General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1694 Views
  • 0 replies
  • 0 Likes

Resolved! DoS threshold per zone

Hi All,

 

What additional tool can l use to get CPS/SPS intonation hitting specific zone?

I found this KB with three wonderful MIBs:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-c

...

myky by L3 Networker
  • 4407 Views
  • 3 replies
  • 0 Likes

Resolved! PA license to download images

Hello

What type of license do I need to download images ?

Firewall has access to updates.paloaltonetworks.com but when I click "Check now" nothing happen.

Trial license will be ok ?

 

Thank you

Konrad

polak71 by L1 Bithead
  • 4093 Views
  • 4 replies
  • 0 Likes

PA 5050 & 5060 replacement with PA 5250

Firewall upgrade/replacement

Dear All,

 

Can anyone please advise on any specific points to be taken care for a hardware replacements for a pair of firewall 5060 fully managed by Panorama & to be replaced with 5250. 

To me a high level plan looks like.

1.

...

Gchander by L1 Bithead
  • 3921 Views
  • 1 replies
  • 0 Likes

Resolved! HA HSCI 3220

I have a pair of 3220s I'm configuring in HA active/passive. We connected the HSCI ports and got a green light on the ports and showing green/up on the HA dashboard widget. They are direct-connected and configured as Ethernet. Do I need to set an IP

...

Traffic pattern of threat ID 38643

Wavelink Emulation License Server HTTP Header Processing Heap Buffer Overflow Vulnerability' generated by PAN NGFW detected on host 10.10.10.1. " Vulnerability Exploit Detection (hostname:8081/)"

We have customer asking what is the traffic pattern tha

...

Resolved! PanOS CLI show tags?

I can tag a rule via CLI, but how can I ask Panorama to show me rules tagged with tag-name?

 

set device-group DG-Name security rules "Existing-rule-name" tag tag-name

BoDollis by L1 Bithead
  • 4705 Views
  • 1 replies
  • 0 Likes

Whitelisting messenger-app

Hi guys,

 

Goal: Whitelisting messenger app in mobiles but deny facebook

Do you have any problems in whitelisting messenger app in a mobile? It seems creating a policy and allowing facebook-chat is not working.

But if i included facebook-base it will wor

...

RemusDV by L1 Bithead
  • 2971 Views
  • 2 replies
  • 0 Likes

Useless PBF warning

Hi All,

 

That's not an issue.. I just want to share with you this thought

 

Starting from the fact that the egress interface is NOT a matching criteria.. But I have to configure around 80 VPN tunnel (with their own backup tunnel using pbf option "disabl

...

PBF_warning.JPG
Warning_Rule.JPG

Block traceroute

Hi all,

is there a way to block IP source if I match traceroute App-ID? Maybe with a custom vulnerability?

s_quasar by L3 Networker
  • 7346 Views
  • 7 replies
  • 0 Likes

FreeIPA LDAP group mapping

UPDATED:

The LDAP package FreeIPA uses , 389-ds-base, had some security vulunerabilities and has been updated. This update has caused the PA to fail checking users within groups. Here's is the latest configuration that works with 389-ds-base (1.3.8.4-

...

FreeIPACapture1 (1).GIF
FreeIPACapture2 (1).GIF

can't login to web console

I have just instaled MM on Ubunto 16.04. Using these instructions:

Howto on Ubuntu 16.04

$ sudo apt-get update $ sudo apt-get upgrade $ sudo apt-get install -y gcc git python-minimal python2.7-dev libffi-dev libssl-dev make $ wget https://bootstrap.p...

Mattk by L2 Linker
  • 11894 Views
  • 8 replies
  • 1 Likes
  • 24216 Posts
  • 117 Subscriptions
Top Liked Authors
Labels