General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 478 Views
  • 0 replies
  • 2 Likes

Resolved! Copy config from live PA820 to old PA500

We recently got a PA820 in live production and I'm concerned if we have a device failure that it may be difficult to take a saved config from the PA820 and import it into the old PA500.  Does anyone have any experience with this?  Is it even possible

...

Nickzzz by L1 Bithead
  • 3816 Views
  • 6 replies
  • 0 Likes

Resolved! Mindmeld Installation issues

Hey guys, having issues with fresh installs of Minemeld. I've had success installing it on a test virtual box however this time I'm deploying in a VMware environment.

 

This is the message that I get. I've tried removing the packages for clean install

...

vdnguy2 by L1 Bithead
  • 4226 Views
  • 3 replies
  • 0 Likes

PA-5020 factory defaults

Hello!

 

I have 2 PA-5020 with 5.0 software and want to upgrade them to 8.0. One way to do this is to follow upgrade procedure.

 

Configuration is very simple and can be deleted.

 

Is it possible to upload 8.0 software using GUI, boot firewall in maintenan

...

mkopcic by L2 Linker
  • 1831 Views
  • 1 replies
  • 0 Likes

MTU Packet counter increases during packet capture

Hi

 

Doing some analysis and whilst doing a packet capture I notice that flow_fwd_mtu_exceeded  starts increasing rapidly.

 

Any ideas?

 

Thanks

David

show counter global filter packet-filter yes

 

flow_fwd_l3_ttl_zero                   15996        0 drop  

...

OCSP responder question

When you generate a certificate for your login page on the Palo Alto and it is signed by a self signed CA... if you created an OCSP reponder should that responder be added to the certificate when you create that certificate for the Palo Alto login pa

...

Resolved! Debug question (Debugs turned on)

Let's say different techs have applied debug commands in the past.

 

Eg: Someone two weeks ago set the debug user-id on debug comand.

 

Now he/she forgot to set the  "debug user-id off"

 

Is there a comand to see which debugs are turned on?

 

Thanks.

 

Luis

lestrada by L0 Member
  • 3383 Views
  • 2 replies
  • 0 Likes

Resolved! Activate a new GlobalProtect Client?

Hello folks,

 

Another first for me this week.  Before we upgrade our PANOS, I wanted to activate a new GlobalProtect client first.

 

It says here that it will download new client when users connect.

 

Is that true?  Will it download and install (upgrade)

...

GPUpdate.jpg
OMatlock by L4 Transporter
  • 10352 Views
  • 8 replies
  • 0 Likes

Design suggestions

We are trying to implement SSL offload using proxy gor our hosted websites, so they can be inspected by firewalls. Management currently is more alligned to SSL offload by proxy rather than decryption by FW and it is working the way below. But with th

...

image.png
raji_toor by L4 Transporter
  • 2164 Views
  • 3 replies
  • 0 Likes

Resolved! Multi hop DHCP relay

Hi

 

So I want to get my VOIP phones to dhcp to the vPBX.

 

Phone are on a vlan in the office vPBX is in the DC

 

so vlan for phone -> PA -> vlan -> arista switch -> vlan -> PA (clustered A/A) -> vlan -> vPBX

 

So I can setup DHCP relay on the first PA and I

...

Exclude threat from alerting on IPS

How can I effectivly remove alerts for specific threats on our IPS tap?

 

There are some that we are aware are actualy trivial and can't be fixed but cause a lot of alerts.

 

Is simply adding it as an Exception on the Vulnerability Profile enough?  I tri

...

Allow all shorteners

Good morning,

 

Is it possible to allow all shorteners (bit.ly, goo.gl...). But only shorteners.

 

There isnt any category for this..

 

Regards.

MineMeld not loading after installation

After succesfol installation of MineMeld in a Debian9, by using this article: https://github.com/PaloAltoNetworks/minemeld-ansible

 

When accessing to HTTPS://IP_Address it stays forever loading (showing the loading "M"). I can't see any error in the

...

MarcelST by L3 Networker
  • 2674 Views
  • 1 replies
  • 0 Likes

Virus/spware download blocked but no threat logs

Hi

 

When users are accessing internal portal then they are getting "Virus/spware  download blocked" on browser with file name (althrough they are not accessing this file) but there is no virus/spyware logs in threat monitor tab.

 

Any pointers how to fi

...

  • 23707 Posts
  • 110 Subscriptions
Top Liked Authors
Labels