General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Adding additional public IP range

Hi all - I've been having a bit of trouble getting this to work - I've done it on Cisco & Sonicwall boxes before, but this is my first PA 3020. We were just assigned additional public IP addresses by our ISP. The existing block is 206.x.x.x/29 and the new block is 165.x.x.x/29, so they're note contiguous. I went into the Ethernet Interface...

bwade by L0 Member
  • 5611 Views
  • 3 replies
  • 0 Likes

Resolved! OS partition

Is there anyway to freeup space on the partition were the OS resides on the PA or is that automagically done when you upgrade the os. All articles dealing with clean up of the disk space has mainly to do with purging logs, the image repository, the configuration but not really the OS.

jdprovine by L4 Transporter
  • 4250 Views
  • 3 replies
  • 0 Likes

Security policy rule - allowing a specific host access to ftp.sophos.com

Hello, A colleague needs to access ftp.sophos.com (195.171.192.29) using Filezilla as their SFTP client, via TCP port 990. I set up the security policy rule as follows: They could not log onto the ftp.sophos.com site. The password credentials they used are correct. Is the rule set up correctly? On a Cisco ASA I would have used the following A...

Source.PNG
Destination.PNG
Service.PNG
Actions.PNG
rchung54 by L2 Linker
  • 14928 Views
  • 18 replies
  • 0 Likes

Resolved! Using Minemeld for URL EDL

Dear MM comunity, I am trying to use MM for parsing a URL list to populate a PA NGFW which lacks Url filtering license. I have found that predefined miner urlhaus.URL which seems very well done. It is based on https://urlhaus.abuse.ch/ , which is free of charge. I have cloned it, then cloned a URL aggregator and a URL Output. I used the fo...

wdoria by L0 Member
  • 12864 Views
  • 4 replies
  • 0 Likes

Resolved! Device maximum ospf peers

hi guys is there a document that list the maximum OSPF peers and OSPF Areas for PA5220(per device is better) since ther might be a hardware or software limit on it for stability purposes. Thanks

toskie by L1 Bithead
  • 3826 Views
  • 1 replies
  • 0 Likes

Downgrade Pan OS

Does the debug svm revert still work on the 8 os? https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcYCAS

jdprovine by L4 Transporter
  • 9227 Views
  • 8 replies
  • 0 Likes

Odd NAT issue...

Had a very odd issue yesterday, I created two new Bi-Directional nat rules [seperate NAT IP's] to the outside world, one worked fine the other did not... One server could not get to the outside world..The NAT matched [OK],The Security Rule Matched [OK], Searched the configs [and old ones] for any possible clash with the NAT IP "X.X.X.115", Nothi...

nat1.jpg
nat2.jpg

Certificate Setup on HA Pair

Hello, I wanted to use the SSL/TLS profile facility to restrcit management GUI sessions to TLSv1.2 but am having trouble with the certificates/process to follow. We have an Active/Passive HA Pair, i have been trying to setup on the passive to test but it is not working, from having a look around i susepct this may need to be setup on the Active...

Resolved! Default Master Key lifetime

Dear Comm, I do understand that we use the master key for encrypting our private keys and passwords stored on the firewall. However I am wondering why we should touch this key at anytime? What is the default lifetime of the default master key? I assume it to be 0 (=infinite) as I cant find anything about this question even in the PANOS admin gui...

Rboehme by L2 Linker
  • 6588 Views
  • 2 replies
  • 0 Likes

ldap user group unable to get access

I have ldap server setup with auth profile. User gets authenticate by ldap server and can login via global protect.User is part og the group and a policy is created for this group to access resources.If i change the group to any access is granted but not with specific group in policy.

Regarding pcnse

What is the level of toughness that we have in real exam than what we see in practice test on a scale of 1-5.Is there any good pcnse practice tests that match the level of real exam. The only source of my prep is just the pcnse study guide is there any book that is recommended.Thx.

Sanssj by L2 Linker
  • 4747 Views
  • 3 replies
  • 0 Likes

Resolved! Datafeed Empty Indicators

Dear group; I had running Minemeld server with defautl Miner like that spamhaus_DROP, spamhaus_EDROP working fine. I Create a Custom Miner of prototype libraesva.LIBRAESVA_Advertising_IP4 with the follow info: Miner: LIBRAESVA_Advertising_IP4-feet2CLASS minemeld.ft.http.HttpFTPROTOTYPE libraesva.LIBRAESVA_Advertising_IP4Processor: aggre...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels