General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Multi hop DHCP relay

Hi

 

So I want to get my VOIP phones to dhcp to the vPBX.

 

Phone are on a vlan in the office vPBX is in the DC

 

so vlan for phone -> PA -> vlan -> arista switch -> vlan -> PA (clustered A/A) -> vlan -> vPBX

 

So I can setup DHCP relay on the first PA and I

...

Exclude threat from alerting on IPS

How can I effectivly remove alerts for specific threats on our IPS tap?

 

There are some that we are aware are actualy trivial and can't be fixed but cause a lot of alerts.

 

Is simply adding it as an Exception on the Vulnerability Profile enough?  I tri

...

Allow all shorteners

Good morning,

 

Is it possible to allow all shorteners (bit.ly, goo.gl...). But only shorteners.

 

There isnt any category for this..

 

Regards.

MineMeld not loading after installation

After succesfol installation of MineMeld in a Debian9, by using this article: https://github.com/PaloAltoNetworks/minemeld-ansible

 

When accessing to HTTPS://IP_Address it stays forever loading (showing the loading "M"). I can't see any error in the

...

MarcelST by L3 Networker
  • 1814 Views
  • 1 replies
  • 0 Likes

Virus/spware download blocked but no threat logs

Hi

 

When users are accessing internal portal then they are getting "Virus/spware  download blocked" on browser with file name (althrough they are not accessing this file) but there is no virus/spyware logs in threat monitor tab.

 

Any pointers how to fi

...

nbar

Hi,

What is the NBAR equivalents in pa- qos or how does it works in PA

 

Thanks

simsim by L4 Transporter
  • 2250 Views
  • 8 replies
  • 0 Likes

Resolved! After Factory Reset Cannot connect to management server

Hi,

after i make a Factory Reset via Maintenance Mode with this HowTo -> https://live.paloaltonetworks.com/t5/Management-Articles/How-to-SSH-into-Maintenance-Mode/ta-p/59635 i cant connect via "www" to the management.

 

My new IP is default 192.168.1.1

...

IP Wildcard in custom report?

I have a custom report, I need to exclude 40 Instances of

 

192.168.x.100 to dest port (1234 or 1235)

 

is there a short way to do this or am I faced with 40 repeating lines like this....

 

( addr.src notin 192.168.10.100 and ((port.dst neq 1234) or (port.

...

Log forward without internal logging?

Should it be possible to LOG forward without having internal logging?

 

Some stuff I need to be able to deal with on the firewall, but others I just want recorded long term.

 

Seems to be no option to do it.

what NAT and Network config

Hi,

I have a router from my carrier. This gives me an internal IP 10.0.9.3 /16 from my internal Network 10.0.0.0/16 network and the GW IP he gave me is 10.0.30.99.

Now he makes natting so i could get internet access and there i have a static official i

...

Resolved! Global protect domain based local breakout

Hi,

 

I have a question regarding Global protect and partial split tunnelling.

 

Does GP have an option to only allow specific domains via local breakout, all other traffic should be forwarded into the tunnel.

 

I'm asking this question regarding 0365, all

...

xml stream error

Hi, I'm using Soltra Edge to poll the taxii service from MineMeld.  All works well in that the service can be discovered and I can start polling.  Towards the end of the polling (or possibily at the end), the following error is generated in Soltra Ed

...

PhilipW by L0 Member
  • 1141 Views
  • 0 replies
  • 0 Likes

Skype for Business not work if use SSL Decrypt

Hi,

 

Is it possible to exclude Skype for Business application from SSL Decrypt?

 

Custom No decrypt URL category is not an option because new clients with on-premises Skype instances coming constantly.

 

br

Toni

ToniE by L2 Linker
  • 3918 Views
  • 6 replies
  • 0 Likes
Top Solution Authors
Top Liked Authors