General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! How to solve "CWE-693 : Protection Mechanism Failure" in Paloalto firewall

Hello Geeks, During our compliance scanning (PCI-DSS External Scanning) process on our paloalto 3020 firewalls, the scanner found new vulnerability, "CWE-693 : Protection Mechanism Failure" and suggested to fix it ASAP to comply. Hence, I started googling to solve this issues and found no useful solutions for this yet. Is there any way to solve ...

Wayne88 by L1 Bithead
  • 21662 Views
  • 7 replies
  • 0 Likes

Resolved! Blocking Web Advertisements with an External Dynamic List

Hello everyone, I am attempting to block web advertisements on our PA-3020. We have two of these devices which utilize Panorama. We have blocked anything categorized as "web-advertisement" on the firewall, which is great, but a ton of ads are still getting through. What we would like to do is as follows: Utilize an external dynamic list (a text ...

Upgrading PAN OS from 7.1.X to PAN OS 8.0.X

Hello ; We have been using PAN OS 7.1.x for months and now due to some requirements I am planning to upgrade our PAN OS to 8.0.x but not sure what the possible problems will be. Therefore, will be good if you share your ideas and comments on 8.0X and what problems you faced during the use so I can consider all these steps before taking any actio...

Ghafar by L1 Bithead
  • 4905 Views
  • 5 replies
  • 0 Likes

Quick Note on 8.1.0 Deployments

Since its release we've seen an uptick in folks deploying 8.1.0 to their firewalls, and that's a great thing. I just want to throw out a word of caution before doing so however; while 8.1.0 is one of the most stable base releases Palo Alto Networks has published, you need to do your homework before deploying this in any environment. LAB Devices...

BPry by Cyber Elite
  • 13805 Views
  • 15 replies
  • 6 Likes

Resolved! QOS and internet traffic

Can PANOS controll / rate limit internet downloads ? On my squid boxes I can ratelimit and it does this by delaying acks. Can the PA QOS do this work as well ?

Resolved! How to Change network address of running MineMeld server

Hello, I have a MineMeld server working perfectly with different nodes (O365, Zeus, etc). It has an IP address like: 192.168.1.xxx but now I want to change to a different VLAN ex: 192.168.99.xxx So what is the process to change this correctly to work again with the new IP? I tried to change the IP in /etc/network/interfaces but then the minemeld...

aitorms by L1 Bithead
  • 17903 Views
  • 6 replies
  • 0 Likes

Resolved! How-to delete a policy-based forwarding rule from CLI

I'm trying to find the correct syntax to delete a policy based forwarding rule from a PA firewall via the CLI. having a really hard time formulating this from the CLI reference. How would i do this by referencing the ID. also, this firewall is managed as part of a Panorama template. would i need to use the 'override deviceconfig system' comman...

Resolved! Global Protect include a specific URL?

Hey folks, This is a follow up question from one of my other posts. We are using PAN-OS 7.1.15 and GP client 4.1.https://live.paloaltonetworks.com/t5/General-Topics/GlobalProtect-and-general-Internet-access/td-p/207888 We are moving to Okta as our IDP for our applications. When logging into Okta it recognizes your client public IP and we have ...

OMatlock by L4 Transporter
  • 5220 Views
  • 2 replies
  • 0 Likes

inbound ssl decryption - multi cert to single ip

Hoping to get a little feed back regarding inbound ssl decryption. We have beeing doing inbound ssl decryption to our public presense on version 8.0.7. Things have been going realitivley well but I am running into some issues and not sure if I can fix it at the firewall level. Where I am running into issues is when we have multiple certs applied...

clewis1 by L3 Networker
  • 4842 Views
  • 4 replies
  • 0 Likes

Resolved! user-ID cache timeout vs idle timeout on firewall

Hi 1- On firewall, what is the different between cache timeout value (1 hour that cannot be configure) and idle timeout value (which is equal to user-ID agent timeout value)? 3- if idle timeout value is 480 minutes (8 hours) then what will happen to user-IP mapping after one hour in firewall?2- Also what events reset both timers?3- Also I noti...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels