General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PAN OS 8 displaying multipe threat/anti virus versions

Hey folks.

 

I don't know if this is intentional or not, but it's annoying as hell, and if it's configurable, I'd like to know hwo to fix it.

 

Since upgrading to Pan OS 8 on one of my PA's (a 500), I've noticed that when I check for dynamic updates, I g

...

threat_display.jpg
darren_g by L4 Transporter
  • 2190 Views
  • 3 replies
  • 0 Likes

CLI commands for Palo Alto configuration

Hi,

 

Are there any CLI commands which we can use to assess all the checks listed in the CIS Palo Alto Firewall 7 Benchmark?

 For Example:

Check : Ensure 'Minimum Password Complexity' is enabled

 

Navigate to Device > Setup > Management > Minimum Password

...

Arti_K by L1 Bithead
  • 5484 Views
  • 5 replies
  • 0 Likes

Integrating Minemeld with TheMediaTrust

There is a current miner prototype for themediatrust, and the comment from the .yml file indicate that you need a valid TMT DTI API Key to use this Miner.   How do you configure this DTI Key in the Config section from the New Local Protoype page?

 

 

Th

...

jcornell by L0 Member
  • 2127 Views
  • 1 replies
  • 0 Likes

Palo Alto and Cisco ISE packet issues

Hi 

 

ive got an issue when a user connects on our VPN using the global protect client the connection will take nearly a minute to connect and in the backgroup create several failures on our Cisco ISE RADIUS server, before finally let the user connect.

...

Resolved! SSL decryption alert or log

Hi

 

We use SSL decryption and from time to time we have issue with web sites and apps not working because we are decrypting their traffic.

 

If its a web site that doesnt like ssl decryption most of the time the end user will get the relevant response p

...

Resolved! Failed to Initiate Phase 0 (ID population)

Hi community,

 

Does anyone already saw this commit error and knows how to solve this issue without doing a simple reboot?

 

 

PAN-OS 8.0.7, Apps&Threats 773

 

Regards,

Remo

20180203_185654.png
Remo by L7 Applicator
  • 6128 Views
  • 1 replies
  • 0 Likes

Commit limits

Hi Guys,

 

We are running scripts to push configurations into the firewalls. Everything is done via CLI and with set statements (I know that it is odd, but that's the way it is). Does anyone know are there any limits on the configuration size because s

...

Content in TS-files ?

I've been trying to find infoirmation on what the content of the TS-files are.
Reharding GDPR; does it contain information about the company's users and their behaviour (ie traffic-/URL-logs) ?

pivvre by L2 Linker
  • 1194 Views
  • 0 replies
  • 0 Likes

ICMP gets dropped by DEFAULT DENY ANY ANY

Source IP: x.x.172.230

Source Zone: int-fw

 

Destination IP: x.x.20.50

Destination Zone: DMZ

 

Requirements: SRC and DST IPs should be pinged bi-directionally.

 

Scenario:

- I've allowed the traffic using ICMP, ICMP-0, ICMP-8, PING bi-directionally but still

...

mcjyrnn by L1 Bithead
  • 5842 Views
  • 11 replies
  • 0 Likes

IPSec VPN- Layer 2

Hello,

i'm using this ressource to configure Site-to-Site IPSec VPN in Layer 2 with a PA-200.

Of course, it's not working this is why i'm here with a lot a questions.

edit: it's working now

 

1/ i'm assuming the left part of the diagram is considering as

...

  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels