General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4473 Views
  • 0 replies
  • 0 Likes

Client Authentication Sequence only works for 1st item in the list

I configured Client Authentication Sequence for both GlobalProtect Portal and Gateway for both LDAP and local database. For some reason, only the first item in the list works. It does not seem to try the rest of the sequences in the list. If LDAP is first in the list, then LDAP authentication works but not Local database. If Local databse is...

rhap4boy by L1 Bithead
  • 4616 Views
  • 4 replies
  • 0 Likes

Minemeld Installation OVA + ISO : LiveCD or removable?

Hi everyone, I want to install Minemeld following the official tutorial [1] that uses an Ubuntu OVA + MineMeld ISO that installs the software during the first boot. My question is if that ISO can be removed after first boot and the consecuent installation, or it's a LiveCD that needs to be plugged in all time. Something like the following proces...

Azure Datacenter IP Dynamic List Issues

Hi all, We have the azure_cloudIPS miner, processor and outpur working and can view the list of IPs via the link (https://minemeld.mycomp.com/feeds/AZ_DC_IPS). We have simplar feeds setup of Office365. However, the on teh PaloAlto, the dynamic list is empty). Test URL Source is successful, and the Office365 feed populates just fine. There...

DIzzard by L0 Member
  • 2845 Views
  • 1 replies
  • 0 Likes

Advise on using AD user-id in local PA groups?

I am struggling with utilizing ActiveDirectory groups in firewall policy. My concern is then our AD administrators have control over transversing our firewall policy. Generally speaking say for example we have a FW policy setup where AD group ServerAdmins has <some type of> to a resource, they (the AD administrator) could very easily throw...

zthiel by L2 Linker
  • 3651 Views
  • 3 replies
  • 0 Likes

Resolved! New GP deployment - DNS, ping, and tracert work, but no app traffic

I've set up a new GP config on a new PA-820 firewall. I have an old firewall I'm replacing, but I'm running them side by side. On the new 820 GP, I can connect with a GP client, and then ping internal servers. I can verify that DNS is working with nslookup using our internal DNS servers and all of the internal resources resolve and can be pinged...

Resolved! User-ID Proof Of Concept - With Proxy

Good afternoon Team, Pardon my stupidity here. I'm running a PoC at the minute and customer is keen on the User-ID aspect. However, the have most of their users behind a proxy. We have configured the PoC in standard TAP, with LDAP server profile etc etc. We are picking up users in logs from AD but I'm wondering if there is a way to see users beh...

One to one NAT mapping for many to many

Sonicwalls have a setting that allow a /24 subnet being natted to a different /24 subnet to get mapped on a one to one basis. Example, 192.168.1.10 will get bidirectionally natted to 10.0.0.10, 192.168.1.11 will get bidirectionally natted to 10.0.0.11, etc... The last octet will always stay the same which allows one nat rule to be added so both...

Query on Split tunneling

Hello, We are trying to exclude one IP from including routing in split tunneling.VPN is working, however, I found that when going to 192.168.16.22, still through VPN rather than local LAN.What we need to setup is ONLY this range, 192.168.0.0/16, will be accessed via VPN except one particular IP shown below.Looks like we need to use include and ...

Config.png

Resolved! Can Wildfire be integrated with Traps?

Hi; If Wildcard declares a file to be melisious after having been downloaded by one user, then what? Can Wildfire inform End Point Protection Traps management to quarantine that particular user device? KindlyWasfi

Resolved! What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

Hi; My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or pr...

Many to many dynamic NAT (/24 to /24)

Is there a way to make a dynamic NAT rule that translates one /24 subnet to another /24 subnet work in both directions and map last octet to last octet? There's a way to do it in Sonicwall so if your natting a subnet to another it will make .20 on the real local subnet map to .20 on the natted subnet and do that for all IP's. The reason why I as...

  • 24380 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels