General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Debug question (Debugs turned on)

Let's say different techs have applied debug commands in the past. Eg: Someone two weeks ago set the debug user-id on debug comand. Now he/she forgot to set the "debug user-id off" Is there a comand to see which debugs are turned on? Thanks. Luis

lestrada by L0 Member
  • 4261 Views
  • 2 replies
  • 0 Likes

Resolved! Activate a new GlobalProtect Client?

Hello folks, Another first for me this week. Before we upgrade our PANOS, I wanted to activate a new GlobalProtect client first. It says here that it will download new client when users connect. Is that true? Will it download and install (upgrade) on the client automatically?I was thinking it would just be made available on the Portal for down...

GPUpdate.jpg
OMatlock by L4 Transporter
  • 14983 Views
  • 8 replies
  • 0 Likes

Looking for advise, MFA or additional step for access to a server over RDP

I'm trying to add additional protection for users accessing resources on an isolated network. Is there any way that I can utilize our Palo Alto's to accomplish this scenario? We do use global protect and user-id mapping already, but as an example I would like John while on his laptop\pc that whenever he access lets call it ServerA over RDP that ...

zthiel by L2 Linker
  • 3520 Views
  • 4 replies
  • 0 Likes

Design suggestions

We are trying to implement SSL offload using proxy gor our hosted websites, so they can be inspected by firewalls. Management currently is more alligned to SSL offload by proxy rather than decryption by FW and it is working the way below. But with the cenario below they are also concerned about the password being revealed after SSL offload. How ...

image.png
raji_toor by L4 Transporter
  • 2904 Views
  • 3 replies
  • 0 Likes

Resolved! Multi hop DHCP relay

Hi So I want to get my VOIP phones to dhcp to the vPBX. Phone are on a vlan in the office vPBX is in the DC so vlan for phone -> PA -> vlan -> arista switch -> vlan -> PA (clustered A/A) -> vlan -> vPBX So I can setup DHCP relay on the first PA and I can set the DHCP server as being the ip of the vPBX, and I believe as it wi...

Exclude threat from alerting on IPS

How can I effectivly remove alerts for specific threats on our IPS tap? There are some that we are aware are actualy trivial and can't be fixed but cause a lot of alerts. Is simply adding it as an Exception on the Vulnerability Profile enough? I tried this and did get a number of alerts afterwards. Cheers Rob

Allow all shorteners

Good morning, Is it possible to allow all shorteners (bit.ly, goo.gl...). But only shorteners. There isnt any category for this.. Regards.

MineMeld not loading after installation

After succesfol installation of MineMeld in a Debian9, by using this article: https://github.com/PaloAltoNetworks/minemeld-ansible When accessing to HTTPS://IP_Address it stays forever loading (showing the loading "M"). I can't see any error in the logs, services are fine. Any ideas?

MarcelST by L3 Networker
  • 3121 Views
  • 1 replies
  • 0 Likes

Virus/spware download blocked but no threat logs

Hi When users are accessing internal portal then they are getting "Virus/spware download blocked" on browser with file name (althrough they are not accessing this file) but there is no virus/spyware logs in threat monitor tab. Any pointers how to fix this?

nbar

Hi,What is the NBAR equivalents in pa- qos or how does it works in PA Thanks

simsim by L4 Transporter
  • 6561 Views
  • 8 replies
  • 0 Likes

Resolved! After Factory Reset Cannot connect to management server

Hi,after i make a Factory Reset via Maintenance Mode with this HowTo -> https://live.paloaltonetworks.com/t5/Management-Articles/How-to-SSH-into-Maintenance-Mode/ta-p/59635 i cant connect via "www" to the management. My new IP is default 192.168.1.1 and i can ping it. when connect via ssh i login with admin:admin then i see the message "Syste...

IP Wildcard in custom report?

I have a custom report, I need to exclude 40 Instances of 192.168.x.100 to dest port (1234 or 1235) is there a short way to do this or am I faced with 40 repeating lines like this.... ( addr.src notin 192.168.10.100 and ((port.dst neq 1234) or (port.dst neq 1235)))and( addr.src notin 192.168.10.100 and ((port.dst neq 1234) or (port.dst neq 1235)...

Log forward without internal logging?

Should it be possible to LOG forward without having internal logging? Some stuff I need to be able to deal with on the firewall, but others I just want recorded long term. Seems to be no option to do it.

what NAT and Network config

Hi,I have a router from my carrier. This gives me an internal IP 10.0.9.3 /16 from my internal Network 10.0.0.0/16 network and the GW IP he gave me is 10.0.30.99.Now he makes natting so i could get internet access and there i have a static official ip adress. for example 123.456.789 My test pc give it the ip 10.0.9.3 subnet 255.255.0.0 and gw 10...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels