General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4133 Views
  • 0 replies
  • 0 Likes

Decent IPv6 miner

Hello all, We use MineMeld with our PA firewalls at work, so I thought I'd try it at home as well, and it was easy to integrate with my OpenBSD PF firewall. Lots of high-quality IPv4 address and subnets to block! However, I also run IPv6 at home and would like to import a decent feed. I already use unbound to blackhole everything in the SomeoneW...

Resolved! DAGPusher - Add device - Is vsys supported?

In a Dagpusher output, I see the VSYS as a column, but when adding device there is no input field for VSYS. I checked the code on GitHub for the file at: minemeld-webui/src/app/nodedetail/dagpusher.controller.ts Seems like maybe the VSYS is not fully implemented as part of add device. Can anyone confirm whether we can mention VSYS ...

Planned Cloud Services - GlobalProtect Cloud Service Maintenance Notice

Dear valued Palo Alto Networks customer, Please be advised that we have a planned service maintenance for the Cloud Services- GlobalProtect Cloud Service infrastructure scheduled from 12/21/2017 6pm PST to 12/23/2017 6pm PST. We expect the service to continue without disruption and you can continue business as normal. However, if you experien...

PA 3050 Logged in user web filtering

Hi , ive got a 2 PA 3050's running well , however sometimes they seem to fail to detect the user thats currently logged in and then it follows the sert rules to allow then a "Student-level" web filtering rules whereby shopping , and social media etc are blocked , is there some sort of browser addon that i can install on Chrome to ensure the 305...

VICO88 by L0 Member
  • 2110 Views
  • 1 replies
  • 0 Likes

How PAN firewall deals with deceptive or invalid URL ?

Users in my organization received spam email with embeded link URL like http://いい中古車.com When I check URL category in PA test URL website it says "http://いい中古車.com" is not a valid URL. What are the option to block this other than adding it in Block list under URL filtering profile ?

Fail over with SRV records

I know this isn't really a question for PaloAlto but I was hoping I might get some insight from the community.We are looking at acquiring a second circuit from a different ISP for a backup failover, not load balancing. I have been studying SRV records for prioritizing which circuits IP addresses remote users should use. It appears that SRV recor...

Bvance by L2 Linker
  • 2603 Views
  • 1 replies
  • 0 Likes

Problem w/ user ID

Hi Gurus, I'm trying to implement user id agentless.The LDAP & User Identification are created correctly. Below is the output:J-C.Valiere.da@PA_Ecore_Master> show user group listcn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=comcn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com...

Resolved! Customizing response page

First time doing this and I'm fairly familiar with HTML and CSS however I'm not sure how to target SubcategoriesIs there a way to target Subcategories when using a custom response page? The online documentation only mentions <category/> also do you upload the file as a .txt or .html file? this is what I have in the script part<div id="c...

Resolved! Asymetric Bandwidth On IPSEC VPNs and MPLS Tunnels

We are having unidirectional problems with our site to site circuits bandwidth. I am not sure if this is a PAN problem or a problem with the providers. It’s interesting that IPERF shows slowness to the remote site on MPLS but on IPSEC the slowness is to the main site (10.10.1). Traceroutes show the traffic is symmetrical on all tests.All connect...

traffic_examples_2017-12-12_14-43-38.jpg
BrianRa by L3 Networker
  • 7777 Views
  • 7 replies
  • 0 Likes

Resolved! ECMP Weighted Round Roubin

Hi, I have a case where we have to PA FWs and there is 3 connections between them,1- Two Microwave Links (Up to 100mbps)2- One DSP Link (Up to 10mbps) There is a total of 3 IPSec Tunnels and i'm using weighted round robin, however, i don't know how to calculate the weights and what numbers i should put in the ECMP to reflect the real speeds of t...

Resolved! What to do when IPSec VPN proxy IDs are the same?

Hi folks, We have several IPSec VPN connections and luckily so far all with unique Proxy IDs.I am trying to prepare when I create a new one and has the same Proxy ID as another.I see this article and talks about creating a NAT both ways.https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Help-with-IPSec-Proxy-IDs-with-overlapping-IPs/ta-...

OMatlock by L4 Transporter
  • 7152 Views
  • 5 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels