General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Configure DUAL ISP

We have now two ISPs And we want to configure PA so that when first ISP is down the traffic (in and out) passed to the second ISPCan you give me please a guide about it?

Radmin_85 by L4 Transporter
  • 5894 Views
  • 10 replies
  • 0 Likes

Empty Scheduled custom CSV reports

I configured an 'Email Scheduler' for my custom reports which will be sent on a monthly basis. They will be sent correctly in .pdf format, but when I choose .csv in my 'Report Group' I receive empty .csv files. Is this a bug or a misconfigured configuration?

Resolved! Parsing of US CERT STIX files

Hi all, We have a wish for parsing the STIX file, which is provided in this alert from the US CERT: https://www.us-cert.gov/ncas/alerts/TA18-149A I have tried to research it myself, but I can't seem to find a way to do this in minemeld. Any ideas?

borising by L4 Transporter
  • 6237 Views
  • 2 replies
  • 0 Likes

Resolved! IP addresses disappearing from miner

Hello, I've created a miner to add IP address based on stdlib.listIPv4Generic and class minemeld.ft.local.YamlIPv4FT. Default configuration (just cloned). This week, some IP addresses just disappeared from this miner. We added an IP address to the miner last 21st, on the 22nd of this month the IP address disappeared from the miner. Older ind...

PA VM 6.1.0 Routing issues

Hello Experts,I am stuck with a Palo Alto test setup. I have a 6.1.0 VM version running on VMW. I have simulated the inside interface by a 10.10.0/24 subnet—- the two hosts are a **bleep** Small Linux with IP 10.10.10.190 (/24) which is connecting to the PA VM Ethernet1/1 L3 interface with IP 10.10.10.200 (/24). VMnet2 is used for managment inte...

Resolved! Firewall intercepts Virus between networks. False Positive???

Dear Palo Alto experts..., We have various systems in our LAN seperated by our Palo Alto firewall. In the last 24 hours the firewall detected 2.7K times the virus "Virus/Win32.WGeneric.rktkq" The systems are scanned for inventory by two programs. Spiceworks and PDQ inventory. The scan server is on one side of the firewall. The other servers are...

2018-05-31 10_39_51-FW-PA500-1.png
2018-05-31 10_35_11-FW-PA500-1.png

The WildFire module price

Hello, сolleagues!I am interesting in the PaloAlto and I am only starting to use it. IPlease say where can I buy subscription to the The WildFire module ?Can I buy only The WildFire subscription or I must buy smth else?If anybody know where is a page with prices - please say. I found the page with description https://www.paloaltonetworks.com/pro...

Resolved! X-forwarded-for not showing results

We use F5 with its VIP interfaces in DMZ and is doing SSL offloading (presents a cert on the webserver's behalf allowing plain text traffic to be inspected). As in below example, external source(1.1.1.1) acesses 2.2.2.2(PA NATS to 10.10.10.10 of the F5 VIP). F5 then does SSL offload and SNAT for communication with server, but the source interfa...

image.png
raji_toor by L4 Transporter
  • 6121 Views
  • 4 replies
  • 0 Likes

Resolved! Is there a protoype that can read this XML format?

Before I go down the route of writing a prototype (or attempting to), I was wondering if there was a prototype that I could use to read an IP list in this XML format. I would be interested in pulling out the address and country: <?xml version="1.0" encoding="utf-8"?> <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" ...

Running MineMeld from OVA

Good afternoon! I have a quick question about running MineMeld from the OVA. We have some pretty strict policy against installing via GitHub and, the best way for me to get MineMeld installed, would be to use the OVA method. I'm new to running it this way. After I get MineMeld up and running on this VM, can I upgrade MineMeld to the latest ...

Not having a Threat license on panos and do the AV and anti-spyware functions even work?

I am a little new to PA firewalls. My question is, with an expired Threat license, or no Threat license installed at all, is all the functionality of the AV and anti-spyware components not active? Customer has one with expired license, but I am trying to be specific on what functionality they have lost due to the expired license. Another cust...

S_Gibney by L0 Member
  • 2678 Views
  • 2 replies
  • 0 Likes

Create new prototype for Rest API and simple URL

Hi Experts, I have a customer who wants to create new prototype for this customer. customer requirement is very simple but, it's very hard to me. first of one, customer said spunk is using Rest API, below is feeds from splunk curl -k https://splunk_IP_address/services/search/jobs/export -d "search=| inputlookup autofocus_lookup" -d output...

jilim by L1 Bithead
  • 4669 Views
  • 3 replies
  • 0 Likes

RTP fragment packet flowing is not allowed when fragment enabled on zone protection of PAN-OS

Hi All, I have an issue about sip/rtp traffic. Endpoints are using a calling application that used sip protocol . We have also enabled fragment feature in zone protection setting.I investigate this issue and when endpoint make calling, zone protection drops rtp packets because they are fragmented.Could you inform me is there another solution adv...

Resolved! How do you use the new predefined Dynamic IP lists?

Greetings all, I'm wanting to use the new Palo Alto provided dynamic IP lists to block known malicious or high risk IPs but, when creating a security policy, I can't seem to get it to appear in the list for selection. I've tried copy/pasting the name in there and it just shows the red underline. I'm doing this in 8.0.7 Panorama and both of my f...

jsalmans by L4 Transporter
  • 9970 Views
  • 11 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels