General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

General TLS protocol Error

We have forward proxy (ssl decryption configured) We are having intermittent access to some webpages users have to reload the page to gain access.We are seeing General TLS Error on the decryption logs under Error. What Iv found out about the error is that This message indicates that an error doesn't meet the criteria for any of the afo...

image.png
Salathiwe by L3 Networker
  • 6391 Views
  • 4 replies
  • 0 Likes

User ID Anomalies

Hi, I had a strange behaviour with some user on user ID. We have 2 site A and B and our firewall have the mapping from the same agent. we found that user1 access site A and user2 access site B. issue that we found that user1 is access site B using the user2 IP. We check on each site the mapping is fine, but we dont find the user1 mapping ...

DennyChanditya_0-1729151292634.png
DennyChanditya_1-1729151338014.png

Resolved! SSL Inspection issues with GlobalProtect users

We're having some strange SSL/TLS Inspection errors while on GlobalProtect. We are getting unsupported-parameter errors while a user is connected to GlobalProtect trying to get to any internet site, including things like google.com. Doing a packet capture on the firewall it shows the connection trying to happen on tls 1.0 which we do indeed not ...

Claw4609 by L5 Sessionator
  • 41351 Views
  • 23 replies
  • 1 Likes

Resolved! Ping and other Applications in the same rule on a non-standard port

Is there a way to allow ping on a rule that has another application that uses a non-standard port? So for example, if yum uses port TCP 3142 instead of its default tcp/80,21 is there a way I can attach ping to that rule and still have it work? Like on Cisco ASAs you can add icmp as a port/service. Example that doesn't work: Example that does work:

bafergel_0-1632856860628.png
bafergel_1-1632856909682.png
bafergel by L2 Linker
  • 5562 Views
  • 3 replies
  • 0 Likes

Resolved! Upgrade from version 10.2.7-h8 to 10.2.11-h2

Hi, could you help me?I should make a release change from version 10.2.7-h8 to 10.2.11-h2for palo alto 3440. The two firewalls are in HACan you tell me the various release jumps I should do and if there is a procedure to follow?

F.Basco by L0 Member
  • 2397 Views
  • 3 replies
  • 0 Likes

Minimize log size

Hi All, if there's a way how to reduce or minimize the log size sent to the syslog server? if any KB / document / best practice how to reduce logs to sent to syslog server Thank you

deactivate bundle license from PA1410

Hi, I have a problem to deactivate bundle license, because it is... bundle license. Cannot deactivate license key Advanced_Threat_Prevention_2023_11_13.key which is part of bundle without parent_id attribute. What is parent_id attribute and how to find it? where in configuration I can use it? how to deactivate bundle license?

Problem with (URL Category custom), (Destination Address any) and (application any)

We have identified for some time that when rules are created with 'Application: Any' + 'Destination Address: Any' + 'UrlCategory: Custom' for example: Name: Rule_google.com_permitSource Zone: TrustSource Address: AnySource User: AnyDestination Zone: UntrustDestination Address: AnyApplication: AnyService: 443-tcpURL Category: URLC_Google.comURL F...

Migrating Panorama license from VM to another

Hi, I need to take the uuid and cpuid from Panorama, but when i run "show system info" its not appears these paramethers. How can i get these uuid and cpuid to transfer the license?????? My PanOs version is 5.1.0 hostname: Panoramaip-address: 192.168.22.191netmask: 255.255.255.0default-gateway: 192.168.22.10ipv6-address:ipv6-link-local-add...

regarding upgrade certificate on 18 NOV

Hello,I want to ask regarding this topic https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158Do I have to upgrade the version of PaloAlto ? The version I have is 10.2.4-h3 ? do I need to upgrade this version ? so not to have problems ? Best regards,

Zurattos by L1 Bithead
  • 1027 Views
  • 1 replies
  • 0 Likes

🚀 Join us at Palo Alto Networks Headquarters for Ignite - November 14, 2024 🚀

Enterprises are embracing AI to revolutionize their operations, but with innovation comes new cybersecurity challenges. That’s why you can’t miss Ignite on Tour! This event is your gateway to exploring how AI is transforming cyber defenses. Join us to: Defend Against AI-Driven Attacks Secure Employee Usage Protect AI Development Simplify Cy...

emgarcia by Community Team Member
  • 2229 Views
  • 2 replies
  • 4 Likes

How EDL Tor Exit IP Addresses is updated?

Hello, I have noticed the EDL Tor Exit IP Addresses includes only over 1200 entries and the total list of exit nodes is over 12000: https://www.dan.me.uk/tornodes I was wondering based on what criterion Palo Alto is updating the EDL. Does anyone know this? Just because the EDL doesn´t reflect not even near the total number of IPs. Thank you!

Carracido by L4 Transporter
  • 4590 Views
  • 3 replies
  • 0 Likes
  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels