General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

DNS Block and Notification on Specific Networks

Greetings all, I'm toning down some of our NAC enforcement in favor of trying to find other ways to secure the network (lots of users on BYOD don't like to install a 3rd party client to monitor their device). One of the things we were doing was to check for proper DNS settings. We block external DNS in favor of using several sets of internal s...

jsalmans by L4 Transporter
  • 6041 Views
  • 4 replies
  • 0 Likes

Resolved! Global Protect with RSA SecurID and Group Mapping for Security Policy

I have setup Global Protect with RSA SecurID authentication. I would like to use the Active Directory groups of these users in my security policy to then allow or deny access to resources based upon their membership. I have configured the group mapping settings and the firewall is pulling in the AD groups. However, the policies I have created...

Site-to-site VPN with Strongswan (opensource)

Hi all,I wonder whether anyone has successfully configured site-to-site IPSec VPN tunnel with CalAmp LTE Fusion device (a cellular mobile router). Somehow I cannot establish the vpn tunnel under different configurations and I know it is running opensource strongswan. Interestingly, CalAmp has an older model Vanguard 3000 for 3G and the vpn tunne...

Panorama using Variables with DHCP server

Ciao,I'm using variables in Panorama in order to use one Template for all firewall remote site deployment.However in the DHCP server configuration I'm able to use variables as primary DNS server (i'm usign PAN as DNS proxy).Any Idea?Thanks

2 Output to the same destination

I need 2 output to Azure Sentinel, one for domain and the other for IP. The first output for IP is workingI add the second output for domain = the first output stop working. Is it normal behavior ? Where should I look ? How can I fix it ? THanks

MineMeld with Office 365

Hey forks! I would like to add the office control functionalities in minemeld, but I cannot find a way to add it, no configuration that I apply collects data, and I no longer know if I am doing it badly or it does not work. Could you help me? Thank you very much in advance

Resolved! URLHaus complete list help

I am trying to pull the complete list from URLHaus (https://urlhaus.abuse.ch/api/) and specificly the CSV feed. (https://urlhaus.abuse.ch/downloads/csv/) The problem is this. The feed is huge! Over 200k right now, so the PAN will not take it because of it's limits. I noticed that most of these URL's are marked offline. So there are less than ...

Mattk by L2 Linker
  • 7615 Views
  • 2 replies
  • 0 Likes

Resolved! Active PA license expiring soon

We have PA in active passive mode.Seems Active PA license is expiring soon. Due to our internal process we can not get license in time. If active PA license is expired will it work normally in Active passive mode?

MP18 by Cyber Elite
  • 4488 Views
  • 3 replies
  • 0 Likes

Resolved! Link or Path monitoring function

If I have not enabled any type of HA, can I still enable Link or path monitoring to trigger a firewall (not in HA) to go in suspend or non functional state ?

PS007 by L2 Linker
  • 4004 Views
  • 2 replies
  • 0 Likes

False Positive (virus/win32.wgeneric.vnujo)

Dear Support, Our customers have been reporting that palo alto is identifying our software as malware. application ms-ds-smbv3virus/win32.wgeneric.vnujoID 219797367 How can we proceed to whitelist our software permanently? Thank you

prsi0203 by L1 Bithead
  • 7955 Views
  • 4 replies
  • 0 Likes

Resolved! How do you deal with Service Route and MGT port redundancy?

We had an outage that took out a switch, and the PA management port is connected to that switch. I was unable to access the UI or CLI, and VPN was unable to authenticate via LDAP. I found the issue was that all the Service Routes were set to default using the MGT port. After looking through the settings, I see that I can assign a Management Prof...

Maxstr by L3 Networker
  • 6708 Views
  • 4 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels