General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

Resolved! Custom App signature and App pushed from PA update

What if we create creates a custom application containing Layer 7 signatures.And after few days the PA send the Latest APP and Threat updates and we download those in the PAWhat will happen if the update contains an application that matches the same traffic signatures as the custom application? or which thing is hit first custom app or applica...

MP18 by Cyber Elite
  • 3463 Views
  • 2 replies
  • 0 Likes

Block VPN access for lost iphone/ipad

Hi, I followed the document on how to create VPN for IOS devices with certificates, and I got it working.I was wondering how I can deny a device VPN access for a device which is lost or stolen. Deleting the certificate Client ID certificate on the PaloAlto Box does not help. The device can still connect.The user can change his password but I wou...

LocalDB Node Bulk Uploads

Is it possible to bulk upload to the LocalDB Nodes? The input UI appears to only accept a single indicator per line, and doesn't do any validation of the information being input.

Indicator Loader.JPG

Resolved! GlobalProtect stopped to work after appliance reboot

The GlobalProtect Portal/Gateway had been working perfectly until tonight I have restarted the Palo Alto appliance.After - I was not able to connect. The portal page - ERR_CONNECTION_TIMED_OUT. I tryied to load older configs, I have even reinstalled the software version (8.0.13). No luck. I the Session Browser I do not see anything that looks li...

Resolved! PA-220 - bidirectional NAT - how to get a Nintendo Switch to work online

Greetings, I am trying to create the NAT IP only rule as outlined here.https://www.ericooi.com/palo-alto-firewall-home-network/ I have a single External WAN interface Etherenet 1/1. I am wondering how the referenced NAT SOURCE Translation interface (Object/Physical/Other???) is created to configure the Source Translation?I am only able to add '...

catrock by L2 Linker
  • 12299 Views
  • 4 replies
  • 0 Likes

Resolved! About Threat and Wildfire submission

Hi all and specialist engineer, I would like to know sometimes I'm doubt about monitor wildfire submission and threat which wildfire is shown in a monitor (ref: wildfire portal ) but why threat does not show even though same both a file name and type malware.

Resolved! IPSec P2P VPN Tunnel not working

Hi,I am trying to terminate on PaloAlto VM-100 (8.0.13) an IPsec tunnel.It seems that the other side is not able to connect at all. We have checke all IKE settings and they seem OK.I am using a Loopback interface with an external IP address (exactly as I am using for the GlobalProtect VPN which is working fine).Do I have to create any NAT rules ...

Where is app-id for https?

I am trying to fulfill a request by my security team to enable app id on our palo alto rule base & I cannot find the app id for https. There is also a machine inside our envirionment that needs to be accessed over tcp 444 using https:// so I assume enabling app id won't break communication to this machine as long as I specify port 444 in th...

VM-100 serie firewall in AH mode on vmware Hyper-Converged VxRail.

Hello Team, I am going to deployed the VM-100 serie firewall in AH mode on vmware Hyper-Converged VxRail ( with esxi).The VM-100 series will bee used to protect the servers deployed on the VxRail.What are the requirements needed for the deployement of the WM-100 on the vmware Hyper-Converged VxRail ?cans somone please sugested a senario of ...

TaxiiDataFeed - Aging out of Feed

Hi Guys, using as prototype the "stdlib.taxiiDataFeed" I've exposed through Minemeld a TAXII Feed. Now i've observed that this prototype is the only that can't be aged out, in fact the IoCs collected from the sources comes in addition to those already present in the Feed. Is there a functionality to enable the aging out of the Output (stdlib.ta...

rafy92 by L1 Bithead
  • 14089 Views
  • 7 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels