General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 315 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3661 Views
  • 2 replies
  • 14 Likes

Last SNMPv3 question

How does one know if SNMPv3 is truly working . I ask because I just copied SNMPv3 profile from a known system but dont have actual auth/priv credentials to do snmpwalk since profile is encrpted in terms of password. Are there logs I can check particu...

Resolved! Wie starten mit PA220 und 8.0

Hallo,

 

ich suche ein Start Tutorial in welchem einfach erklärt wird, wie man mit der PA220 startet. Also dieser Beginner Guide hab ich schon, IP vergeben etc. Aber nun welche Regeln sind Empfehlungen, wie blockiert man diverse URLs? Wie baut man eine

...

High availability failover due to high dataplane usage

our internet went down a few weeks ago when our primary PA failover to a secondary PA. We found out, after doing some research and investigative work, that this was due to the amount of new session created, which cause the PA to use the slowpath and

...

mmbengue by L0 Member
  • 2714 Views
  • 2 replies
  • 0 Likes

How do I fix this?

Trying to connect PA-500 to user id agent on domain member server and keep getting this from the agent ID app log.

 

10/02/17 18:33:09:959[ Info 1219]: New connection 10.100.20.20 : 33369.
10/02/17 18:33:09:975[ Info 1292]: Device thread 1 with 10.100.2

...

selfsignedcert.PNG

Resolved! How can I get the available VSYS in PaloAlto Firewall?

Hi everyone,


I'm develping an automatic software to get configure data from PaloAlto firewall. I need to know if a firewall is virtualized (I already know how to get this info) and, if the firewall has one/more than one vsys, I want to know these vsys

...

Resolved! How to find a IP range by DMZ?

I am trying to find a range by DMZ. For example in ASA we can show-

show route | inc 10.10.10

and it will show the DMZ where that route belong.

 

Is there a way to find that in PAN OS 7.1?

sarif5 by L0 Member
  • 1914 Views
  • 1 replies
  • 0 Likes

How to count sessions at Palo Alto.

Hello all.

I would like to know how to count sessions at Palo Alto.
I do not understand that the number of sessions is different between the two devices.
The two devices are Palo Alto and BIG-IP.
It is counted as 140 thousand sessions at Palo Alto and 30
...

awawa100 by L2 Linker
  • 2780 Views
  • 2 replies
  • 0 Likes

Syslog multiple configurations

I am having no issues actually sending syslog data.  The issue is sending to much over the network.  I have two different applications that require syslog data from the firewalls.  One application requires all the logs with all the content.  The othe

...

vseward by L1 Bithead
  • 2862 Views
  • 4 replies
  • 0 Likes

packet-diag flow basic “matched rule index 0”

What does the rule with the index number 0 refer to in the packet-diag flow basic for the security as well as the NAT policy? The id manager does not show a security nor nat rule with an index 0 while the show session shows that the traffic was match

...

Problem with NAT

I have an interface layer 3 on Palo Alto device with an IP public X.X.X.X connected to a router with IP public X.X.X.Y, I can ping the IP of the router, but from the router to the Palo Alto does not have ping, I have a profile of management that allo
...

SergioHV by L0 Member
  • 1597 Views
  • 1 replies
  • 0 Likes

cron services restart of minemeld

Hi,

 

I'm researching about restart all the services of minemeld but I don't get nothing. How I can do it? I would like set a task on cron for example. 

 

is it possible? Please, if you need more info let me know!

 

Thanks

SantiBT by L2 Linker
  • 4216 Views
  • 3 replies
  • 0 Likes

Resolved! Low Forwarding 8.0 (7050)

When following white paper. When i get  to verify i get below: Not sur ewhat this means as I only have 1 collector . Please adivse

 



admin@PALO-TIA-03P-HA(active)> show log-collector preference-list

Log collector Preference List is malformed


How to delete all unused rules?

Hi Guys!

 

I am looking for an way to delete all unused rules.

 

On CLI, I can list all unused rules:

 

> show running rule-use rule-base security type unused vsys vsys1

 

 

After that may it is possible to delete the rules from it.

 

Thanks!

 

 

 

 

 

  • 24189 Posts
  • 100 Subscriptions
Top Liked Authors
Labels