General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Auto Focus Question - File Hashing

I need to know if AutoFocus can give a file hash field in the log event entery when it sees a file come through.

 

This file hash will allow us to answer two use cases that we are currently working on, if the file hash is displayed in Splunk, when the

...

Global Protect Certificate

Hi

 

I configured global protect, but when clients try to connect through the agent, they got "Gateway "name":The server certificate is invalid, please contact your IT administrator".

 

For the configured certificates, I configured self-signed certificat

...

myasin by L2 Linker
  • 4323 Views
  • 3 replies
  • 0 Likes

Change Management IPs

Hi

 

We have Panorama managing 6 PA FWs (3 HA Clusters). We want to change the management net of Panorama and Firewalls.

Now logically we will change management IP of Panorama first. Then the Firewalls will lose connectivity and probably logs will be lo

...

PA-200 HA Sync

Hi,

I have a message when I attempt to run a commit:

 

"The running configuration is not currently synchronized to the HA peer, and therefore, this commit will only be applied to the local device.

Please synchronize the peers by going to the dashboard an

...

sync.jpg
s_quasar by L3 Networker
  • 4427 Views
  • 15 replies
  • 0 Likes

FQDN refresh problems

Hell guys,

We have a problem that the FQDN refresh fails nearly everytime. What I mean with "nearly" everytime is, that there are periods in which the FQDN refresh is running smoothly, and then suddenly it fails again.

Example: A few days ago the FQDN

...

HIP logs to Panorama

I am looking to export HIP logs to Panorama. Firewalls are in Active-Passive mode. Since firewall sync HIP logs in between them I was getting two logs in panorama for each log entry (one from each firewall). Even though I configured active firewall o

...

Rajesh12 by L3 Networker
  • 1266 Views
  • 0 replies
  • 0 Likes

Resolved! user if agent and switching between ids

we have configured rules with group mapping using LDAP.

We have one user where he switch between user ids and when he trieds to login to server with user id not allowed in list he gets

denied.

 

should he log off and log on as best practice when he switc

...

MP18 by Cyber Elite
  • 2933 Views
  • 5 replies
  • 0 Likes

8.1.4 CP Normalizing

All of our users who auth over CP are now normalizing as 'domain.com\user' although we need them to be user@domain.com.

 

The authentication profile they go through has the %USERINPUT%@%USERDOMAIN% modifier.  Domain is filled in & login attribute is 'u

...

Resolved! Minemeld Proxy error

Hi,

 

I've setup Minemeld to use the corporate proxies based on this thread and I'm still getting this error:

 

"ConnectTimeout: HTTPSConnectionPool(host='www.dshield.org', port=443): Max retries exceeded with url: /block.txt (Caused by ConnectTimeoutErr

...

otlaP5 by L0 Member
  • 4787 Views
  • 2 replies
  • 0 Likes

Resolved! Panorama Managed collectors - Default and M500 Log collector

We have Panorama M100 in Panorama Mode.

They are in HA pair.

 

Also we have 2 M500 as dedicated log collector mode.

 

Under Panorama managed collectors  I see default is also checked along with 2 dedicated log collectors.

 

Need to know why default option i

...

Capture1.PNG
MP18 by Cyber Elite
  • 2560 Views
  • 6 replies
  • 0 Likes

Resolved! Split tunnel VPN inclusion rule - traffic dropped

Hello Community,

I need to allow traffic to come down the VPN tunnel rather than the Split Tunnel.
I have addred a VPN tunnel inclusion rule on the GlobalProtect Gateways as described in this article:


https://www.paloaltonetworks.com/documentation/80/pa

...

000000 by L1 Bithead
  • 1866 Views
  • 2 replies
  • 0 Likes

Use MP SSL Session Cache

when i run the below command 

 

show system setting ssl-decrypt setting

 

vsys : vsys1
Forward Proxy Ready : yes
Inbound Proxy Ready : no
Disable ssl : no
Disable ssl-decrypt : no
Notify user : no
Proxy for URL : no
Wait for URL : yes
Block revoked Cert : yes
Cer

...

MP18 by Cyber Elite
  • 2516 Views
  • 2 replies
  • 0 Likes

How to apply advanced filters for O365 API feeds?

Hi,

 

We would like to retrieve IP addresses from O365, but only for a specific endpoint set (in that instance, endpoint set 56 which is related to O365 authentication (login.microsoft.com etc.), as you can see here: https://docs.microsoft.com/en-us/

...

Picheck by L0 Member
  • 2658 Views
  • 0 replies
  • 1 Likes
  • 24255 Posts
  • 99 Subscriptions
Top Liked Authors
Labels