General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Zone available in template stack but not available in policy

Issue Description Specific zone which created in global template is available in one stack but unavailable in other, though this global template is part of their stack. Config detailsEach firewall has their own stack, template and 1 common global template zone created on global template is available on both stackspa_3050_stack(firewall1)pa_vm(...

2018-05-03 10_12_10-Panorama.png
2018-05-03 10_12_54-Panorama.png
2018-05-03 10_13_06-Panorama.png
2018-05-03 10_13_28-Panorama.png

Resolved! New site to site VPN creation with same proxy IDs

HiI have a HQ PAN connecting to a remote ASA and IPSec is up with static routes and proxy IDs. Have installed and configured a new PAN parallel to remote ASA which is going to be replacing itQuestion is, can i have a new VPN configured in HQ to new remote PAN, where the proxy IDs will be same as the operational one? The remote IP for PAN is diff...

mhamid by L1 Bithead
  • 3443 Views
  • 2 replies
  • 0 Likes

Resolved! MT v3.3.15 doesn't appear to import/upload PANOS xml file from my PA-820 running v8.0.7

I was trying to Upload a Panos XML file that I saved from the PA-820 to MT v3.3.15, but when I go to the "Zones" side-tab from the "Manage Networks, Routing, Zones", etc icon, I didn't see any of my existing zones. The upload action actually didn't appear to do anything except display a link to "media.paloaltonetworks.com/Ip/endpoint-security/"...

Resolved! Panorama and Solarwinds SCP for Scheduled Backups

I have SCP running on windows host, Solarwinds Can I please ask if anyone has this working successfully?. Palo support seem to suggest that the SCP server needs to be Linux host Thank youAjaz NawazJNCIE-SEC No.254CCIE-RS No.15721

nawaza by L2 Linker
  • 7325 Views
  • 5 replies
  • 0 Likes

Should sub interfaces be graphed

We have aggregate interfaces under which we have created sub interfaces. The graph for aggregate inerfaces displays expected avg/min/max but the sub interfaces are displaing very unexpected avg/min/max.

image.png
image.png
raji_toor by L4 Transporter
  • 2787 Views
  • 3 replies
  • 0 Likes

Resolved! SSL Decryption - Enterprise CA

Hi Everyone, Recently a decision was made to implement SSL Decryption for outbound inspection. We work within a Microsoft PKI environment and are experiencing issues in signing the CSR generated by the firewall. I create the CSR based on the "how to implement and test ssl decryption" document I found via the Live Community (https://live.paloal...

cafowler by L2 Linker
  • 9061 Views
  • 4 replies
  • 0 Likes

What's new in MineMeld 0.9.9

Release Date: 2016-04-19 How to update: Updating MineMeld UI - new logo - new you can edit and create a local version of an existing prototype, just press NEW at the top of the prototype view Nodes - miner for JSON feeds Prototypes - prototype for AWS IP ranges, based on the JSON feed Miner (suggested by coldstone1) Engine - better de...

Screen Shot 2016-04-19 at 17.44.10.png
lmori by L7 Applicator
  • 7807 Views
  • 4 replies
  • 1 Likes

Update List Using REST \ similar

Maybe a stupid question and\or I've missed the obvious... One of the issues we have with our Palo firewalls is - when we deploy 'active' IPS rules (block-ip etc) the maximum length of time is 3600 seconds. We have a log solution that we use to trigger alerts if we're being probed over multiple days etc and would like to trigger a script, ra...

apackard by L4 Transporter
  • 20437 Views
  • 12 replies
  • 0 Likes

Deploying Minemeld Using Vagrant and Virtualbox

Hello All, Based on @lmori's great guide for doing a manual install of Minemeld on Ubuntu 14.04, I have taken his configurations and wrapped them in a Vagrantfile for easy foolproof deployment of Minemeld. It's a simple 3 step process: Install latest version of Virtualbox for your OS (Download) Install latest version of Vagrant for your OS ...

nbilal by L3 Networker
  • 13652 Views
  • 2 replies
  • 9 Likes

TAXII Feeds not working correctly.

I am having major issues with my TAXII feeds recently. A long running feed stopped working recently with an error "'unicode' object has no attribute 'get'". I have figured out that it only gives this error on any MM instances running on Trusty 14.0.4.5 that were manually installed. The cloud loader install seems to work with the same config impo...

kethomas by L1 Bithead
  • 3950 Views
  • 2 replies
  • 0 Likes

Resolved! MineMeld Speedtest.net host mining

Hi all, I managed to install MineMeld on-prem and are playing around with it now. As a first task I'd like to setup a domain feed delivering SpeedTest.net hosts from countries we deployed Palo Alto firewalls. Setting up the miner, a domain aggregator and an output worked, no problem there. We download the full hosts list from http://c.speedt...

oschuler by L4 Transporter
  • 4167 Views
  • 1 replies
  • 0 Likes

Resolved! Remote shutdown via CLI or through Panorama

Hello all,I'm tasked with initiating a graceful shutdown of mutiple PA3060 firewalls following UPS-detected mains power loss via a scripted process. I can login to invididual firewalls using plink but I can't work out how to enter the shutdown command with the confirming 'y' keystroke.Does anyone have experience of this, please?We have Panorama ...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels