General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

GP user logouts.

trying to find out if there's a list of the various messages and what they mean, particulary with 'globalprotectgateway-logout-succ'. I'm specifically trying to identify what 'Reason: remove previous login' means. I assume it means the previous session didn't close and a new session was created, like if the user's machine goes to sleep or reboot...

Resolved! How to translate IP and port from trust to trust?

My goal is to be able to reroute traffic from internal server 192.168.0.10 port 123 to other internal server 192.168.0.20 port 456 My understanding is that I do not need a u-turn nat rule since we're using internal IP addresses, however so far I've not found any rule configuration that successfully makes the translation when tested nor have I be...

Resolved! DNS Sinkhole - working or not?

I have followed the configuration guide for setting up dns sinkhole but i am not seeing the expected output in the logs. My configuration is as follows:-Client sits on a zone 'mplstrust' (internal LAN)Internal DNS Server sits on zone 'dnstrust' (internal LAN but different subnet to mplstrust zone)We have subscribed to Dynamic Updates for Spyware...

shaneo by L1 Bithead
  • 7379 Views
  • 6 replies
  • 0 Likes

Resolved! suspend passive

If you suspend a passive firewall in an active/passive HA configuration does it just mean that you have turned off HA and the active cannot fail over to the passive?

jdprovine by L4 Transporter
  • 5979 Views
  • 5 replies
  • 0 Likes

Resolved! Probably a simple question

Our product detects malware in network traffic streams (the product does not really matter here). When we generate what we call an event, we know the source/destination ip/port. We have had some customers ask for automatically putting the external (usualy the source) ip address on a block list. the list of blocked ip's will of course grow ...

Resolved! URL filtering Block List is not working properly

Hello, I have encountered an issue with some URL when I try to block them manually through the block list in URL filtering. I have blocked many URL for a client, but they can still access to some of those pages. The FW they are using is a PA-3020 with firmware version 7.0.10 and I have replicated the issue in my PA, which is a PA-500 with 7.1.7,...

SOC_CSG by L4 Transporter
  • 11492 Views
  • 4 replies
  • 0 Likes

Resolved! Multiple VPN Issue For FortiClient VPN & GlobalProtect VPN

Hi Support Our Client is using use FortiClient VPN to connect to their servers and get internet access. Also, they use GlobalProtect. When users who are using both the VPNs simultaneously lose internet access when enabling the GlobalProtect VPN. I’m presuming there is a setting somewhere that needs updating to allow this?

NavidAlam by L3 Networker
  • 13371 Views
  • 1 replies
  • 0 Likes

Resolved! Security Policy using URLs?

Hello community.Let's say I have an Atlassian Confluence site that needs to be accessed by a user (or multiple) - is it possible to specify down to the URL to only give the user access to a given set of pages? Confluence permissions only allow me to give access to entire spaces. Could be advantageous to allow a general user not tied to a specifi...

Idenfiy number of connection of per zone with or without snmp

Dear All, I need to configure zone protection, how to find the number of connetion per second for each zone. I tried with "show session info" and i can see "new connection establish rate" but i need to take the average for 2 or 3 weeks.So if its on the snmp which ouid i have to use to monitor or any other method to identify the con...

Resolved! Incoming Traffic from Palo Alto IP Address

I have a customer who asked about traffic which he saw on his Firewall.I looked in firewall logs from several others customers and find the same IP address. It is always a HTTP oder HTTPS connection. The traffic is coming from the 70.42.131.170. According to several internet sources this IP address belongs to PaloAlto Networkshttps://whatismyipa...

Resolved! IPS Signatures

Hello friends, I have some signatures with fortigate names and I neet to know the equivalence in Palo Alto, by the CVE Palo Alto dont indentify it, could anyone help me? web_app3: Narcissus.Image.Configuration.Remote.Command.ExecutionCVE-2015-1579 CVE-2014-9734applications3: Ektron.XSLT.Transform.Remote.Code.ExecutionCVE-2012-5357applications3: ...

Website Down??

Can't get to the main website, it briefly worked but was useless as it only had CLOUD event stuff on it?? Can't get to support site either? "Live" works Various chcek sites say the same, DOWN.

Resolved! PAN-OS 8.0.8 - use region in policy based fowarding rule

Hi community! I would like to know, if it is possible to use a region-object as destination address in a Policy-based-forwarding-rule?I found an articel from 2014 ("Policy Based Forwarding PBF based on destination country or self defined region?") that says it is not possible.Since it is a couple of years old, the PAN-OS version mentioned in tha...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels