General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 291 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3622 Views
  • 2 replies
  • 14 Likes

Issue FQDN address with dns records with short TTL

I have configured a firewall rule to allow some servers  to ssh to vs-ssh.visualstudio.com to allow the servers to use ssh to connect to the git repo of Azure devops.

 

This rule uses fqdn address object to allow the servers to only connect on ssh to t

...

ECMP + 3 Internet links + Outgoing traffic

Hello friends!

 

We have now 3 ISPs, we started to use load balancing (all methoeds tested);

 

Problem: Sometimes, packets from PA220, interface 1/4 (ISP 1),  goes out to internet thru interface 1/5 (ISP 2).

User's traffic with no problem.. But PA220 inte

...

ScreenShot293.jpg
ScreenShot294.jpg

Local Support for Pan-DB

Hi All,  a client of ours lives in SouthEast Asia and is looking to purchase Pan-DB and wonders if they will need to rely on local support there, which is very spotty.  It looks like this community and the support side of things is very strong.  How

...

Resolved! wildfire questions

Hi All,

 

I recently started applying wildfire profiles for most of my traffic to public cloud on all applications. This includes some senitive information for eg: user trying to print out a document that has some sensitive details.

I know wildfire prov

...

MS Update ActiveX Cab file Denied?

Hello.

 

I just reloaded a Windows 7 x64 computer.  The first check wants to update the Windows update agent.

For some reason PA blocks it as a ActiveX Cab file.

The first check allows, but the it's denied. (picture attached).

I added a Virus exception fo

...

pa1272018a.JPG
catrock by L2 Linker
  • 3886 Views
  • 3 replies
  • 0 Likes

Resolved! Teamviewer and Commit warning

We have to allow only Teamviewer on some pc's, not internet browsing.

I created rule with apps:
teamviewer (apps-group)
teamviewer-web
adobe-flash-socketpolicy-server, ssl, web-browsing

But this rule will allow web-access to all sites.

Ok, i created custom

...

aaobuhov by L2 Linker
  • 4300 Views
  • 3 replies
  • 0 Likes

DLP Options

Im exploring some various DLP options for one of my clients. Im niot finding much in regards to DLP functionality on Palo Altos (I have a pair of 3020's) 

Does anyone know what Palo Altos DLP solutions consist of? If any?

Im primarily concerned with th

...

Resolved! revert configuration automatically

I had a situation where checking log at start session box in a security policy while troubleshooting, after 2 minutes to commit changes, I lost comunication with the fw, because data plane get 100%. I would like to know if there is a commit revert co

...

Marivi by L3 Networker
  • 2877 Views
  • 1 replies
  • 0 Likes

useful custom reports

Hey all,

I want to create some custom reports to get more useful information about what is going on in my network.

I would like to know - just informational - which reports do you use in your daily business?

Respectively which reports you consider as us

...

MPI-AE by L4 Transporter
  • 6499 Views
  • 21 replies
  • 0 Likes

Where is the BPA tool located??

I want to run BPA reports against my configs but I can't find the tool anywhere???

 

I know it exists as I have a Initial Analysis from our 3rd party supplier, but I would prefere to cut them out of the loop.

 

Any ideas?

 

Cheers

 

Rob

Resolved! Getting Started with Best Practices Templates

Hi 2 all

 

I am trying to create best practice for Vulnerability Protection and Anti-Spyware Profile with extended packet capture as desribed in

https://www.paloaltonetworks.com/documentation/81/best-practices/best-practices-internet-gateway/best-practi

...

aaobuhov by L2 Linker
  • 3212 Views
  • 3 replies
  • 0 Likes

Resolved! /opt/panrepo

Hello,

someone know for What is used this partition? /opt/panrepo

Marivi by L3 Networker
  • 5959 Views
  • 2 replies
  • 0 Likes

Dynamic group from panorama.Vm info source

Hi,

We realised that vcenter fields are not being updated when we create a dynamic address group in panorama. From the fw is working fine and values are refreshed in real time. The method we use to monitor vcenter is VM information source.
So we dont k...

BigPalo by L4 Transporter
  • 1342 Views
  • 0 replies
  • 0 Likes

PVLAN with Palo Alto?

I'm looking at doing some re-design for our DC networks and wanted to investigate some further segmentation.  Since we aren't really large enough for NSX or ACI I wanted to look at PVLAN.

 

I've got some Nexus9K switches with Layer 3 licensing in HA an

...

jsalmans by L4 Transporter
  • 4978 Views
  • 5 replies
  • 0 Likes
  • 24180 Posts
  • 100 Subscriptions
Top Liked Authors
Labels