General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Command line "show session all" limited to 1024 entries

First some information on the use case:500 userseach user is generating approximately 10 simultaneous sessions => 5000 simultaneous sessionsI would like to get the amount of current sessions per user, from the command line. I currently use the API to basically do:for user in $user_list; do panxapi.py -jo " <show><session><all...

Migrate PA-500 to PA-820

Hi, I have a customer with a PA-500 cluster in version 6.0.3 out of support and has bought some new PA-820 that come with version 8.0.0. As the PA-500 are not supported and I do not want to update them to version 8.0.0, is it possible to load the xml version 6.0.3 in a version 8.0.0? Regards.

How to recover Radius profile shared secret ?

Folks- Any idea how to recover shared secret of Radius profile which is set to verify and encrypt the connection between the firewall and the RADIUS server ? Is there a more system:runnig config CLI command like Cisco in PAN firewalls which can help me out ? Radius profileRadius server admin don't know the shared secret as well.

image.png

Resolved! Policy Commit Failed

Hi All, recently I have created an interface in Firewall which is managed by Panorama. Now after creating the interface, I am not able to push configuration on Firewall and getting below error. Can someone please help me? Below is the error. +++++++++++++++++++ Details:In virtual-router VR-OSPF, OSPFv2 is not supported on interface ae2.3020 in ...

Resolved! Looking to get started with SSL Decryption

I'm currently reading articles on this site on how to set this up. I was hoping someone could point me to a guide or tell me a very basic test set up for this feature on the P.A. Thanks in advanced.

User-id not working correctly

Hi All! i have a issue with the user-id feature: some users are not recognized by the PA device: if i check the logs searching for the username i see the last access some days ago, but if i search for his ip he is doing traffic.Even checking via CLI with ' show user ip-user-mapping all | match username ' i don't see anything. PA is running PAN-O...

DKanta by L2 Linker
  • 5188 Views
  • 6 replies
  • 0 Likes

Untrust to Untrust

Should the untrust to untrust be denied. As the defalt interzone traffic allows everything. untrust to untrust rules for us are ether used for IPSEC or global protect. It seems to me blocking this traffic effects detecting SCANS.

raji_toor by L4 Transporter
  • 5918 Views
  • 2 replies
  • 1 Likes

Security profile group best practice

HI guys, I've read most of the reference material by Palo alto only applying security profiles on inside->out security polices but not outside->inside polices. I would think that is a given since outside->inside policies are to protect your front facing web services. Do you guys apply security profiles for outside->inside policies. Khai

No wildfire submissions (FWD_ERR_CONN_FAIL_PUB errors)

Hi there, Wildfire is not submiting files. I have the simplest configuration possible, and I'm using the test file (https://wildfire.paloaltonetworks.com/publicapi/test/pe). However, nothing is getting to the portal, or logs for that matter.I'm running VM-100 on a ESXi server, 8G RAM, 4 vCores, PAN OS 8.2.The only thing I have noticed is on the ...

Hwinter by L2 Linker
  • 6765 Views
  • 7 replies
  • 0 Likes

Configure GlobalProtect With Public IP adresse

Hello 1-i have the router adsl with the public ip adresse : ex 41.137.11.123 (WAN interface) ==> this is a Public/fixe IP adresse.2-i have a paloAlto firwall, is connected by its wan interface (192.168.1.2) to the local interface of the router adsl (192.168.1.1). 3-i follow this course to configure the GlobalProtect (https://live.paloaltonetw...

Resolved! Call API key via invoke-restmethod

Is Palo Alto's API able to accept GET requests from the PowerShell "invoke-restmethod" cmdlet which have the api key set as a variable? I ask this because I would like to run these requests without embedding my API key in the HTTPS GET request. This does not seem secure to me. Rather, I would like to store the API key elsewhere and have Power...

Log forwarding "Zone Protection" ?

I can't find an up to date way to enable log forwarding for "Zone Protection" profiles. I found a guide for 6.1 but its not relevent for 8.0 I want alerts when we get port scanned. Cheers Rob

SSL Decrypt and GitHub

I keep fighting this SSL Decypt issue with my PAs, its almost getting to the point where its not worth running the SSL decrypt function because it causes so many issues. I am currently having issues with people downloading a zip file from git hub. github.com/Microsoft/vsts-agent/releases/download/v2.117.2/vsts-agent-win7-x64-2.117.2.zip The err...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels