General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 270 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3595 Views
  • 2 replies
  • 14 Likes

MineMeld Splunk App

Hi Guys,

 

I'm new to this community. At the moment, we are actively exploring MineMeld in our environment and would like to know if there is any connectors available for Splunk to consume intel collected by MineMeld .

Please advise.

Thank you.

Is my upgrade the cause of a vlan not working

After I upgraded my palo alto fro 7.1.15 to 7.1.16 I had a report that a certain vlan can not longer access the internet.  I have a back up of the config before the upgrade and one after the upgrade and so far I don't see any change in virtual router

...

jdprovine by L4 Transporter
  • 3224 Views
  • 9 replies
  • 0 Likes

Arp getting time out after 30 min on sub interface

We are facing some starnge issue .

We are having an ISP which is connected to sub interface.

We are trying to repalce it with new one. Same Subnet /29 but different IP. NAT rules also same because same subnet.

The issue we are facing is when new ISP con

...

Static Routes

We have a Cisco ASA that has tunnels to our branch offices.  An Example is 192.168.9.0/24.  The local network is 192.168.10.0/24.  The lan port of the ASA is 192.168.10.10.  The lan port of the Palo Alto is 192.168.10.1.  When I change the gateway to

...

Resolved! Risky ports

What are the risky ports we should not allow from user zone (internal network) to external network (internet / external network)? Like we don't allow 21/23 etc, please suggest other ports too.....

SumitB by L1 Bithead
  • 2406 Views
  • 3 replies
  • 0 Likes

Resolved! excluding threats from TAP allerting?

We have a TAP interface listening to a number of vlans (internal and external)

 

We get a lot of noise in our allerts from threats we would prefer not to get alerted on.

 

For example, presently "SipVicious"  scans are occuring all the time to what are a

...

MineMeld and ELK

Hi all,

 

I'm having some trouble parsing MineMeld events into Logstash, and then into ELasticSearch. Does anyone have any resources available for this kind of set up?

tom.dell by L0 Member
  • 3694 Views
  • 2 replies
  • 0 Likes

Bad Gateway Error - Minemeld Not Running

Hi All,

 

My Minemeld instance seemed to randomly break and I'm not sure why. When I try to login I get a bad gateway error and the EDL URL's give the same message. Here are some log snippets:

 

minemeld-engine.log:

 

2018-05-11T06:25:45 (4222)base.s

...

password policy has locked out the admin

Is there a way to have an email warning if a password is going to expire?  One of our palo alto (which is stigged) has locked every user out.  This includes the emergency and admin accounts.  I guess, now the only way to get back in is to to in via t

...

Missing ikemgr.log

I wanted to delete the ikemgr.log.old, however, I deleted the ikemgr.log

Now no vpn logging is available anymore. I already restarted the management plane. No luck.

Does somebody know what to do?

Gerben by L0 Member
  • 2609 Views
  • 3 replies
  • 0 Likes

Resolved! adding more than one UIA agent on firewall?

Hi Techies,

 

I have a small doubt whether I can add more than one UIA server in my firewall in the sense that they should behave kind of active passive .

 

Requirement is something like that I want to secure user id functionality on firewall so that if

...

Any Any Rule

Many times I have seen that engineers used to allow any rule during troubleshooting and forget to remove which creates problem in audit and compliance check, is there any option so that engineers should configure rule with any in source/destination/p

...

SumitB by L1 Bithead
  • 1612 Views
  • 2 replies
  • 0 Likes

Controling East-West traffic without NSX

Hello,

In a "Supported Deployments on VMware vSphere Hypervisor (ESXi)" section of the documentation (https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-o

...

  • 24173 Posts
  • 100 Subscriptions
Top Liked Authors
Labels