General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 290 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3617 Views
  • 2 replies
  • 14 Likes

Resolved! Upgrading GlobalProtect while on corp network

Hi everyone,

 

I have a client who said every time they try to upgrade globalprotect, they have mixed results. The issue seems to be that they'll set the GP App to "Allow with prompt". However, the users will never get the prompt while they are on the

...

ce1028 by L4 Transporter
  • 3797 Views
  • 9 replies
  • 0 Likes

Resolved! Adding app depencendies

This might be a dumb question, but I visited 3 clients in the past 2 weeks that did not include application depenendcies in their policy rules

 

For example, they'll have a rule allowing webex-base, but don't add rtcp, rtp-base, or stun.  To be fair, a

...

ce1028 by L4 Transporter
  • 2071 Views
  • 2 replies
  • 0 Likes

SSL Version

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

Resolved! HTTPS URL Filtering without decryption

Hello all,

 

I am trying to implement URL Filtering for HTTPS websites but without decryption. I found a post on how to deliver response pages to Users. (https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-

...

Resolved! Untrust to Untrust - Allow

I was working at a customer site and noticed the customer's last rule before their "Catch-All - Deny" rule was  "Untrust - Untrust Allow". It was a universal rule with source zone untrust  destination zone untrust set to allow. When I asked why they

...

ce1028 by L4 Transporter
  • 10849 Views
  • 11 replies
  • 0 Likes

Binding to AD with globalprotect

We have user accessing the globalprotect VPN using their AD account and we have userid enabled, but we do not see any evidence of the users in the AD domain controller, is that because GP is accessing the DC using a service account? Is there anyway t

...

jdprovine by L4 Transporter
  • 4232 Views
  • 13 replies
  • 0 Likes

Dual ISP IPSEC vpn tunnel monitor drops the connection

Hi all,

 

I added second ISP to firewall and created ECMP for dual ISP followed those guides:

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#

 

https://live.paloaltonetworks.co

...

SShnap by L3 Networker
  • 2716 Views
  • 3 replies
  • 0 Likes

GRE support on PAN-OS 8.0

Hi,

is it possible to terminate a GRE tunnel on a PaloAlto? Parhaps there is something new in 8.0

 

Best regrads,

Sebastian

sst by L0 Member
  • 4239 Views
  • 5 replies
  • 0 Likes

Resolved! Log forwarding - Local on Gateway or Panorama

Hello - I have Firewalls configured with Log Forwarding to Panorama. The question is, do the traffic logs of the Firewall Gateway keeps the copy of the logs and send another copy to Panorama or does it have only one copy forwarded to Panorama

 

Can i c

...

PA VM licensing issue between support accounts

Hi,

 

Although looking through this in internal sources as well, but maybe you guys have seen this and have an idea.

 

Initially there was PA VM-100 trial registered in Support Account 1 - partner account. Everything's good.

Trial expired, full license wa

...

nikoo by L3 Networker
  • 3958 Views
  • 3 replies
  • 0 Likes

Web-Browsing default port application

Hey , 

 

i just wondered why in the era that all web traffic is moving forward beeing encrypted and browsers like chrome will soon mark websites that uses HTTP protocol as "unsage" paloalto "web-browsing" application still uses in it's default ports on

...

minow by L4 Transporter
  • 17882 Views
  • 5 replies
  • 0 Likes

Re:Minemeld Miner Config

Hi guys,

How can we creat a prototype miner in the MInemeld hosted by autofocus, is there any tech document with regards to how to customize/config a prototype for Miner.

Thanks 

Sanssj by L2 Linker
  • 2523 Views
  • 1 replies
  • 0 Likes

Resolved! Decryption servers same ip

Hi,

 

We need to decrypt traffic (SSL Inbound Inspection) for a server which is running 3 URL. This server has 3 certificates, one per application.

 

So we would like to decrypt traffic for this 3 applications but in decrypt policy we only configure usin

...

BigPalo by L4 Transporter
  • 1736 Views
  • 1 replies
  • 0 Likes
  • 24179 Posts
  • 100 Subscriptions
Top Liked Authors
Labels