General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 529 Views
  • 0 replies
  • 2 Likes

Resolved! recommended version of Panorama 8.1?

 

I have new PA that has come with 8.1 version.

Currently we have PA and PAnorama running on version 8.0.9.

 

Which is the recommended version of PAnorama in 8.1?

MP18 by Cyber Elite
  • 2739 Views
  • 3 replies
  • 0 Likes

moving firewall from one device group to another

I have one parent device group with  7 firewalls.

I have created 2 new device groups and i need to move 4 firewalls from the parent device group into these 2 new device groups.so  each new device group will have 2 firewalls each.

 

right now issue is th

...

MP18 by Cyber Elite
  • 4365 Views
  • 6 replies
  • 0 Likes

Resolved! does panorama gets local config from firewall

 

On one of education videos it says that in background panorma talks to firewall every 90 mins or so and pulls whole config

from palo alto(local config on palo alto and global config pushed via panorama?

 

Need to confirm if we have local config on palo

...

MP18 by Cyber Elite
  • 3362 Views
  • 6 replies
  • 0 Likes

Resolved! PA not installing antivirus automatically

On Active PAssive PA both devices are configured to download and install the antivirus every hour.

Today PAssive PA installed the software but on Active it only downloaded the antivirus update.

 

I need to manually install the antivirus on the active PA

...

MP18 by Cyber Elite
  • 3081 Views
  • 2 replies
  • 0 Likes

Resolved! Single packet threat pcap and disk space alert

 

I have enabled threat signature to capture single file only.

 

but from last 3 days i see so many same threat logs with pcap done.

 

i got email today of disk space alert

 

i checked disk space

 

show system disk-space

Filesystem Size Used Avail Use% Mounted

...

MP18 by Cyber Elite
  • 2148 Views
  • 1 replies
  • 0 Likes

Resolved! losing panorama config pushed to firewall

 

wondering if we have pushed all the config from panorama to pa.

PA has all the global  security polices.

 

what will happen  if we lose that panorama device like hardware failure?

 

or if we delete all the config from panorama and give it reboot?

MP18 by Cyber Elite
  • 2371 Views
  • 2 replies
  • 0 Likes

Resolved! ssl decryption and policy deny

 

I have configured ssl decryption and rule is there to allow the traffic 

IT is hitting the right rule but policy says denied?

 

 

what can be reason for this?

 

Capture.PNG
MP18 by Cyber Elite
  • 6464 Views
  • 5 replies
  • 0 Likes

Resolved! session offfload and flow basic

 

When we do session offload then PCAP can not capture the session offload traffic .

if i am also doing flow basic on that then flow basic will not be impacted by session offload?

 

Regards

Mike

MP18 by Cyber Elite
  • 3642 Views
  • 4 replies
  • 0 Likes

Resolved! Wildfire appliance on a darknet

I have recently been given the responsibility of installing and managing a previously purchased WF-500.  It was purchased for an environment that is completely disconnected from the Internet, totally dark.  My question is - is there a way to manually

...

Resolved! ssl-decrypt exclude-cache ---SSL_CLIENT_CERT

 

when i run below command 

 

show system setting ssl-decrypt exclude-cache

 

VSYS SERVER APP TIMEOUT REASON DECRYPTED_APP PROFILE EXCLUSION_LIST_MATCH

13.71.172.130:443 ssl 42077 SSL_CLIENT_CERT undecided default No

 

does this mean that PA can not decrypt

...

MP18 by Cyber Elite
  • 4126 Views
  • 2 replies
  • 0 Likes

Resolved! Decryption Profile ----No decryption

i am using default  decryption profile.

 

Under tab  no decryption i see below

 

block sessions with expired certs

 

 

need to understand when does this setting is used when i am doing the ssl decryption or not doing ssl decryption?

 also does it only apply

...

MP18 by Cyber Elite
  • 2904 Views
  • 4 replies
  • 0 Likes

show counter global | match proxy

Need to verify if below output looks good from ssl decrypt 

 

show counter global | match proxy
ctd_fwd_session_proxy_deny 384306 0 info ctd pktproc Content forward: action init denied for decrypted sessions
ctd_switch_proxy 4 0 info ctd pktproc switch t

...

MP18 by Cyber Elite
  • 3447 Views
  • 3 replies
  • 0 Likes

Resolved! LDAP over IPsec?

Hello.

 

I'm trying to configure UserID via our domain controllers in AWS.

 

The setup:

We have an HA PA-820 pair on-prem connected to our domain in AWS via a redundant IPsec tunnel.  Traffic is passing between LAN and IPsec zones; on-prem workstations ca

...

  • 23731 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels