General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Autofocus threat indicator timestamp does not tally with Minemeld logs

Hi all, Got a question regards to the time stamp seen on Minemeld logs then I mine samples from autofocus. Take for example, from AF-Ransomware Node in mine meld, I can see a particular hash having a "first seen" and "last seen" with a format of "1531114747953", however, when I search the SHA 256 hash using Autofocus search feature, the "Creat...

chtoh82 by L2 Linker
  • 6045 Views
  • 3 replies
  • 0 Likes

PAN-OS upgrade problem for google web services

Hi everyone i got the problem for the PAN-OS upgrade from 6.1.X to 7.1.1X, the environment deploy SSL decrypt already, also had security profile include URL-filtering, Anti-virus, Anti-spyware, vulnerability, it like normal use, but when i finished upgrade palo alto appliance, we cannot succeed running google services like google-maps, google-tr...

TysonLiu by L2 Linker
  • 8721 Views
  • 10 replies
  • 0 Likes

Resolved! Session ID 0

Hi , When checking monitoring logs very often especially with ICMP, I come across" Session ID 0" and unable to find any information for the same using CLI . This throws error message as Session ID should start with 1. Not sure, why only WebGui displays as 0. Please assist. admin@PA> show session id 00 should be between 1-2147483648Inv...

PA11.JPG

PAN Hardware & PAN-OS ver. for ACE and PCNSE Certification

Hi all, I'm looking to study for and pass PAN Accredited Configuration Engineer certification and perhaps PCNSE down the road but would like to know what PAN hardware & PAN-OS version software I should get my hands on to help me out. To give some background, I hold CCNA R&S and CCNA Sec and I don't know what ACE and PCNSE would be equiva...

Resolved! Getting "Initializing minemeld...." after upgrade to 0.9.48. Logs, other values not updating

We are running MineMeld on an Ubuntu VM. I upgraded minemeld using ansible. I ran into a glitch the first time I tried the upgrade, and I had to revert to a VM snapshot. I retried the upgrade and all seems ok except when I ssh to the device I always get the "Initializing minemeld. It could take some minutes, please wait ....". I have to do ctl-...

alterioc by L2 Linker
  • 4763 Views
  • 1 replies
  • 0 Likes

MineMeld SIEM integration error

Good morning, we are trying to integrate MineMeld with IBM Qradar but we configured the threat intelligence app in Qradar. We configured the taxi URL: https://X.X.X.X/taxii-discovery-service but when we navigate on it we received the error: 405 Method Not Allowed. Anyone have just deal with this error? thank you

o365 api miners not working - 0.9.48 Ubuntu VM

Running Minemeld on Ubuntu VM. I upgraded from 0.9.44 to 0.9.48 to get the o365 api miners. The API miners fail with "Bad Request" I tried restarting the API but that did not resolve the issue. Can someone advise me on what to do to fix this problem? Thank you

BadReq.JPG
badreq2.JPG
alterioc by L2 Linker
  • 3239 Views
  • 1 replies
  • 0 Likes

Regex for Chromebook Username

Hello all! We have a little hiccup with our chromebook integration. The issue is, when a user logs in, the info is reporting to the PAN as "domain\john_smith". The PAN is setup to read users as "domain\john smith" so it tags the user incorrectly and applies the incorrect policies. Is there a way to use regex to parse the username and if an "_" ...

Screen Shot 2018-07-19 at 9.45.41 PM.png
jcalzada by L0 Member
  • 3964 Views
  • 3 replies
  • 0 Likes

Traffic Logs not showing up on Monitoring Tab

Hi All, Device Type: PA-220Software Version: 8.0.11-h1 Im having an issue with old traffic logs not showing up on the monitoring tab. I can see live logs but if I want to check the logs for the previous day or previous 2 days then nothing shows up. It only goes back to a certain time. We have cleared all the logs on Friday 13 July so that it can...

Error fetching External Dynamic List (EDL)

Hello, When trying to fetch an EDL from a web server configured without support for TLSv1 (only support TLSv1.1 or 1.2) the result is "Server error : URL access error". I don't know if PAN-OS 7.1.18 fetch client for EDL only support TLSv1. Checking ciphers compatibility for 7.1 I can't find the answer: https://www.paloaltonetworks.com/documentat...

fjmjugr by L1 Bithead
  • 7817 Views
  • 6 replies
  • 0 Likes

Resolved! requesting connection status via code or through CLI

Hey there, I'm designing windows 10 app which needs to connect to a office based database via a remote laptop.The laptop will have access to the office through the GlobalProtect VPN.I need a way to query the GlobalProtect windows agent to see if there is an active VPN connection so I can start making database calls or use locally stored data.Any...

Asymmetric Routing and TCP syn check (Pulukas Solution)

Hi Everyone, Asymmetric Routing and TCP syn verification is a common issue and there were many articles on how to resolve that, basically1 - To change routing itself and make sure there are no asymmetric routing in the network - best from PA point of view2 - disable tcp syn verification globally on the firewall - worst for PA 3 - Disable tcp syn...

Dimitrus by L0 Member
  • 4623 Views
  • 2 replies
  • 0 Likes

Support for inspecting SSL message for kafka connect

We are using Kafka for messaging and have a requirement to inspect the SSL message sent to kafka broker from kafka connect. Kafka using binary tcp protocol with kafka broker listeners on PLAINTEXT://9093 (without SSL) Can paloalto decrypt and inspect the kafka message content?

  • 24429 Posts
  • 125 Subscriptions
Top Solution Authors
Labels