General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Palo Alto Agentless User-Ip mapping Not Working

Hi Folks, Need urgent help on an issue where " PAN Box Integrated with AD as an LDAP entity for USER-IP Mapping. So when User switches from LAN --> WiFi or WiFi --> LAN different IP Subnet, user-ip mapping don't change instantaneously" because of this user based policy doesn't enforce. Please help.

Resolved! Threat Prevention - IPS features

Hi, Can we enable IPS features on a particular sub-interface/zone in Palo alto so that it gets applied to all traffic that enters through that particular sub-interface? From the little reading which i did, i am seeing it as configuring it in security profiles and applying the profile under individual security policy. I particularly ask for a ...

MGRashmi by L2 Linker
  • 5349 Views
  • 4 replies
  • 0 Likes

Resolved! Scheduled export of csv system log for Global Protect logins

Have been looking around trying to find this and can't find it. I have a filter for system logs to filter all the successfull Global Protect logins for the last calendar week. I have been manually exporting this to a csv but wanted to schedule the process to email the csv out. Is there any way to do this?

Resolved! Aperture working/basic, how aperture policy works

I started with aperture and document mentioned "Aperture compares your user defined aperture policies to the data content and context to calculatre any policy violations" I understoodConext = data exposureContent = Data patterns inside the acutal file As palo alto stores only meta-data, how the policy is checked. Whether policies are sent to the...

Passive device dataplane interface and management interface

Hi Team, Can we ping management IP of the passive device from the any one of the dataplane interface on the passive device. Interfaces on the passive devices are up (showing green) --> passive link state is auto. We have tried pinging the internet interface and it is working fine but internet is not working. We are unable to ping the manageme...

IPSec VPN not working before phase 2 negotiation

Hello, I made an VPN Tunnel between paloalto and fortigate(3 tunnels). Every config is same between them. 2 of them work well but 1 tunnel has an issue. About 3 mins before phase 2 negotiation(by lifetime or other reason), traffics can't go through the tunnel.(I can see traffic logs that incomplete). After negotiation and install sa, it works no...

yhlee1 by L2 Linker
  • 6793 Views
  • 7 replies
  • 0 Likes

Is it ok to set ipsec phase 1 lifetime 24 hours when the peer set it to 86400 secs?

HelloI made ipsec tunnel between paloalto and fortigate. I keep have issue about rekeying, so I try to set different lifetime phase 1 and 2.phase 1 : 28800 -> 86400phase 2 : 28800 -> 28800 In paloalto I can't set 86400 sec, so I plan to set it 24 hours. Is it okay to set it that way? Because fortigate will set the value to 86400 sec.

yhlee1 by L2 Linker
  • 8487 Views
  • 2 replies
  • 0 Likes

Resolved! Whitelisting Load-Balanced Sites - Fetch DNS records as JSON

For sites (to be whitelisted) that are behind ever-changing IP ranges (e.g. Amazon load balancer), has anybody used a services like these? https://dns.google.com/resolve?name=www.netflix.com https://dns-api.org/A/www.netflix.com Is there an existing miner that does DNS lookups? I saw this recommend in another thread but I'm hoping to a...

Minemeld TAXII ISAC

Hi all, I have the way to get feeds from ISAC with a TAXII prototype and I want to share with you all. Proabably it can help someone. Firstly it's necessary to import the minemeld-taxii-ng extension on system>extensions and install extension from git, and activate it, https://github.com/PaloAltoNetworks/minemeld-taxii-ng.git Then, clone the t...

isac_example.JPG
Xavi_Gil by L0 Member
  • 6651 Views
  • 1 replies
  • 3 Likes

Resolved! How to enable API access for Minemeld

I have been working on syncing a manual localDB miner list via this Python script (https://gist.github.com/jtschichold/95f3906566b18b50cf2e3e1a44f1e785) When I use it, I get 'Unauthorized' when trying to access /status/minemeld. If I manually authenticate via browser first then attempt access, it works. My question is do you have to change...

hbiglin by L0 Member
  • 8170 Views
  • 4 replies
  • 0 Likes

Developing my first Extension: MineMeld Server now reports ERROR RETRIEVING EXTENSIONS LIST

I worked on my first extension today (based on the structure and files of youtube-miner). As soon as I imported it into MineMeld I got the ERROR RETRIEVING EXTENSIONS LIST: INTERNAL SERVER ERROR red box of shame. What log should I be looking in for clues? I've searched a bit and I know this was the path of the local folder. I removed i...

Resolved! wlc monility and EoIp traffic

Hello All, I have WLC and anchor-WLC with PA firewall in between, I have rule allowing EoIP and wlc-mobility APPs with application-default service selected, I don't see on monitor tab any single packet logged, even though I know for sure it is there, I was able to see it through PA CLI with debug filter set(EoIP example packet below):Packet rece...

evdanil by L1 Bithead
  • 7333 Views
  • 4 replies
  • 0 Likes

Resolved! running-config to candid-config OR candid-config to running-config

Hello All, Kindly help understand the concept. I am preparing for my PCNSE and I was reading through the a manual provided by Palo Alto (EDU-255). Under Configuration Operations, at one point the document reads that “the running configuration is copied to a candidate configuration during firewall startup”. On the very next page, the document rea...

Creating Minemeld IPv4 Lists

I'm a newbie with Minemeld and Autofocus. I'm looking to create a Minemeld Miner that will maintain IPv4 Whitelist based on an AWS Site that is load balancing and/or using DNS Round Robin.The CDN that we're pulling data from lives in AWS and IP Address Resolution is constantly changing (see api.ebass-emmi.eu). My plan is to create a External Dyn...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels