General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 732 Views
  • 0 replies
  • 0 Likes

Global Protect Client software version

Hi all,

 

We upgraded client vpn 3.1.4 to 4.1.2. We are having 200 end users. I just need to check how many users accessing new Version. because still old version also available.

 

How many of using Globalprotect version 3.1.4 ?

How many of using Globalpr

...

Resolved! Adding device serial number to Panorama with API

I am trying to add a PA-VM to the Panorama using the Panorama API.

 

I try:

 

https://1.0.20.30.40//api/?key=LUFRPT0zAndSoOnAndSoOnAndSoOn=&type=config&action=set&xpath=/config/devices/entry[@name='all']&element=<serial>12345678012345</serial>

 

and I get

...

Resolved! Question about outbound hostname restrictions

I'm familiar with user based restrictions to outbound resources, such as youtube, but is it possible with say, a regex expression, to block access to a site like youtube through a list of machines that include a name like kiosk, as in cakiosk01, coki

...

murphyca by L1 Bithead
  • 4343 Views
  • 7 replies
  • 0 Likes

Resolved! Single firewall with core connections

I have a single firewall no HA at the moment which is connected to my 2 core routers which the routers running HSRP. How does Palo device know which device to send traffic to as it seems its sending too both causing asymmetrical routing.

clydef by L0 Member
  • 2200 Views
  • 2 replies
  • 0 Likes

Resolved! TAXII into QRadar

Hi there,

Is there any guidance for how to set up TAXII output for QRadar to ingest? I see in the latest release notes:

 

- TAXII DataFeed now translated IP Ranges into CIDR for better compatibility with 3rd party TAXII clients (read IBM QRadar)

 

 

...

Resolved! How to use Aggregate interfaces LACP?

Testing a PA-220. Create an Aggregate group with 2 interfaces.

Both interfaces connect to an unmanaged D-Link switch. And it connected to the company network.

The aggregate interface can up when LACP is not enable.

After enable LACP. It down and hover t

...

jeremylo by L3 Networker
  • 8372 Views
  • 5 replies
  • 0 Likes

Need help determining why something is blocked.

I am getting the following items blocked, but I can't tell why.  I am not blocking the games category with my URL filtering.

 

I also can't find a way to specifically allow Microsoft PE file transfers. I have also tried whitelisting the site, but nothi

...

Palo-Deny.GIF
dsmall by L0 Member
  • 2517 Views
  • 3 replies
  • 0 Likes

Resolved! How to add a new admin user via the API

I'm working on a script to deploy new Palo Alto firewalls in vmware from template, using powershell.

I'm doing this with API calls in the powershell code.

 

for instance, change hostname:

 

$hnURL = "https://myPA//api/?key=" + $apiKey + "&type=config&acti

...

ICAP support with PA for DLP

Hi Team 

 

please advise if DLP , ICAP is supported with PA . There is no document found as such , but i have found few fourms which says it is not supported but wanted to check as a confirmation. 

Rameshwar by L3 Networker
  • 5559 Views
  • 1 replies
  • 0 Likes

Re: Application based Policy approach

While moving from a service based to application based policy approach how to tackle the dependent applications for the specific application. for instance consider a app "webex-base" which is dependent on apps"rtcp, rtp-base, ssl, stun, web-browsing"

...

Sanssj by L2 Linker
  • 3271 Views
  • 1 replies
  • 0 Likes

Resolved! Mixed Internal and External GlobalProtect

Hi All!

I'm working through the "Mixed Internal and External Gateway Configuration" and something isn't quite clear - 

Do I need to create 2 separate GlobalProtect Portals (one to listen on the outside interface and one for the internal interface) or s

...

Issue with External Dynamic List

I have just created a new/first External Dynamic List on my firewall with a type of URL. I have applied an action under a number of URL filtering Profiles, but I see the following messages: request system external-list show type url name edl-url1 Ser...

murphyj by L2 Linker
  • 3073 Views
  • 3 replies
  • 0 Likes
  • 23977 Posts
  • 115 Subscriptions
Top Liked Authors
Labels