General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Unable to export certificates EXCEPT via IE11

Two PA3020s in an active/passive HA pair

PanOS 7.1.14

 

Tested with Google Chrome and Firefox on Linux.

Tested with Google Chrome and Firefox on Windows 7.

 

When trying to export a certificate from Device tab --> Certificate Management --> Certificates, n

...

fjwcash by L4 Transporter
  • 3873 Views
  • 3 replies
  • 0 Likes

Resolved! Moving between device groups

I am looking to move my firewalls from one Panorama (7.0.3) device group to a new device group.  All active policy rules have been cloned over to the new device group from the existing device group, and the objects are all "shared". 

 

Even though al

...

Resolved! Cannot retrieve indicators from FS-ISAC feed

I recently created a feed over at FS-ISAC for my organization, and I'm able to connect successfully from within MineMeld, however I am not receiving any indicators. My initial_interval is set to 30d and when I test using 'taxii-poll' from the shell ...

benime by L1 Bithead
  • 5228 Views
  • 2 replies
  • 0 Likes

Resolved! SSL forward trust option

Hi,

 

We have a certificate generated by RapidSSL as CA. but we can NOT set this certificate as a forward trust certificate to use in Decyption SSL, the option shows disable. Roots is in the list "default trsuted certificate authorities".

 

Why the optio

...

1.JPG
BigPalo by L4 Transporter
  • 6682 Views
  • 9 replies
  • 0 Likes

Resolved! JSON Parsing - ProofPoint

Has anyone been able to get ProofPoint TAP logs into MineMeld?  I think the issue I'm having is with my JSON configuration.  Here's what I have so far but it's not pulling any indicators.  I've tested my query on http://jmespath.org/ with sucessful r

...

json.JPG
jt1025 by L2 Linker
  • 11434 Views
  • 14 replies
  • 0 Likes

QUIC deny vs drop

Just curious.

 

The recommended QUIC rules set the action to 'deny', but the first rule is for service udp 80/443 any application. Is there a reason this is a 'deny' and not a 'drop'?

 

Reference

HOW TO BLOCK QUIC PROTOCOL

https://knowledgebase.paloaltonet

...

mike406 by L2 Linker
  • 2456 Views
  • 1 replies
  • 0 Likes

Resolved! Custom App signature and App pushed from PA update

 

What if we create creates a custom application containing Layer 7 signatures.

And after few days the PA send the Latest APP and  Threat updates and we download those in the PA


What will happen if the update contains an application that matches the sam

...

MP18 by Cyber Elite
  • 2363 Views
  • 2 replies
  • 0 Likes

Block VPN access for lost iphone/ipad

Hi, I followed the document on how to create VPN for IOS devices with certificates, and I got it working.

I was wondering how I can deny a device VPN access for a device which is lost or stolen. Deleting the certificate Client ID certificate on the Pa

...

LocalDB Node Bulk Uploads

Is it possible to bulk upload to the LocalDB Nodes?  The input UI appears to only accept a single indicator per line, and doesn't do any validation of the information being input.

Indicator Loader.JPG

Resolved! GlobalProtect stopped to work after appliance reboot

The GlobalProtect Portal/Gateway had been working perfectly until tonight I have restarted the Palo Alto appliance.

After - I was not able to connect. The portal page - ERR_CONNECTION_TIMED_OUT.

 

I tryied to load older configs, I have even reinstalled

...

Resolved! About Threat and Wildfire submission

 

Hi all and specialist engineer, I would like to know sometimes I'm doubt about monitor wildfire submission and threat which wildfire is shown in a monitor (ref: wildfire portal ) but why threat does not show even though same both a file name and typ

...

  • 23583 Posts
  • 103 Subscriptions
Top Liked Authors
Labels