General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! How do you use the new predefined Dynamic IP lists?

Greetings all,

 

I'm wanting to use the new Palo Alto provided dynamic IP lists to block known malicious or high risk IPs but, when creating a security policy, I can't seem to get it to appear in the list for selection.  I've tried copy/pasting the nam

...

jsalmans by L4 Transporter
  • 5867 Views
  • 11 replies
  • 0 Likes

SSL decryption non standard ports

Hello all,

 

I am wondering if palo can identify and decrypt encrypted traffic on non-standard ports(other than 443)? In other words, does firewall decrypt all encrypted traffic traversing through that matches rule?

Resolved! show user group name not showing user list

Hello,

 

We are not getting the list of individual users in the command: show user group name <name>

 

> show user group name "CN=adminstaff,OU=staff,OU=security,OU=Groups,OU=College,OU=Schools,OU=CEWA,DC=test,DC=edu,DC=au"

 

short name:  test\adminstaff

 

s

...

Farzana by L4 Transporter
  • 6799 Views
  • 1 replies
  • 0 Likes

PAN-2020 site-to-site with Meraki Cloud managed firewall

Hi all,

Has anyone had success establishing a site-to-site tunnel between an PAN firewall and a Cisco Meraki Cloud managed firewall?  I've been messing with it for most of the day and have not found much luck.  I've added a third party peer on the Mer

...

cmateam by L3 Networker
  • 7491 Views
  • 7 replies
  • 0 Likes

Resolved! Configuring OCSP

I am trying to configure OCSP and I am a little confused.

 

I have added an OSCP responder. 

 

It appears the second step is to allow the Firewall to use it by configuring Device-Management->Interfaces.  However, for most of my settings, I am using a Ser

...

Resolved! Minemeld with Proxy

Is there any way to perform the minemeld install from behind a proxy? I am deploying a minemeld node in a datacenter where internet access is only available via squid proxy.

 

Thanks,

Nasir

nbilal by L3 Networker
  • 15464 Views
  • 12 replies
  • 0 Likes

VPN SITE TO SITE PALO ALTO NETWORKS

Hello,

 

I configure a VPN tunnel between two firewalls Palo alto Networks . The tunnel status is up but the other network is unreacheable.

I configure the tunnel on the trust zone . I restart the firewalls without result . The first PA-500 with PANOS 7

...

ra7oub4 by L2 Linker
  • 6598 Views
  • 7 replies
  • 0 Likes

AVG & Avast Antivirus

Does anyone use AVG or Avast for their anti-virus requirements and how do you handle streaming updates?

 

It is my understanding that Streaming updates are updates that are pushed to endpoints by AVG/Avast?  These updates are different from typical upd

...

Exception for threat type "file"?

Hi,

 

I have following in my logs:

 

Threat tpye: file
Threat name: CSV file
ID: 52032
Severity: low
File Name: xyz.csv

 

For Vulnerability Protection and Anti-Spyware I know how to easily create exceptions for specific IPs/URLs. Is there a way to easily creat

...

Resolved! HA2 Backup Port Link Speed

Does the HA2 backup port need to be the same link speed as the primary HA2 port?

 

Customer is wondering if it is possible to use a 10G SFP+ port to backup the 40G HSCI port.

 

I cannot find anything in the documentation discussing this and don't current

...

User-ID Service - Client IP Population

All,

 

When we first installed our User-ID Agent service on Windows Server 4-5 years ago we implemented Security Log Reading (from domain controllers logs), AD Session Scanning, and MWI polling.  About 5-6 days ago we started running into issues (which

...

  • 24195 Posts
  • 100 Subscriptions
Top Liked Authors
Labels