General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

False Positive (virus/win32.wgeneric.vnujo)

Dear Support, Our customers have been reporting that palo alto is identifying our software as malware. application ms-ds-smbv3virus/win32.wgeneric.vnujoID 219797367 How can we proceed to whitelist our software permanently? Thank you

prsi0203 by L1 Bithead
  • 7993 Views
  • 4 replies
  • 0 Likes

Resolved! How do you deal with Service Route and MGT port redundancy?

We had an outage that took out a switch, and the PA management port is connected to that switch. I was unable to access the UI or CLI, and VPN was unable to authenticate via LDAP. I found the issue was that all the Service Routes were set to default using the MGT port. After looking through the settings, I see that I can assign a Management Prof...

Maxstr by L3 Networker
  • 6751 Views
  • 4 replies
  • 0 Likes

How to resolve invalid NAT rules in Expedition

I've downloaded and run the latest Expedition VM, and have imported my Cisco ASA config file, but Expedition says all my NAT rules are invalid. Not clear what that means, and the instructions (link below) say nothing about how to resolve them. https://live.paloaltonetworks.com/t5/Expedition-Articles/Expedition-Documentation/ta-p/215619?attachme...

Seeking Guidance on What Content Should Be Included In a Panorama Maintenance Guide

Tasked with creating a "Panorama Maintenance Guide," but finding little detail regarding what should be included. I have search for something similar from Panorama, but I have been unable to locate anything.There are a few functions I want to include, but I do no have those technical details for performing the task. Details to include if possibl...

TLHaga by L0 Member
  • 2871 Views
  • 2 replies
  • 0 Likes

Resolved! Checking for CloudWatch

Hi all, Relatively new with Prisma and playing with the RQL. Would anyone be able to tell me if there's a query i can run that tells me if cloudwatch is enabled within an AWS environment? Report wise, I tried running something against CIS compliance and it's really just telling me that cloud trail is not integrated with cloud watch which doesn't...

Resolved! HIP logs review

Hi, Need your insight !!We have few VPN portals to meet HIP checks ( laptop - Domain and anti virus ) I could see the HIP logs in the HIP Match ( that means host passed the HIP match ?)Or those logs that shows HIP match passed or failed ? Any keyword or check mark to verify host cleared the HIP matches ? ThanksKM

GlobalProtect reports Machine Certificate (null) but it isn't...

Hey all,Recently upgraded to PAN-OS v9.0.3 and GlobalProtect is no longer working for some. Error messages in the system logs are showing GlobalProtect portal client configuration failed... Machine Certificate CN: (null) for those that fail but also Machine Certificate CN: (just a blank here) for those that are successful. This is intermitten...

cafowler by L2 Linker
  • 6574 Views
  • 1 replies
  • 0 Likes

Resolved! Panorama Error

Getting below error in Panoram's system logs : Panorama has lost connection to its peer, no log will be forwarded Though from Panorama all devices looks connected .Verifed the device status from panorma. Anyone facing similar issue ?

deepak12 by L3 Networker
  • 11198 Views
  • 4 replies
  • 0 Likes

TCP issues when moving an application through a Palo Alto FW

Hi, Following scenario: we have a 2-level Firewall Filtering / Security Setup active in our infrastructure, with a Cisco ASA currently acting as the Internet Firewall (updated to the latest Cisco ASA OS version) and an internal Firewall (Checkpoint appliance, also updated to GAIA OS R80.20). Among others (like Web Servers, DNS, Email, and so on)...

NAT PPTP VPN

Hello, im trying to set up a NAT rule for a PPTP VPN tunnel.I have set it up like this:Source: untrustDest. zone: untrustSource address: AnyDest. address: lets say 20.20.20.20/32Service: anySource Translation: NoneDest-Translation:20.20.20.20/32 Security RuleZone:untrustSource address: Geo Location:NO,EUDestionation:20.20.20.20/32Application: PP...

holten by L1 Bithead
  • 4107 Views
  • 1 replies
  • 0 Likes

TLS 1.3 support

Hi everybody,any news regarding change of decryption from passive to proxy mode to support TLS 1.3 decryption?Thank you,Jan

Palo Alto lab devices

Hi guys,I was assigned to work on a project with involves working with Palo Alto appliances a lot. I have never touched such a firewall before, so I am planning to get two (or more) devices for my home lab and experimental use. Do you think the PA-2050 model would be suitable to get me started and possibly help me get certified? Thanks a lot.Reg...

Problems with panorama and paloalto ACC No data display

Hello good afternoon I have a problem with my panorama and a Palo Alto HA, in the panorama the complete traffic is not visualized and in the ACC no data display. Already apply these commands > request log-fwd-ctrl device <serial number> action stop> request log-fwd-ctrl device <serial number> action start But the same thing is ...

Question about Global protect Pre-Logon Issue

Hi, I configured GP pre-logon method, But it’s only working in administrator mode even though the user is part of administrator group, it’ not working for normal users. I followed below KB article,https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 In global protect client installed laptops, we are able to connect g...

GlobalProtect.jpeg

On boarding Large Numbers of Firewalls Using Panorama and Bootstrapping

I am working on a project which will involve deploying a large number of PA220 firewalls to branch offices. This will happen over a period of time with probably around 30-50 branches per phase of work. These branch firewalls will be managed using Panorama. I am looking to streamline the whole deployment process and to this point have completed t...

rmarlow by L1 Bithead
  • 6456 Views
  • 3 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels