The inline help says "To choose source zones (default is any), click Add and select from the drop-down." but 'any' is not an option when I actually try to create the rule in Panorama and I'm forced to choose a zone to be able to save the rule.

pkaren by L1 Bithead
  • 2781 Views
  • 2 replies
  • 0 Likes

Measure CPS practically

Hi Guys,We have PAN VM 300. To implement Zone Protection, we want to measure CPS. Now we dont have Panorama and dont do firewall monitoring with any tool.Now the admin guide suggests that:Use third-party tools such as Wireshark or NetFlow to collect and analyze network traffic.Use scripts to automate CPS information collection and continuous mon...

Resolved! Is PAN-OS 9.0 recommended version for PA-3020 device?

Hi, Is PAN-OS 9.0 recommended version for PA-3020 device? I can see the OS 9.0 is supported to PA-3020 but not sure whether is recommended version for PA-3020? Also, I have gone through the known issues about OS 9.0 and looks like no major impact that could affect on to the network. However, I would like to stick with a recommended version so pl...

ChiragP by L2 Linker
  • 5781 Views
  • 3 replies
  • 0 Likes

Panorama on ESXi resources

Hello community, we would like to build virtual Panorama and log collectors as virtual machines on ESXi.Does anybody know, if resources like CPU and memory must be dedicated to these machines only or can they be shared?I cannot find it in any documentation. Thank youRegardsRoman

Bandwidth limitation per policy

Hello All, I have filled the local database with users because we do not have an Active Directory, i create a captive portal to enforce the users to do authentication. in the polices i have grouped the users depends on what they should go through network. I need to know if there is any way to limit the bandwidth for wan connections depends on th...

diferente Version PAN 3220

HiThe new PA3220 device (FW2) has PANOS version 9 installed, but the firewall (FW1) that is operative is on PANOS 8.1.3.What are the steps to update the FW1 to the actual version of PANOS?

Global Protect Authentication Profile

Hi I have setup Global protect and I want to use it with LDAP Authentication profile. It works fine however when in the auth profile I add a specific AD group so only users in the group allow to connect to VPN it doesn't work. Even sometime with specific group added others users can connect to the VPN or it doesn't allow anyone to connect. Alrea...

umar00o by L2 Linker
  • 2825 Views
  • 2 replies
  • 0 Likes

Resolved! Azure Active Directory IP ranges

Hi all, I'm trying to use Minemeld to create an EDL that includes only the IP address ranges used by Azure AD. I've tried a few things, but can't seem to get it to work. My current setup is as follows Miner = cloudIPsWithServiceTags Processor = based on stdlib_aggregatorIPv4Generic but using the following config infilters:- actions: ...

dpurton by L0 Member
  • 15184 Views
  • 4 replies
  • 0 Likes

Wildfire Public Cloud - email

We’ve recently upgraded our PAN from 8.0.4 to the latest version (8.1.13) successfully. Now the issue is that we’ve been getting an email stating that “registering Wildfire Public Cloud has been successfully” every 20 minutes. Is there a way to make this particular email to stop? Subject: INV-FW1 - SYSTEM ALERT : medium : Successfully registered...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels