General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! losing panorama config pushed to firewall

wondering if we have pushed all the config from panorama to pa.PA has all the global security polices. what will happen if we lose that panorama device like hardware failure? or if we delete all the config from panorama and give it reboot?

MP18 by Cyber Elite
  • 3099 Views
  • 2 replies
  • 0 Likes

Resolved! ssl decryption and policy deny

I have configured ssl decryption and rule is there to allow the traffic IT is hitting the right rule but policy says denied? what can be reason for this?

Capture.PNG
MP18 by Cyber Elite
  • 8209 Views
  • 5 replies
  • 0 Likes

Resolved! session offfload and flow basic

When we do session offload then PCAP can not capture the session offload traffic .if i am also doing flow basic on that then flow basic will not be impacted by session offload? RegardsMike

MP18 by Cyber Elite
  • 5094 Views
  • 4 replies
  • 0 Likes

Resolved! Wildfire appliance on a darknet

I have recently been given the responsibility of installing and managing a previously purchased WF-500. It was purchased for an environment that is completely disconnected from the Internet, totally dark. My question is - is there a way to manually download wildfire signatures and updates and install them on the appliance?

Resolved! ssl-decrypt exclude-cache ---SSL_CLIENT_CERT

when i run below command show system setting ssl-decrypt exclude-cache VSYS SERVER APP TIMEOUT REASON DECRYPTED_APP PROFILE EXCLUSION_LIST_MATCH13.71.172.130:443 ssl 42077 SSL_CLIENT_CERT undecided default No does this mean that PA can not decrypt the ssl traffic due to client cert? what can be actual reason behind this?

MP18 by Cyber Elite
  • 5276 Views
  • 2 replies
  • 0 Likes

Resolved! Decryption Profile ----No decryption

i am using default decryption profile. Under tab no decryption i see below block sessions with expired certs need to understand when does this setting is used when i am doing the ssl decryption or not doing ssl decryption? also does it only apply to ssl decryption policy ?

MP18 by Cyber Elite
  • 3930 Views
  • 4 replies
  • 0 Likes

show counter global | match proxy

Need to verify if below output looks good from ssl decrypt show counter global | match proxyctd_fwd_session_proxy_deny 384306 0 info ctd pktproc Content forward: action init denied for decrypted sessionsctd_switch_proxy 4 0 info ctd pktproc switch to proxyproxy_process 217482856 146 info proxy pktproc Number of flows go through proxyproxy_inval...

MP18 by Cyber Elite
  • 4469 Views
  • 3 replies
  • 0 Likes

Resolved! LDAP over IPsec?

Hello. I'm trying to configure UserID via our domain controllers in AWS. The setup:We have an HA PA-820 pair on-prem connected to our domain in AWS via a redundant IPsec tunnel. Traffic is passing between LAN and IPsec zones; on-prem workstations can ping both domain controllers. I have configured an LDAP Server Profile, an Authentication Prof...

Tunnel Migration

Hello, I am going to migarte my production firewall PA5050 into new location, already done the setup of firewall. Can any one please suggest the best possible way to migrate my all IPVPN tunnels in New Palo Alto, is basilcy to move one palo alto to another one, do we have a specified tool for that? or i need to do it manually. Thanksamit

Resolved! Working temperature

Hello everyoneWhat are the normal working temperature for palo-alto pa-820, pa-500 and pa-3020 ? It seems that it's beyond to the normal specifications ( above 40 °C )Thanks's you for your answer

Learner by L1 Bithead
  • 7415 Views
  • 6 replies
  • 0 Likes

Resolved! Microsoft authentication issues with Akamai IPs blocked by Palo Alto (?)

There was a massive outage on Microsoft sites. It has been resolved now, but I was wondering if this something related to Palo Alto Dynamic updates.https://www.reddit.com/r/sysadmin/comments/9nc9oj/microsoft_authentication_issues_with_akamai_ips/We just got nailed this morning with issues caused by Palo Alto Firewalls adding an Akamai IP/IP-rang...

Resolved! AutoFocus-Hosted MineMeld: access to API

Hi, we have an autofocus instance with MineMeld application enabled. I'd like to call this Minemeld's API in order to get some metrics for our internal reports about Intel. With self-hosted Minemeld is easy, but, is it possible with AutoFocus-Hosted application? I don't know the URLs to make the request, the user or authotization header to ...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels