General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

SSL decryption non standard ports

Hello all, I am wondering if palo can identify and decrypt encrypted traffic on non-standard ports(other than 443)? In other words, does firewall decrypt all encrypted traffic traversing through that matches rule?

Resolved! show user group name not showing user list

Hello, We are not getting the list of individual users in the command: show user group name <name> > show user group name "CN=adminstaff,OU=staff,OU=security,OU=Groups,OU=College,OU=Schools,OU=CEWA,DC=test,DC=edu,DC=au" short name: test\adminstaff source type: ldapsource: TEST_AD_Groups We can see them in the Webgui. We followed t...

Farzana by L4 Transporter
  • 9355 Views
  • 1 replies
  • 0 Likes

PAN-2020 site-to-site with Meraki Cloud managed firewall

Hi all,Has anyone had success establishing a site-to-site tunnel between an PAN firewall and a Cisco Meraki Cloud managed firewall? I've been messing with it for most of the day and have not found much luck. I've added a third party peer on the Meraki, but it doesn't seem to make any connections back to PAN even an attempt to establish the tun...

cmateam by L3 Networker
  • 10435 Views
  • 7 replies
  • 0 Likes

Resolved! Configuring OCSP

I am trying to configure OCSP and I am a little confused. I have added an OSCP responder. It appears the second step is to allow the Firewall to use it by configuring Device-Management->Interfaces. However, for most of my settings, I am using a Service Route Configuration and I don't see HTTP OCSP listed as an option in Service Route. Is ...

Resolved! Minemeld with Proxy

Is there any way to perform the minemeld install from behind a proxy? I am deploying a minemeld node in a datacenter where internet access is only available via squid proxy. Thanks,Nasir

nbilal by L3 Networker
  • 20251 Views
  • 12 replies
  • 0 Likes

VPN SITE TO SITE PALO ALTO NETWORKS

Hello, I configure a VPN tunnel between two firewalls Palo alto Networks . The tunnel status is up but the other network is unreacheable.I configure the tunnel on the trust zone . I restart the firewalls without result . The first PA-500 with PANOS 7.1.0 and the second with PANOS 8.0.3Should I do an upgrade to the OS? Or there is any suggestion ...

ra7oub4 by L2 Linker
  • 10067 Views
  • 7 replies
  • 0 Likes

Error : Number of addresses ,dynamic groups, external-ip-lists.... exceeded platform capacity (2500)

While pushing policy from PAN to PA220 Firewall running 8.0.3I am getting attached Error. We have around 6kplus object in that specific template.As per PA support, 8.0.X pan version comes with a precheck that will not allow commit till the object count be below 2500 value for PA220.My Query...1. Does all objects get pushed from PAN irrespectivel...

Nischal by L2 Linker
  • 7712 Views
  • 2 replies
  • 0 Likes

Exception for threat type "file"?

Hi, I have following in my logs: Threat tpye: fileThreat name: CSV fileID: 52032Severity: lowFile Name: xyz.csv For Vulnerability Protection and Anti-Spyware I know how to easily create exceptions for specific IPs/URLs. Is there a way to easily create exceptions the same way for "file threats"?Furthermore I'm not aware that my file blocking prof...

Installing a pair of 850s and a pair of 3260s this weekend - interface speed

We have had some requirements change since ordering this equipment and may change direction on where these new firewalls get installed. Initially we ordered the 3260s for our hosted data center since most of the servers are located there and vendor provided backup solution is there. The concern was the amount of traffic that we would be pushing ...

Resolved! HA2 Backup Port Link Speed

Does the HA2 backup port need to be the same link speed as the primary HA2 port? Customer is wondering if it is possible to use a 10G SFP+ port to backup the 40G HSCI port. I cannot find anything in the documentation discussing this and don't currently have access to the hardware to test. Thanks.

User-ID Service - Client IP Population

All, When we first installed our User-ID Agent service on Windows Server 4-5 years ago we implemented Security Log Reading (from domain controllers logs), AD Session Scanning, and MWI polling. About 5-6 days ago we started running into issues (which we have yet to determine what is causing it), where polling seems to be openeing up multiple con...

problem after upgrade with Task Manager

Hello,After upgrade panorama from 8.0.6 to 8.0.8. the Commit All operation stopped showing the progress bar in the Task Manager.the Status colon in the Task Manager shows "Completed" and the "End Time" colon shows the exact date and time as the "Start Time" colon. Someone know if this is a problem for this release?

Marivi by L2 Linker
  • 2567 Views
  • 1 replies
  • 0 Likes

Resolved! Stable MineMeld version and new Office 365 API

Hi guys, I'm using Minemeld 0.9.44.post1 and would like to test the new prototype O365 API MINER, since microsoft decided to change the way they publish IPs and URLs. I know that the development version of Minemeld (0.9.46) already comes with it, however I would like to maintain my stable version and only get the mentioned prototype to test. Is ...

Resolved! how are files forwarded to wildfire?

Please help me understand how files are forwarded to wildfire public cloud and how secure is the connection between firewall and wildfire cloud?Also, my understanding is that firewall hashes every file it encounters against its databse(local) and lookups for new hash info on cloud whenever a policy hit occurs for wildfire.Am I correct? TIA

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels