Any 3rd party app for user activity report?
Anyone using a 3rd party app to generate user activity reports from Palo logs? The report I get from Palo is not that interactive and informative.
Anyone using a 3rd party app to generate user activity reports from Palo logs? The report I get from Palo is not that interactive and informative.
Hi Experts , We have existing rule for "Syslog" application ,our current security polcy with App-id and services configured as below , Application - "Syslog" ( default application which allows TCP 1468, TCP 1514, TCP 6514, UDP 514 and UDP 1514 ) Service - "application-default" Now we have a requirement to additionally add TCP-514 and U...
Hi, I am some what confused and reaching out for a little help. We have a pair of 3020s in Active/Passive mode with two interfaces, DMZ (Ethernet1/1) & Public (Ethernet1/3). HA is configured to use dedicated HA Ports and all indicators on the dashboard are Matched and UP. When I manually suspend the Active device, the Passive device becomes ...
Hello,We are going to migrate from Traps ESM to Traps Management Service.After this, we want our helpdesk to administrate Traps, but we do not want to create a palo alto account for every user. Now I found some information about the Palo Alto Directory Sync Service, but unfortunately a login to TMS is not mentioned in the documentation.Is this n...
According to Documentation, https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields.html The field Flags is a 32-bit field that provides details on session; this field can be decoded by AND-ing the values with the logged value. In my Traffic Log: <14>Apr 3 ...
I'm trying to block users from going to the site: itsalmo.stI go to: Objects > Custom Objects > Url Catagory > Blocked Urls and then add *.itsalmo.st/Then I commit.I waited a while, can see it inthe list but users can still reach it and use the page.I tried it again, no go.An hour later it's still not being blocked. I'm a new admin to t...
Quick write here. We currently use Pingdom to monitor external reachability to services and our remote office edge devices. In some scenarios such as new office deployments, we may need to utilize the WAN interface to setup the device. The problem here is the All-or-None approach of management profiles. We want only ping from pingdom's probe...
We currently block incomming regions such as China - CN however we have some traveling teammates that will need to be able to VPN connect back to us in US who will be in Tawain. The crux of my question is if CN is blocked but TN= Taiwan ROC by the abbeviation lookup is NOT blocked will this traffic be allowed if attemped from Taiwan? I could fi...
Hello,We want to use wake on LAN in a vlan attached to a layer3 interface on the firewall. The magic packets are sent from a server outside the vlan to the broadcast address. I allowed WOL-packets in the firewall policies, and I see them in the logs, but the computers don't start. Do we have to configure something else in the firewall to allow i...
I have tried a lot, and at this point I think I just must be missing something obvious that for whatever reason wont come to mind. From the PA3050 I can not ping outbound from the public IP. When I run captures, all outbound traffic is in dropped stage. There is no network functionality at all, and I am unable to find the issue. Security ConfigN...
Is there a way to prevent (address) objects created in Panorama from deploying to firewalls/device-groups where they are unnecessary?
Good day,I have such kind of issue after PAN update to 9 version.Here are 5 allow categories, pre-defined categories (low-risk, medium-risk, high-risk and newly-registered-domains), which I want to make alert. But after change, all of categories became allow.Have any of you faced this kind of situation?Thanks in advance.
Is it possible to log the version of ssl/tls being used for decrypted sessions (inbound ssl inspection in particular)? I know we can control what versions are used in the decryption profile but is there any way to identify the specific ssl versions being used in sessions without doing a full pcap? We were looking for a way to do this in mass.
Hello Community,I have posted this question before, and was told that it is a server error, I have replaced the server but with the same error, so I thought I would post it again, could it be somthing wrong with the server configuration, or could it be a bug.I am facing an issue where the External Dynamic List shows an error when tested by cli c...
The office has 2 internet data line. Each of them has a fix public IP address. Device is a PA-820.I want to separate the utilization of the data line as below. 1. Office area/staff primary use 1st data line. If this line down then auto change to use 2nd data line. When 1st data line resume. Auto change back.2. Guest area always use 2nd data line...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |

