General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! How to configure a specific event to be sent via email

Hi Guys,

How would I go about configuring my PA to email me everytime another device with the same IP address of the Palo Alto joins the network, please? I didn't want anything else to be emailed to me, just that particular event. I remember I was abl

...

sonivEX by L0 Member
  • 2228 Views
  • 3 replies
  • 0 Likes

H/A Clustering Query

Hi,

 

I have a query regarding H/A clustering, I potentially have a requirement for H/A clustering with 3 firewalls and not just 2 (i.e. Active/Standby or Active/Active).

 

I believe that presently a 3 firewall cluster is not currently supported however

...

Data Plane high PA - 5020

i have problem about data plane, and the TAC say : packet rate is high, but i cannot find, how much PA-5020 can handle packet rate maximum.

i use command "show system statistic sessio" packet rate is 130K - 150K and dataplane 77% at 11:00 AM, but i se

...

Block recently registered domains

Is anyone successfully blocking domains that have been registered recently (last 30 days)? My testing has shown in the last three days, 380k domains have been registered. My PA-3020 capacity for External Dynamic Lists only supports a total capacity o

...

ASCIT by L2 Linker
  • 3534 Views
  • 5 replies
  • 0 Likes

Resolved! Download PAN-OS from GUI failing, potential MTU Problem ...

Ok folks

 

Here's an interesting one for you.

 

This is to do with connectivity between Panorama and updates.paloaltonetworks.com

 

We can retrieve licence info and download list of updates available for downloads (SW and Threats), but when clicking on dow

...

nawaza by L2 Linker
  • 2839 Views
  • 3 replies
  • 0 Likes

Resolved! Zone protection show wrong severity

We are doing a lab and making test attacks and see if the PA can detect them, we have an interface in tap mode and it is doing the span, we did all the configurations in a PA-200 but when we lunch brute force attacks or sql injection,  the logs shown

...

RCastro by L1 Bithead
  • 2161 Views
  • 3 replies
  • 0 Likes

Dynamic NAT

We are moving NAT from the routers to the firewall (5050), the routers do not release the session's efficiently so we are constantly running out of IP's in the pool. Is there a rule of thumb for the number of IP's to sessions on a PAN 5050? We run at

...

GFN182 by L2 Linker
  • 1904 Views
  • 2 replies
  • 0 Likes

Best Practices of log filter

Hello,

 

 

As a network admin, when user escalates that he cannot access some specify website, what's the best way to find the property log which was triggered by use's browsing activity?

 

Of course we can apply filer as "username", but even though, we w

...

qd_056 by L2 Linker
  • 3298 Views
  • 5 replies
  • 0 Likes

Log forwarding, filtering and auto tag

Hi there

 

I've played with this feature for a while on my own FW, but must be doing something wrong. I'm adding the log forwarding profile, and when checking the filter I make, I get many log lines. But I don't get any output in the DAG. I've tried wi

...

gtomte by L3 Networker
  • 5164 Views
  • 5 replies
  • 0 Likes

PAN OS 8 displaying multipe threat/anti virus versions

Hey folks.

 

I don't know if this is intentional or not, but it's annoying as hell, and if it's configurable, I'd like to know hwo to fix it.

 

Since upgrading to Pan OS 8 on one of my PA's (a 500), I've noticed that when I check for dynamic updates, I g

...

threat_display.jpg
darren_g by L4 Transporter
  • 2315 Views
  • 3 replies
  • 0 Likes

CLI commands for Palo Alto configuration

Hi,

 

Are there any CLI commands which we can use to assess all the checks listed in the CIS Palo Alto Firewall 7 Benchmark?

 For Example:

Check : Ensure 'Minimum Password Complexity' is enabled

 

Navigate to Device > Setup > Management > Minimum Password

...

Arti_K by L1 Bithead
  • 6105 Views
  • 5 replies
  • 0 Likes

Integrating Minemeld with TheMediaTrust

There is a current miner prototype for themediatrust, and the comment from the .yml file indicate that you need a valid TMT DTI API Key to use this Miner.   How do you configure this DTI Key in the Config section from the New Local Protoype page?

 

 

Th

...

jcornell by L0 Member
  • 2208 Views
  • 1 replies
  • 0 Likes

Palo Alto and Cisco ISE packet issues

Hi 

 

ive got an issue when a user connects on our VPN using the global protect client the connection will take nearly a minute to connect and in the backgroup create several failures on our Cisco ISE RADIUS server, before finally let the user connect.

...

  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels