General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Check Point R77 firewal security rules +400 rules policy migration

hello team We have to migrate a Checkpoint R77 policies firewal security rules +400 rules policy migration, however we can't see those policies when we export to the expedition tool, we know that in R80 version you can use the CLI on the CKpoint to export in pieces those big amount of rules from 0-400 and from 400-800 and so.we try to use the sa...

What's new in MineMeld 0.9.32

Release Date: 2017-02-06 Changes to the default behavior To avoid data corruption, MineMeld engine now periodically checks availble disk space. If the available disk space falls below the limit of 10MB per configured node, the engine shuts down and refuses to start. If after the update the engine does not start you can try to free disk space ...

mm-wheel-extension.gif
lmori by L7 Applicator
  • 9381 Views
  • 4 replies
  • 2 Likes

Sync Between Active Directory and User-ID

Hi there, I have security policy allowed for particular group A. when i add/remove member in group A it doesnt sync with the security policy. Is there a way to sync between active directory and User-ID/ Security policy? Thanks in advance.Pratik

Resolved! Error at task npm install on RHEL

Hi all,I'm installing minemeld-ansible on Redhat 7.When i run this command:sudo ansible-playbook -K -i 127.0.0.1, local.ymlI got this error:TASK [minemeld : npm install] *********************************************************************************************************************************************************************************...

Panorama: Bulk Edit Security Policy to update Security Profile Group

Hi, I have about 900 rules spread across 2 different groups within Panorama. I would like to apply a shared Security Profile Group to all these rules where there action is Allow. I have done some searching around but have not found any answers, however I apologise up front if I have missed a post (or article) where this has already been answere...

Resolved! Palo Alto VM, Layer 2 bridge (transparent), 802.11q sub interface mac flapping on cisco switch

Hello everyone,I have an existing palo alto PA-3550 which we are migrating over to vmware, virtualized version (VM-300), onsite, no cloud. On the appliance we have two sets of layer 2 interfaces bridged together. One set is basically a transparent firewall, the other is just marking qos traffic. Since this device has 20 or so 1 gb ports, each...

Software packet buffer depletion

I am working with a client who is experiencing very high CPU utilization on the data plane and his packet buffers do not release. He is running 8.1.7 in a lab setting with no traffic being generated to the firewall. He has VM is setup with 6.5GB ram and 2 cores, 1 for management and 1 for data plane, and 60GB hard drive with VM-100 license. ...

SSL decryption in forwarding proxy and a Web proxy after paloalto firewall

Hi all,i have a PA firewall used for internet navigation and a transparent proxy for Web navigation.I have enabled ssl decryption for a specific URL category that i have set in url profile in block-continue.If i set my PDL browser with the proxy i didn't recive the response page and the connection goes in timeout. If i remove proxy from pdl it w...

Does PAN-DB categorization apply to subdomains?

If I register a domain in PAN-DB for categorization (https://urlfiltering.paloaltonetworks.com/), do all subdomains automatically fall under the parent category? For example, if I register "mywebsite.net" for categorization, will the assigned category apply to "info.mywebsite.net" as well? Thanks! Allen

Next Gen Firewall Public Wifi Browser Warning Issue

We have a policy for public wifi subnet set toACTION to NO DECRYPT,Set TYPE=ssl-forward-proxy, DECRYPTION PROFILE = NONE When any public device (i.e laptop) try to open a HTTPS website that prohibited by our organization URL policy.For example HTTPS’s porn sites. The browser will come up with the Warning pageFirst page, IE = Website’s security c...

Resolved! User-ID Agents

Hi All, I am migrating Palo Altos to a new Palo Alto. I have a question raised by the end customer. They user User-ID agents currently on their servers. Can they use the same Agents on the new Palo Alto - off the top of my head I am not sure? Given that the new install is a later version of PAN-OS, on a VSYS, new IP ranges internally (and althou...

a.jones by L3 Networker
  • 2693 Views
  • 1 replies
  • 0 Likes

Import/export device state

Upgrading a firewall from a single fw to an HA pair. My plan is to do a device export of the current active firewall then import that device state to the two new firewalls then setup HA. Some of the config pieces are from PANORAMA. Any issues with importing the device state if the fw is not managed by PANORAMA? Or can I add it later? Thanks!

  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels