General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 483 Views
  • 0 replies
  • 0 Likes

Resolved! How to export sample miner from minemeld app in autofocus

Hi experts,

 

I have a customer who uses Autofocus with Minemeld and, uses splunk. 

This customer is using two minemeld. One of Minemeld is from Autofocus app and, another is Standalone Minemeld deployed on Splunk. 

 

but, I found out difference numb

...

stand.jpg
clould.jpg
jilim by L1 Bithead
  • 4518 Views
  • 1 replies
  • 0 Likes

Destination NAT not working

Hello all,

 

I am having issues with my NAT config. I have everything from this doc completed but not seeing any traffic hit my outside interface in the logs.

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/networking/nat/nat-configurati

...

NAT.PNG
policy.PNG

Resolved! GlobalProtect and general Internet access?

Hey folks,

 

Using PAN-OS 7.1.15 and Globalprotect client 4.0.1.

 

Trying to confirm something.  From what I can tell, when connected to VPN via GlobalProtect, my general internet access goes through the VPN tunnel route successfully (after security rule

...

OMatlock by L4 Transporter
  • 10415 Views
  • 12 replies
  • 0 Likes

List of Service Accounts

Does anyone have a running list of service accounts used/needed for best practices?

 

User-ID (per domain or per domain trust)

LDAP profile (per domain for Group Mappings)

 

What else?

mike406 by L2 Linker
  • 1775 Views
  • 1 replies
  • 0 Likes

Resolved! SNMP Paloalto

Hello !

 

I want to do snmp polling to a palo alto firewall, but not using any management "software" (like zabbix). I'm trying to do it via bash command snmpget, in which i pass the object OID 1.3.6.1.2.1.25.3.3.1.2.1 (CPU util on the management plane)

...

DanielVe by L1 Bithead
  • 3724 Views
  • 3 replies
  • 0 Likes

Max session age?

Quick question here.  If there is a perfect TCP or UDP session that is just sending stream data for example (say, an IP camera feed to a DVR server) and there are no app hiccups or dropped packets - is there a max session age for this condition?  I c

...

dberber1 by L2 Linker
  • 2744 Views
  • 3 replies
  • 0 Likes

Resolved! PA inbound decryption

PA drop (decrypt-error, policy-deny) packet when client present a certificate (SMTP STARTTLS).

 

PAN OS version: 8.1

 

Test cases

 

1) Client cert TRUSTED, TLS 1.2 with ECDHE-RSA-AES256-GCM-SHA384

 

Client send Certificate Verify TLS payload

 

openssl s_client

...

decrypt-error.jpg
decrypt-error2.jpg
decrypt-ok.jpg
decrypt-ok2.jpg
blabla by L2 Linker
  • 7087 Views
  • 8 replies
  • 0 Likes

Dataplane increment from 07/03/2018

Hi,

 

We realised that we have had an increment in dataplane from 07/03/2018. Before this day the normal value was 42% aprox. After that day the normal value is incremented to 58%. So we would like to know the reason for this increment.

I check "resourc

...

Resolved! Panorama fails to deploy PanOS to Firewalls

We have a Panorama (M-100) managing several PA5020 firewalls. We need to update the PanOS from 6.1.7 to 6.1.10 (don't push for higher this is all we can do for now). I've updated the Panorama to the 6.1.10 version. Now i try to use the deployment sof

...

Resolved! Any 'Bards' up for a poetic challenge?

It doesn't always need to be hard work and no play, some fun distractions should be part of the job 

 

Therefore I'm calling on all the bards among you (poet warriors in case you never played AD&D  ) to have a swing at a geeky or funny limerick and

...

reaper by Cyber Elite
  • 3137 Views
  • 2 replies
  • 6 Likes

Resolved! User ID agent user-IP mapping refresh evets

Hi Experts

 

As you know the default cache time for user-IP mapping in user-ID agent is 45 minutes. If I am not using WMI or netbios or server session monitoring then:

 

1- How user-IP mapping can be maintained by user-ID agent? This means user has to lo

...

  • 24089 Posts
  • 116 Subscriptions
Labels