General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Intrazone-default rule

Hello, I would like some advice on Palo Alto's default intrazone-default rule. Unless I have a drop any any above this rule I see IP's from all over the public internet hitting my Palo Alto and being accepted on the intrazone rule as the traffic is from zone outside to zone inside. I want all of these random public IP's to be blocked and not a...

PA restart with Internal packet path monitoring failure

We have a pair of 3220 in a cluster. Yesterday we upgraded to 10.2.9-h11 and today we faced a restart of the Active peer twice with this error: Internal packet path monitoring failure, restarting dataplane I could not find any bugs related to this in 10.2.9-h11 Any thoughts? Should we upgrade further?

Max Tunnels for GlobalProtect

Can someone help me to understand the maximum number of concurrent connections possible with the GlobalProtect Clientless VPN solution? Preferably any documentation where this is specified would be great!

mitchduf by L0 Member
  • 873 Views
  • 1 replies
  • 0 Likes

User's traffic not hitting correct security rule.

We're running into an issue where a rule that is meant to update anti-virus protection on port 443 is slipping through and being caught by a lower rule which denies any application and service. (Hardware: PA-5050, OS version : 8.1.6).As far as the security rule is concerned, we have mentioned FQDNs as the destinations (instead of IPs & URLs)...

transfer the vm panorama to the nutanix

Hello Customers are using VM Panorama for VM-ware.Sooner or later, however, the customer will replace the vm-ware with a nutanix.VM Panorama version : 8.1.6VM Mode : VMWare ESXi 1. Can I get an image of a VM Panorama in use and use it in Nutanix?2. Will the log stored in the existing vm panorama be maintained if only the image is taken?3. Can ex...

ttak87 by L1 Bithead
  • 4603 Views
  • 3 replies
  • 0 Likes

Activating Trial license to extend PaloAlto working environment

Hi, community Does anyone has any experience Activating "Trial Licenses"? If let's say our support for PA-FW ends in 10 days and we would like to extend working-period is it possible to use "Trial Licenses"? I know we can use them only once, but we don't know if we can use them before the official support-end to extend them for trial period? If ...

Port Hopping - Is it for defence or Attack ?

I was just going through Tactics, Techniques, and Procedures (TTPs) and saw port hopping and still confused is it for defence or attack. If port keeps changing randomly then how would the connection stay connected?. Please share any article that explains clearly about port hopping or any easy way to understand. #Portmapping #CybersecurityFun...

cryptographic secure erase with NIST 800-88 guidelines

Query: We would like to know if PA firewalls have cryptographic secure erase that complies with NIST 800-88 guidelines. Ref: https://www.stellarinfo.co.in/bitraser/ppc/nist-compliant-data-erasure-software.php?gad_source=1&gclid=Cj0KCQjwsoe5BhDiARIsAOXVoUvVnCf6oEs40k5Qm5ACFgn4UdUirA047WSY2tdQm7R08taWwhYo69UaAlTUEALw_wcB

User-ID Agent Timeout Triggering

I'm going through implementing a special 'modified' SP800-171R2 control list and I believe I can achieve satisfying controls such as 3.13.9 "user session timeout/terminate external access etc etc" control with the UID timeout function. If I tied external internet access to a security group in my AD and granted users membership to that group, t...

RH747 by L2 Linker
  • 3469 Views
  • 2 replies
  • 0 Likes

Facebook Chat Still Active even After Adding Application "facebook-base"

Hi, I am new to Palo Alto and I started learning with watching Keith Barker's PA videos. In a video he configured security policies and demonstrated that he can't use Facebook chat with that configuration. I didn't want to do the exact same thing and in my lab a virtual PC can use Facebook chat. I did not understand why. Please explain with dumm...

User ID Redistribution

Hi, There seems to be an issue with our internal Palo firewalls and their Data redistribution, I'm not sure how long it's been an issue. What it should do is redistribute the user authentication events to every firewall so it can use that us the user id in the firewall policy, but this isn't happening. User ID isn't showing across firewalls, lik...

OCI PA vm unable to communicate outside

Hi, I am a newbie for PA and need of some assistance in configuring PA VM on OCI. I have done the basic configuration Created Zones and Virtual routes etc. I need to create a IPSec VPN from OCI PA VM to OCI VPN (Not a PA VM) setup on a another tenancy. Both configuration identical except for IP address. Added rules to allow all and a NAT tow...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels