General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4221 Views
  • 0 replies
  • 0 Likes

SSL Decryption - Without URL filtering license

Hello I plan to put in place a SSL decryption rule to decrypt ssl traffic (SSL forward proxy). But I don't want decrypt traffic for several categories of website such as financial (bank website). I haven't the URL filtering license. I create a first rule "Do not decrypt" where I specify "Financial-services" in the URL category but when I test an...

Skip Proxy path for specific URL

Hi Friends, I am using PA500 firewall and access internet using websense proxy server. There is some URL are frequently block in websense server even they are allowed in websense security server. My question is how can I confiugerd policy in firewall so some URLS are skip webproxy path and use direct internet path ?. Kindly help. Reagrds,Pradeep

URL Category in Security Policy only for http?

We unfortunately use a smtp server with fqdn. (cannot use fqdn object for certain reasons)And we implemented a security policy with the url category in the "Service/URL Category" section of the security policy.In the security policy, the application allowed is smtp and port allowed is 25.When we test, the connection does not match this rule at a...

Public VPN Bypass Firewall

Hi , I have blocked some Applications (like youtube, facebook etc in PAN-OS9.0.0), But employees are still able to access these applications while using VPN (Like ibvpn, purevpn).If anyone have solution please let me know, how to block that traffic,

shafi.md by L0 Member
  • 3664 Views
  • 2 replies
  • 0 Likes

Miner for IWF feed

Do you use Minemeld to integrate IWF (Internet Watch Foundation) to Palo Alto and can you share the miner config? The list input from IWF json input w and will need to convert to “URL List”. The feed also requies username/passward authenticaiton.

BatD by L4 Transporter
  • 2827 Views
  • 1 replies
  • 0 Likes

Resolved! Error at task npm install on RHEL 7.6

Hi, we are trying to install Minemeld using ansible and we are having the following error TASK [minemeld : npm install] ***************************************************************************************************************************************************************************************************************fatal: [127.0.0.1]...

PA-5220 high SWAP memory usage

Hi, We have from time to time higher SWAP memory usage on 5520 box. Not sure if this would be critical or if I can just higher the treshold values in monitoring system. On reference box the swap memory is 3%, but on this one 85%. Reference PA-5520--------------------------------------------------------------------------------Number of sessions s...

agolob by L1 Bithead
  • 9258 Views
  • 2 replies
  • 0 Likes

Clientless VPN (Web) and SSO credentials

Dear Palo Alto Experts, We have set-up a Clientless VPN webpage for certain users so that they can connect to an internal website from outside the company. When they logon to the VPN portal, with their Windows Credentials (Radius authenticaton), they are shown a couple of icons for internal webpages. One webpage uses Windows authentication to l...

GlobalProtect_Chrome.png
GlobalProtect_Edge.png

Using custom URL categories

Hi guys, We're trying to stop users from accessing webpages featuring 'momo' content. We've set up the below custom URL category and it only blocks Google searches for momo while in incognito mode, and still allows Google image and Youtube results. Is there anything wrong with this, we may have gone OTT trying to get this to work: Using asteri...

URL category.png

Block websites when using VPN

Some users started to use SoftEther VPN client on our company which allows them to bypass URL Filtering policy. How can we allow them to use VPN client but still allow or block access to certain websites. We already implemented SSL decryption rule but it is not working when they are using SoftEther VPN.

nredaj by L1 Bithead
  • 9108 Views
  • 8 replies
  • 0 Likes

Palo Alto and Panorama integration/availibility question

Hi all, I have some questions about integration between PA firewall and Panorama.In my scenario, there's one cluster of PA devices and only one Panorama device.The firewall policies were imported from the cluster into Panorama (Pre-Rules in the Device group).I performed some changes on policies and pushed them back to the cluster. Until now, eve...

licenselu by L4 Transporter
  • 5374 Views
  • 4 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels