General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4254 Views
  • 0 replies
  • 0 Likes

Rulebase Organization and Flow

I hate having OCD sometimes because its things like this I struggle with. How are others organizing their rules? Are you grouping them by source IP? Zone? Common Apps? I have "business units" so each business unit has rules. So After each group of business unit rules there needs to be a deny for that "group" So I was starting to organize by sour...

Resolved! On-Site Spare using

Good day, dear colleagues! We bought two PA-220 and two PA-220 on-site spares. Total we have 4 firewalls - 2 main and 2 on-site spare. But we installed 1 main device and 1 spare. Could this be a problem in the future? Or from the vendor's side these are 4 identical devices? All firewalls was pre-activated. Thank you for a help!

Resolved! MineMeld - Unable to locate package minemeld

Hey, I just installed Ubuntu 16.04 to set up MineMeld according to these instructions:https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-Install-MineMeld-on-Ubuntu-Server-16-04/ta-p/253336 Once running sudo apt install -o Dpkg::Options::="--force-overwrite" -y minemeldI get the following Error: E: Unable to locate package minemeldWh...

husetech by L2 Linker
  • 4497 Views
  • 2 replies
  • 0 Likes

Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Stack

I was looking for ways to provide 'at-a-glance' visualisation of PANW firewall health, including traffic, threat, system & config logs. The stock capabilities, including ACC, are decent but somewhat lacking in providing NOC-style dashboards. Inspired by other visualisation solutions I've seen around, such as the Splunk App & Graylog dash...

Resolved! Application 'github-base' and SSH

Hi all, Can someone please explain why the "github-base" application depends on SSH? We are running into a number of problems with web sites that are hosted on Github. Users want to get to these sites for legitimate reasons. IT people have also wanted to download Github projects. I don't have a problem with approving github-base, but we h...

RSKadish by L2 Linker
  • 18374 Views
  • 7 replies
  • 0 Likes

Maximum VPN Tunnels on a PA-820

Hello,Does anyone know what the maximum VPN tunnels are on the new PA-820 firewalls? The current doc out there does not include the new 220, 800, 3200, or 5200 series firewalls. Thanks.

Resolved! Global Protect with Multiple Portals - Transparent Configuration

Have a client who is rolling out a global GP deployment and looking for redundancy. We have setup portals and gateways on all of their firewalls and everything is working great from being able to connet to the right gateway to being able to choose different gateways. We have now started discussing HA for the portal FQDN itself as this seems to ...

Error process CSV files published as Microsoft Articles

Hi, I'm using pluging "ms-article-miner" from Xavier Homs to miner ip Microsoft space. https://github.com/xhoms/minemeld-msarticle https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Miner-to-collect-Microsoft-Public-IP-space/td-p/186591 Firstly it was working but now it does not show anything. It shows in miner and processor but not...

Threat email alert throttling

We're setup to email threat alerts, and are getting an email for every alert generated.Is there a way to throuttle the emails? Particularly for a single threat that is blocked, we don't need 60 emails/min for all the blocks. It would suffice for the first 10 per 10 min interval. When you get the first 10 emails, you know someone is hammering you...

CHKlomp by L2 Linker
  • 3382 Views
  • 2 replies
  • 0 Likes

How to filter O365 API feed?

I would like to filter for indicators with the category "allow" or "optimize" only. How would you define the filter for that? I cannot find that much information regarding filtering using a processor. I hope my steps are correct? create a new prototype of the IPv4Generic processor create infilters for that infilters: - actions: - accept ...

Resolved! Office 365 MineMeld Miner Will Need Updating

Microsoft has announced a change to their Office 365 address and url documentation that I believe will need to be taken into account on the O365 miner in MM. https://myitforum.com/microsoft-phasing-out-office-365-urls-and-ip-address-ranges-resource-on-october-2-2018/ Basically, they are phasing out the old documentation page, which I believe...

  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels