General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 278 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3603 Views
  • 2 replies
  • 14 Likes

negate destination IP's

 

@reaper @BPry

Is you create an allow rule and then select to negate the destination IP's does that mean those IP's are blocked?

jdprovine by L4 Transporter
  • 2580 Views
  • 6 replies
  • 0 Likes

PA-3220 HA-2 Port Configuration

I have purchased a pair of PA-3220 to run as internet gateway. I planned to configure active/passive for HA but I got the status that the HA-2 link is down and I found on website we need to use HSCI port as HA-2(Data Link). Unfortunately, I haven't p

...

Putmano by L0 Member
  • 4088 Views
  • 4 replies
  • 0 Likes

Global Protect Agent and SSID

Hi 

 

I have configured GP agent with internal and external adresse to seamlessly work w/ always on for my endpoints and this works great. And users can not connect to other networks w/coppper cable without the internal GW. And SSID has to be punched i

...

Resolved! Traffic originate from PaloAlto Firewall

Hello Experts - Can you clarify how to configure Paloalto firewall to source traffic from Data Interface rather than Management Interface

 

Scenario: When Firewall send syslog message to exernal Syslog Server, the Firewall has to be configured to have

...

GlobalProtect timeouts.

When configuring a timeout on Globalprotect, the documentation reads:

 

On the GlobalProtect Gateway Configuration dialog, select AgentTimeout Settings and then configure the following settings:
  • Modify the maximum Login Lifetime for a single gateway log
...

Windows Install Failing

Hopefully someone can help or point me in the right direction.  We've been askedby one of our clients to use Global Protect but the client is failing to install on some PCs.

 

They are running Windows 10 Pro and get the following error when trying to i

...

error.jpg
monkums by L1 Bithead
  • 2397 Views
  • 5 replies
  • 0 Likes

Resolved! Threat False Positives?

Our threat logs are full of 'Fallout Exploit Kit Detection' this morning from many of our networks, although no actul issues have been found.

 

fallout.png

Resolved! How I can stop PSIPHONE?

Dear Experts, 

Please can someone help me with how i can denay PSIPHONE? Its, so defcult to do that. I have enable SSH-Proxy and enable SSL-Forward. and create a rule to block SSH APPs and Proxy APPs and finlly add High Risk APPs. After all that PSIPH

...

Resolved! Best Practice - Blocking Applications at Certain times.

Greetings

 

I am trying to find a Best Practice for blocking applications at certain times for a certain group of users.

 

As i see it

 

I create a policy for these users allowing them access to a few applications. now if i wanted to allow them acces to In

...

Wykeham by L1 Bithead
  • 2029 Views
  • 2 replies
  • 0 Likes

Resolved! palo alto decryption adobe flash player connection error

Hi

 

Few months ago I start doing SSL decryption testing on few users, 

 

One of the issue that I have which I didn't find any answer is Adobe flash player, I excluded the site https://get.adobe.com from decryption but still after downloading the  flash

...

adobe connection error.jpg
SShnap by L3 Networker
  • 3179 Views
  • 1 replies
  • 0 Likes

Ingress inconsistent Packet dropping

 

Hello,

 

There are intermittently packet drops for the traffics destined to Internet from the trust zone.

 

No deny log as the traffic cannot traverse through Palo Alto firewall so I can only see drop and receive logs not firewall and transmit logs from

...

GP VPN causing slowness

recently pushed out always-on vpn, but one site/office is reporting slowness when connected to it. The office is a managed office, so i have no control over their internal network.

 

When VPN is disabled they are able to hit 600mb download/upload. As s

...

welly_59 by L3 Networker
  • 1884 Views
  • 3 replies
  • 0 Likes

Relevant Zone for an IP address in Vwire

Hi Experts,

 

Could you please suggest how to find Relevant Zone for an IP addresses in V Wire mode.  When configuring security policy, we need to mention the source and destination zone.

 

 We've PA firewalls only configured in Vwire with multiple zones

...

PBF not working when ECMP is configured

HI 

 

I have two internet links and configured ECMP to do load balacing based on weight,

 

Here I want to allow few users from my internal to specific desired destination based on my PBF to take my ISP2 path.

 

But it is sometimes taking ISP 1 and sometime

...

  • 24175 Posts
  • 100 Subscriptions
Top Liked Authors
Labels