General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Application match... Sophos-live-protection to 8.8.8.8

Our logs show a numebr of connections from our DC's to port "53" application sophos-live-protection... That's fair enough, I understand the concept of what sophos are tryign to do with this. What I don't understand is why the destination is 8.8.8.8 and not one of the sophos listening addresses... I don't suppose anyone sees this? Rob

Resolved! Create VPN Profile or Group for a vendor to access specific internal server

Hello all, We snagged a PA820 to replace an old ASA 5510. I think I have everything set and I am almost ready to cut over to the new PA firewall, with one exception: I am drawing a blank on the best way to setup VPN access for a support vendor. With our current Cisco solution, the vendor starts up Cisco AnyConnect, and selects a group from a dr...

colesch by L2 Linker
  • 11402 Views
  • 8 replies
  • 0 Likes

mgmtsrvr - virtual memory limit exceeded, restarting

Has anyone seen this before? I'm looking for feedback on whether or not this is directly related to the VM Panorama sits on? This was the decription of an alert I received at 12:30EST today. Sure enough, Pano was rebooting. Any information provided is greatly appreciated!Thanks,Erich

ejm by Not applicable
  • 9330 Views
  • 4 replies
  • 0 Likes

Resolved! Dynamic Destination Routing

Hello All,i have a senarion in which a user vlan routed to internet link1 thorugh policy baseed routing now i have a one destination which has dymaic IPs and only can open with internet link 2 i want this destinatioon to be opend for the user vlan, how can i achieve this?

FShabbir by L1 Bithead
  • 4468 Views
  • 5 replies
  • 0 Likes

Email attachment

Hi EveryOne How i can block the email attachment (RAR ,EXE) file What the proper way to check to fake email are incoming in a local network

MFayez by L2 Linker
  • 2059 Views
  • 1 replies
  • 0 Likes

Resolved! unknown-tcp when tls decryption is enabled

I have a VM-100 in my lab. I haven't used it in while but recently booted it up and upgraded to 8.0.12. I noticed a lot of unknown-tcp traffic for mostly any site when I enabled tls decryption. If i disabled tls decryption, the traffic is all ssl. I have never seen this before. I'm running it on esxi 5.5

ce1028 by L4 Transporter
  • 3499 Views
  • 2 replies
  • 0 Likes

Failed to install licenses. Model incompatible: feature model is VM300 while the device model is PRA

Hello all, I have just setup a Palo Alto firewall virtual instance. I have the interfaces setup now so that I can download updates/content. I attempted to apply my license using the authorization code. The first time that I tried I got an error that I needed a minimum of 6.5 GB of memory, so I shutdown the VM and changed it to 4vCPU and 8GB...

PFerris by L1 Bithead
  • 18322 Views
  • 8 replies
  • 1 Likes

Resolved! Panorama Shared Policy Zones

Hi all,I want to understand before I deploy shared policy in Prod I have 2*2 firewalls in HA (2 For DMZ, 2 For LAN) - I want to create a shared policy to both firewalls (LAN and DMZ)For example,In LAN I have 3 zones (Users, Servers, DMZ) In DMZ I Have also 3 zones (LAN, DMZ Servers, Internet)when I want to create one policy to shared device-grou...

VMWare ESXi PAN-OS upgrade: from 8.0.7 to 8.1.3 ->Active/Passive HA (without Panorama)

Hi community, Having reviewed: https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/determine-pan-os-upgrade-path#id181QEN0D0QY and https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/upgrade-an...

ash83 by L2 Linker
  • 4313 Views
  • 5 replies
  • 0 Likes

Resolved! zone protection issue.

Hi to all!I have such kind of problem.I have applied Zone Protection profile on my outside(untrust) interface.The problem is, that PAN is behind IBR(is configured as virtual wire), where are configured all our public ip.What can we do in this case?Thanks in advance!

Re: configure airgapped miner for on premise minemeld

Hi guys, we recently setup a minemeld server meant for a airgapped environment and we are trying to figure out how to setup a airgapped miner with the other information found here on customizing a miner. https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694 is there any available article for...

Resolved! Traffic using unintended Security Rule?

Hello folks, We have recently installed Cisco Nexus switches and UCS system. All of our routing has been through our PA firewall and continues to be, except for a new Management network created on the Nexus switch. We are trying to use this management network for our vsphere hosts, etc. We added a static route on PA to route requests to the N...

pasecurityrule3.jpg
pasecurityrule2.jpg
pasecurityrule.jpg
OMatlock by L4 Transporter
  • 4514 Views
  • 5 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels