General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Web-Browsing default port application

Hey , 

 

i just wondered why in the era that all web traffic is moving forward beeing encrypted and browsers like chrome will soon mark websites that uses HTTP protocol as "unsage" paloalto "web-browsing" application still uses in it's default ports on

...

minow by L4 Transporter
  • 13477 Views
  • 5 replies
  • 0 Likes

Re:Minemeld Miner Config

Hi guys,

How can we creat a prototype miner in the MInemeld hosted by autofocus, is there any tech document with regards to how to customize/config a prototype for Miner.

Thanks 

Sanssj by L2 Linker
  • 2170 Views
  • 1 replies
  • 0 Likes

Resolved! Decryption servers same ip

Hi,

 

We need to decrypt traffic (SSL Inbound Inspection) for a server which is running 3 URL. This server has 3 certificates, one per application.

 

So we would like to decrypt traffic for this 3 applications but in decrypt policy we only configure usin

...

BigPalo by L4 Transporter
  • 1335 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrading a stand alone PA-Firewall 3020 to a HA-Cluster

Hello everybody,

 

is there any article or best practice document which discribes the configuration of a Palo Alto 3020 Firewall HA-Cluster active/passive while there is already a working stand alone PA 3020 Firewall.

 

Is it the same way I configure a H

...

Mvdohe by L1 Bithead
  • 2700 Views
  • 5 replies
  • 0 Likes

Re: Vwire and L3 Deployment Decryption

Hi,
I would like to know the way it operates in the backend how palo alto does the SSL decryption in Vwire mode . As in a L3 deployment the connection will terminate on the firewall and firewall acts like a MITM and does the SSL Proxying. How is the c

...

Sanssj by L2 Linker
  • 1367 Views
  • 1 replies
  • 0 Likes

SSL Decryption Exclude List - correct syntax?

What is the correct syntax to exclude a whole domain, including subdomains and pages from SSL decryption?

 

Say exclude all URL's from "test.com", would this suffice:

 

*.work.com

 

or would i need to include a list like:

 

*.work.com

*.work.com/*

*.www.work.c

...

welly_59 by L3 Networker
  • 1066 Views
  • 1 replies
  • 0 Likes

IPsec VPN throughput

configured site to site ipsec vpn between PA 820(head offc)XG firewall (branch offc)successfully. in the head offc we have 100 mbps download , 25 mbps upload speed and brach we have 100 mbps download and 50mbps upload speed. the vpn performance is ve

...

GP pre-logon for IOS devices

Hello community,

 

I was wondering if is possible to make Globalprotect for IOS or Android devices to work properly with connect methods other than on-demand, for example pre-logon. Did anyone accomplish this connection method??

 

 

Thanks and Regards,

Mar

...

Carracido by L3 Networker
  • 1572 Views
  • 1 replies
  • 0 Likes

Palo Alto main and sub urls are different category

I have requested palo alto uel re categorzation team for re categorizing the main url of a site for ex: 

abc dot com.

It has re categorized correctlly by Palo as requested. However I am getting  blocks when I access abc dot com /subdomain

When i try re

...

Best practice for Palo Alto Uplink

We are looking to deploy our new boxes (PA-3220) in HA in the next few weeks. We are trying to go with best practice methods. 

 

Currently, we have an Layer 2 ae interface that has multiple subinterfaces. Each subinterface is tagged with a Layer 3 SVI.

...

Global Protect DHCP config

With our firewall for VPN and DHCP all we configure is under GP gateway/agent/client settings we have an IPpool and address route.  We need to add DHCP option 160 and I don't believe that it can be done on the Palo.  We have never setup a  DHCP relay

...

Resolved! Register new management IP address of PA to Panorama

My PA is already connected to the Panorama.

I had to change the Management IP address. 

The PA lost connection to the Panorama.

The Panorama shows the PA with old IP and status Disconnected.

Is there a way to update the IP of the PA on the Panorama, or f

...