General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4225 Views
  • 0 replies
  • 0 Likes

Exporting full applipedia list

I was wondering if there was some way to export the full applipedia list to include the standard ports and implicit use/depends on applications also. Or if this information is somewhere else that is easier to pull from than selecting on each individual one in applipedia.

Disabling NetBIOS with DHCP Option 43

All, I am in the process of migrating DHCP services from a Cisco IOS-XE switch to Palo Alto 220 firewalls. DHCP is working flawlessly however I am curious about the implementation of Option 43 for disabling NetBIOS. In the Cisco world it is implemented like this: ip dhcp pool DHCP_USERS option 43 hex 0104.0000.0002I am trying to understand if ...

image.png

Resolved! Hangout/meet configuration

Hello everybody, In my company, we are implmenting g-suite and I would like to know if some of you already did it. I'm facing some problem mainly on google-hangout/google-meet. When I try to do a hangout video and audio, I see my traffic going to stun and after, I have my traffic "aged-out" and my conference never works. Any idea ? David

Resolved! Data filtering blocking when it should not

We were testing File Blocking and found that it was blocking too much. The configuration consisted of 2 rules: - Applications = ms-ds-smbv1, File-types=any, Action=continue- Applications = any, File-types=any, Action=alert The test was to download an excel file using SMBv1, and result was blocked.We would expect that it would allow it. If we j...

Threat in "ZIP", how do you determine what request it was in??

I keep getting a specific threat logged for a "dll" which I suspect may be in a ZIP that has been inspected. I can't seem to find any information on what ZIP it was in so I can corrolate the event with our web filtering system. The threat log does not seem to give me any clues.. Cheers Rob

Resolved! Diasble 7.1 Administrative session cipher suites

Hello, A recent PEN Test has advised we disbale the Arcfour when connecting via SSH to manage the Palo Alto via CLI. We are on release 7.1.6 (pending upgrade). https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-7-1/cipher-suites-supported-in-pan-os-7-1-admin-sessi...

Resolved! IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -> ISAKMP Negotiation

Hi, I am trying to setup a Site to Site VPN between a Palo Alto FW and a 3rd Party Security FW Vendor; I would like to undestand under which condition the Palo Alto FW would attempt to start an ISAKMP negotiation (for Phase 1) with the IPSec peer counterpart. I'm familiar with the Cisco ASA setup - where, for ex., the tunnel is brought up only w...

CarloInt by L0 Member
  • 3745 Views
  • 1 replies
  • 0 Likes

User-ID Statistics

We have a cenario where the Firewall control the Internet access from users in the local network and we control these access with URL profiles and security policies.We identify the user session with USER-ID Agent installed on Windows AD Servers.I'd like to count how many users the Firewall identify per day in the Internet Access.How can I get th...

mmcastr by L1 Bithead
  • 3972 Views
  • 3 replies
  • 0 Likes

Setting "log at session start" on multiple rules

I found a KB but it's from 2016 and is no longer applicable. I want to enable 'log at session start' on thousands of existing Security Pre-Rules across several Device Groups. I remember a multi-edit function but something's changed and I can't figure out how to do this. We're running Pano 8.0.8 and 7.1.8 on the firewalls.

Resolved! app not show on application field on policy based forwarding

Hi community, what is the reason one app not show applications field/We need create one policy with one app that show on applications, but when I check in PBF the app is not show. The app name "supremo" use default port tcp/443 and Implicitly Uses: web-browsing.What is the reason ?

Cacti Host Template: From PA500 to VM100 - failing

We have enjoyed Cacti statistics from our PA-500 box for years. But when I replaced the PA500 with a VM-100 then Cacti could no more connect to fetch data via SNMP. I thought both models used the same protocol and version. Below you'll see a screenshot of the cacti settings that worked with our PA500. What do I need to change here to connect ...

CactiHost.jpg
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels