Cortex XDR Prevent, URLs
Good afternoon, it is possible from Cortex XDR Prevent to block access to specific internet URLs. Or failing that by category?
Good afternoon, it is possible from Cortex XDR Prevent to block access to specific internet URLs. Or failing that by category?
We have forward proxy (ssl decryption configured) We are having intermittent access to some webpages users have to reload the page to gain access.We are seeing General TLS Error on the decryption logs under Error. What Iv found out about the error is that This message indicates that an error doesn't meet the criteria for any of the afo...
Hi, I had a strange behaviour with some user on user ID. We have 2 site A and B and our firewall have the mapping from the same agent. we found that user1 access site A and user2 access site B. issue that we found that user1 is access site B using the user2 IP. We check on each site the mapping is fine, but we dont find the user1 mapping ...
We're having some strange SSL/TLS Inspection errors while on GlobalProtect. We are getting unsupported-parameter errors while a user is connected to GlobalProtect trying to get to any internet site, including things like google.com. Doing a packet capture on the firewall it shows the connection trying to happen on tls 1.0 which we do indeed not ...
Is there a way to allow ping on a rule that has another application that uses a non-standard port? So for example, if yum uses port TCP 3142 instead of its default tcp/80,21 is there a way I can attach ping to that rule and still have it work? Like on Cisco ASAs you can add icmp as a port/service. Example that doesn't work: Example that does work:
Hi, could you help me?I should make a release change from version 10.2.7-h8 to 10.2.11-h2for palo alto 3440. The two firewalls are in HACan you tell me the various release jumps I should do and if there is a procedure to follow?
Hi All, if there's a way how to reduce or minimize the log size sent to the syslog server? if any KB / document / best practice how to reduce logs to sent to syslog server Thank you
Hi, I have a problem to deactivate bundle license, because it is... bundle license. Cannot deactivate license key Advanced_Threat_Prevention_2023_11_13.key which is part of bundle without parent_id attribute. What is parent_id attribute and how to find it? where in configuration I can use it? how to deactivate bundle license?
We have identified for some time that when rules are created with 'Application: Any' + 'Destination Address: Any' + 'UrlCategory: Custom' for example: Name: Rule_google.com_permitSource Zone: TrustSource Address: AnySource User: AnyDestination Zone: UntrustDestination Address: AnyApplication: AnyService: 443-tcpURL Category: URLC_Google.comURL F...
Hi folks I am having issues with access via ssh from macos/ linux pcs pc ~ % ssh [email protected] Unable to negotiate with 10.10.10.1 port 22: no matching host key type found. Their offer: ssh-rsa ...
Hi, I need to take the uuid and cpuid from Panorama, but when i run "show system info" its not appears these paramethers. How can i get these uuid and cpuid to transfer the license?????? My PanOs version is 5.1.0 hostname: Panoramaip-address: 192.168.22.191netmask: 255.255.255.0default-gateway: 192.168.22.10ipv6-address:ipv6-link-local-add...
Здравствуйте как настроить Palo Alto pa 440 как bridge без айпи адресов можете помочь
Hello,I want to ask regarding this topic https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158Do I have to upgrade the version of PaloAlto ? The version I have is 10.2.4-h3 ? do I need to upgrade this version ? so not to have problems ? Best regards,
Enterprises are embracing AI to revolutionize their operations, but with innovation comes new cybersecurity challenges. That’s why you can’t miss Ignite on Tour! This event is your gateway to exploring how AI is transforming cyber defenses. Join us to: Defend Against AI-Driven Attacks Secure Employee Usage Protect AI Development Simplify Cy...
Hello, I have noticed the EDL Tor Exit IP Addresses includes only over 1200 entries and the total list of exit nodes is over 12000: https://www.dan.me.uk/tornodes I was wondering based on what criterion Palo Alto is updating the EDL. Does anyone know this? Just because the EDL doesn´t reflect not even near the total number of IPs. Thank you!
| Subject | Likes |
|---|---|
| 4 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like | |
| 1 Like |
| User | Likes Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

