General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

HTTP redirect at firewall level(currently being done in IIS

I'm currently doing http redirect at the web server(IIS) and allowing http and https traffic into the web server. Is there a way to do http redirect at the firewall level and that way I only allow SSL traffic and block http coming into the web server. IS it ok to allow http traffic into the web server behind the PAN? I want to know what other ar...

msintech by L0 Member
  • 3564 Views
  • 2 replies
  • 0 Likes

Resolved! Management CPU keeps 100% usage

Hi experts, We are using PA-2020 in our environment and its firmware version is "4.1.6" PA-2020 was working smoothly but now it appears very slow process when we click commit action. We have searched and followed many reference such like 1) disable each policy logging setting (no log now), 2) execute command "debug software restart device-server...

2018-01-10_141253.jpg

MineMeld - how to prevent age out of DShield in a TAXII output DataFeed

Here is the basic setup that I'm having trouble with: Miner: dshield_blocklist: output: true prototype: dshield.block Aggregator: aggregator_dshield: inputs: - dshield_blocklist output: true prototype: minemeldlocal.aggregator_dshield Output Node: taxiiDataFeedDshield: inputs: - aggregator_dshield ...

EdwinD by L3 Networker
  • 5141 Views
  • 2 replies
  • 0 Likes

Modify application

One of the applications (a default one in the Palo Alto) sometimes connects over an other port than the defined standard port for the application. Since I defined the plicys service as 'application default', this traffic gets blocked. Its the application 'magister', which has a standard port of tcp,443 but sometimes connects over 943 & 4502....

Sjoerd by L2 Linker
  • 4091 Views
  • 3 replies
  • 0 Likes

Resolved! Difference between pkts/sec vs conns/sec

Hi All, In Zone Protection Profile, a unit of rate changed from packets/sec to connections/sec when I upgrade into PAN-OS 8.0.It sounds defferent thing, though is this only changes on GUI and nothing changes on this feature, I mean way of counts is same as before?If no, how to calcurate accurate value for 'connections'?Let's say if I configure '...

71.png
80.png
emr_1 by L6 Presenter
  • 4045 Views
  • 1 replies
  • 0 Likes

Recommened PAN-OS as of April 2017 (Q2)

What PAN-OS are people running these days? I am currently 7.0.8 and it is time for the care-and-feeding of the firewall code at my company. I am looking at upgrading to 7.1.8 (but 7.1.9 just came out today). I do not use any SSL Decryption features. Primarily firewalling, IPSEC tunnels and GlobalProtect.

rpugh1 by L0 Member
  • 2913 Views
  • 3 replies
  • 0 Likes

Resolved! BGP filtering question

Hi Quick question, pretty sure I know the answer. But I want to redistribute some of the OSPF routes I have into BGP.So I create a redist profile, say the source is OSPF then I can use the BGP export filtering to stop what I don't want out. So lets say I have in my ospf table 10.10.10.0/2410.10.20.0/2410.10.30.0/24 1.1.1.50/32 1.1.1.51/32 1.1.1....

Proxy ARP

Hi I have a 5220 in the DC and a 850 in the officeOn the 5220 I have an interface onto network 2.7.3.0/24On the 850 I have a NAT for 2.7.3.129/32the 5220 get this via OSPFHow can I make the 5220 response on the interface 2.7.3.0/24 for arp requests for 2.7.3.129Do I have to setup a 1-to-1 NAT on the 5220 so destination nat of 2.7.3.129 to 2.7.3....

How does one create an output filter to exclude IPv4 indicators in a CIDR range?

I have various miners. Various miners are connected to various aggregators which are inturn connected in various ways to different types of output. Some of these miners receive RFC1918 IPv4 indicators. These are aggregated and send to outputs. I'm attempted to have one output which will contain these RFC1918 addresses while another does ...

EdwinD by L3 Networker
  • 7789 Views
  • 5 replies
  • 0 Likes

OSPF and Cisco Routers

Greetings all, I was doing some Core routing work during an outage this last week and ran into a repeat of some issues we had when we initially put our PAN boxes in to place. The original scenario: A subinterface existed on the Palo Alto with the tagging set for a point-to-point vlanThat vlan connected the Palo Alto directly to a Cisco 4500-X V...

jsalmans by L4 Transporter
  • 7090 Views
  • 2 replies
  • 0 Likes

Resolved! NAT Security rule

I'm used to working on Cisco ASA and I'm having a hard time understanding why the security rule states Untrust-L3 for both the source and destination zone. Typically wouldn't that be Untrust-L3 to DMZ? Is there a specific reason for this behavior?

Screen Shot 2018-01-06 at 6.57.18 PM.png
Glitchen by L0 Member
  • 3024 Views
  • 2 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels