General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Certificate not valid

I am trying to setup Machine authentication, where it actually validates the machine certificate, I have a PKI infrastructure, that pushes certificates to the machines, with there name in Common Name, and SAN, of the machine hostname. On they Certificate Profile i have enabled CRL, and added both Root and intermediate CA, and set username to su...

Spiff_21 by L1 Bithead
  • 69543 Views
  • 4 replies
  • 0 Likes

radius and PANF gui

Hello , I have integrated Radius with VM FW the ssh to FW works . I have not created any local user on FW , All users are on radius server but gui to FW does not work with radius account ; when i enter radius creds in gui , it accepts and comes back to the login screen again ? Is that a known issue I created 10 users in Radius and a...

LDAP

We plan to enable channel binding for LDAP on our domain controllers. Since the firewalls use LDAP for querying AD information from the domain controllers, do we need to make any configurations to the firewalls to be compatible?

Captive portal auth with Client Certificate as first auth method and local auth as fallback

Hello team, To identify my users, I have used Captive Portal with ldap authentication profile.Then I removed the ldap from the captive protal config and added a "Certificate profile", and it works well as well. However, when I assign both an ldap profile AND a certificate profile to my captive portal configuration (Device> User Identificatio...

Rule has application any and port 3389 we see discard for application cotp

We have security policy to allow any application on port 3389.I see users are able to connect to server on port 3389. traffic log shows denied on application cotp.my understanding is that if you have application as any it should cover all the applications.why it is getting denied on app cotp for port 3389? Running PAN os 8.1.9

MP18 by Cyber Elite
  • 15173 Views
  • 9 replies
  • 0 Likes

Intrazone-default rule

Hello, I would like some advice on Palo Alto's default intrazone-default rule. Unless I have a drop any any above this rule I see IP's from all over the public internet hitting my Palo Alto and being accepted on the intrazone rule as the traffic is from zone outside to zone inside. I want all of these random public IP's to be blocked and not a...

PA restart with Internal packet path monitoring failure

We have a pair of 3220 in a cluster. Yesterday we upgraded to 10.2.9-h11 and today we faced a restart of the Active peer twice with this error: Internal packet path monitoring failure, restarting dataplane I could not find any bugs related to this in 10.2.9-h11 Any thoughts? Should we upgrade further?

Max Tunnels for GlobalProtect

Can someone help me to understand the maximum number of concurrent connections possible with the GlobalProtect Clientless VPN solution? Preferably any documentation where this is specified would be great!

mitchduf by L0 Member
  • 781 Views
  • 1 replies
  • 0 Likes

User's traffic not hitting correct security rule.

We're running into an issue where a rule that is meant to update anti-virus protection on port 443 is slipping through and being caught by a lower rule which denies any application and service. (Hardware: PA-5050, OS version : 8.1.6).As far as the security rule is concerned, we have mentioned FQDNs as the destinations (instead of IPs & URLs)...

transfer the vm panorama to the nutanix

Hello Customers are using VM Panorama for VM-ware.Sooner or later, however, the customer will replace the vm-ware with a nutanix.VM Panorama version : 8.1.6VM Mode : VMWare ESXi 1. Can I get an image of a VM Panorama in use and use it in Nutanix?2. Will the log stored in the existing vm panorama be maintained if only the image is taken?3. Can ex...

ttak87 by L1 Bithead
  • 4380 Views
  • 3 replies
  • 0 Likes

Activating Trial license to extend PaloAlto working environment

Hi, community Does anyone has any experience Activating "Trial Licenses"? If let's say our support for PA-FW ends in 10 days and we would like to extend working-period is it possible to use "Trial Licenses"? I know we can use them only once, but we don't know if we can use them before the official support-end to extend them for trial period? If ...

Port Hopping - Is it for defence or Attack ?

I was just going through Tactics, Techniques, and Procedures (TTPs) and saw port hopping and still confused is it for defence or attack. If port keeps changing randomly then how would the connection stay connected?. Please share any article that explains clearly about port hopping or any easy way to understand. #Portmapping #CybersecurityFun...

  • 24335 Posts
  • 124 Subscriptions
Top Solution Authors
Labels