General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Cacti Host Template: From PA500 to VM100 - failing

We have enjoyed Cacti statistics from our PA-500 box for years. But when I replaced the PA500 with a VM-100 then Cacti could no more connect to fetch data via SNMP. I thought both models used the same protocol and version. Below you'll see a screenshot of the cacti settings that worked with our PA500. What do I need to change here to connect ...

CactiHost.jpg

Why public cloud users did not need Palo Alto before ?

Dear all We can see heavy public cloud users since 2016. But we did not have Palo Alto on public cloud until recent. Does that mean public cloud does not need 3rd party security solutions like Palo Alto? Because if public cloud users really need 3rd party security solutions like Palo Alto, they should not survive 2016-2018, should they? They sur...

Re: user-id agent issues

We are using windows user-id agent for parsing the user and user group mapping info. often i see in the logs that the user is being not recognized and hitting the deny rule. after couple of minutes it starts recognizing the user and allows the traffic i am skeptical what could be the reason for this disparity. why would any user info and user...

Sanssj by L2 Linker
  • 2556 Views
  • 2 replies
  • 0 Likes

Resolved! Errors in installing Minemeld on Ubuntu 14.04

I am trying to install minemeld on ubuntu 14.04. here the steps I did: I made iptables inactive I Added and verified successfuly the repo GPG key I added the minemeld APT repo I verified that minemled APT is added in /etc/apt/sources.list However, we I do the last step: sudo apt-get update && sudo apt-get install -y minemeld rsyslog-mi...

Capture.PNG

PAN-SA-2018-0015

Hi guys, Just saw the notice about PAN-SA-2018-0015. Doesn't seem like this vulnerability is a real issue. Am I correct? Or is there a viable way of someone exploiting it?

YoniLeit by L0 Member
  • 4790 Views
  • 2 replies
  • 0 Likes

Resolved! How to generate traffic reports for a specifi interface

Hello Palo experts, I want to create a report which tells me what bandwidth has been used on an outside interface, for say the past month. Something that can display the average bandwidth being used during a day would be good. I see on my PA-3050 that under Network>QoS, that live bandwidth stats can be displayed, but can't see where I can exp...

rchung54 by L2 Linker
  • 24451 Views
  • 4 replies
  • 0 Likes

Deleting Panorama templates

Hi, A firewall has been configured with a template from Panorama, the template was then deleted from Panorama.Can i safely remove the template from the firewall without deleting the config applied through the template?

Add device in Panorama

Hi, We are trying to add a devices in Panorama. We have checked the conectivity FW-> in port 3978. We can see the packet running tcpdump in Panorama about packets comming from FW. so connectivity is OK. Everything looks ok. And we have another FWs in PAnorama correctly. This is the status "DIsconnected": FW versions is 7.1.6Panorama 7.1.9

Panora.JPG
BigPalo by L4 Transporter
  • 2254 Views
  • 2 replies
  • 0 Likes

Resolved! What is the value of a Backup Peer HA1 IP Address?

In some of our firewalls I note a secondary IP address is assigned to a single HA group ID. What is the value of having this second IP? The problem it's introducing is that SNMP Trapsare getting gerated once or twice a day noting that the secondary IP address couldn't be reached. But there is never a problem with HA failing over - the primary is...

Can Pan-os take action base on rules, condition or report?

Hi.I have a question about a scenario. Can Pan-OS/Firewall detected a infected host/client pc and take the following action.Blocking internett access from the infected hosts/client pc and move the infected host to a another security zone?ORJust move the infected host to a "security" zone that don't have access to internet?

tonyle by L0 Member
  • 2342 Views
  • 2 replies
  • 0 Likes

SSL Certificate Profiles - PANOS External Dynamic Lists

I'm running into an issue with external dynamic list threat feeds while using panos 8, the problem being is it seems they introduced a great feature to validate and authentication SSL sources by validating the signing CA for the threat feeds that can induce access rule entries. This is great although the problem I'm facing is the implementation ...

RTECIT by L0 Member
  • 4139 Views
  • 4 replies
  • 1 Likes

DNS "Aged Out"

ISP changed fiber line coming into site. DNS server addresses did not change (they say) but the external addresses and gateway did change. I can connect to the internet but just for about 2 to 3 minutes and then I lose access to the internet. Updated all definitions with the new information. Simple network… LAN ...

Panorama - Object

Hello I start the Panorama configuration and I created Device Group. My device group are based on our site location : FR - Paris - Toulouse I would like to know the best way for the configuration. If I create objects in Paris DG (object to define Paris's local networks and servers) and I create also objects in Toulouse DG (object to define Tou...

Resolved! New template stacks after upgrade?

Hi all, I upgraded from an 8.0 release to 8.1.3 to prepare for a migration to some new hardware. I did a commit after the upgrade to make sure everything was synced up between Panorama and the firewalls and I believe everything went ok. I was making some adjustments at the recommendation of the Best Practices analyzer in Expedition and noticed ...

jsalmans by L4 Transporter
  • 7359 Views
  • 5 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels