General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! How can I get the available VSYS in PaloAlto Firewall?

Hi everyone,I'm develping an automatic software to get configure data from PaloAlto firewall. I need to know if a firewall is virtualized (I already know how to get this info) and, if the firewall has one/more than one vsys, I want to know these vsys's names. I just can get this info if I write: set system setting target-vsys ?, but I'm using Pe...

Resolved! How to find a IP range by DMZ?

I am trying to find a range by DMZ. For example in ASA we can show-show route | inc 10.10.10and it will show the DMZ where that route belong. Is there a way to find that in PAN OS 7.1?

sarif5 by L0 Member
  • 2888 Views
  • 1 replies
  • 0 Likes

How to count sessions at Palo Alto.

Hello all.I would like to know how to count sessions at Palo Alto.I do not understand that the number of sessions is different between the two devices.The two devices are Palo Alto and BIG-IP.It is counted as 140 thousand sessions at Palo Alto and 30 thousand sessions at BIG-IP.Thank you.

awawa100 by L2 Linker
  • 4414 Views
  • 2 replies
  • 0 Likes

Syslog multiple configurations

I am having no issues actually sending syslog data. The issue is sending to much over the network. I have two different applications that require syslog data from the firewalls. One application requires all the logs with all the content. The other application only requires a limited number of fields in the trafic log and all of the change lo...

vseward by L1 Bithead
  • 5690 Views
  • 4 replies
  • 0 Likes

packet-diag flow basic “matched rule index 0”

What does the rule with the index number 0 refer to in the packet-diag flow basic for the security as well as the NAT policy? The id manager does not show a security nor nat rule with an index 0 while the show session shows that the traffic was matching security policy “General-Internet” which is index 7 and NAT policy “Student-NAT-Out” which is...

Problem with NAT

I have an interface layer 3 on Palo Alto device with an IP public X.X.X.X connected to a router with IP public X.X.X.Y, I can ping the IP of the router, but from the router to the Palo Alto does not have ping, I have a profile of management that allows the ping, additionally has a NAT with the IP X.X.X.Z which is only used to go out to internet ...

SergioHV by L0 Member
  • 2218 Views
  • 1 replies
  • 0 Likes

Anyone running Sophos antivirus/webfiltering solution on client machines?

It appears that the sophos client on the windows machines uses its service account username to browse on behalf of the user. So essentially being a proxy for the user, the issue is from the monitoring aspect of the palo alto, I can't see the true user-id that is browsing. Anyone run into this or something similar? Any fixes on the palo alto side ?

cron services restart of minemeld

Hi, I'm researching about restart all the services of minemeld but I don't get nothing. How I can do it? I would like set a task on cron for example. is it possible? Please, if you need more info let me know! Thanks

SantiBT by L2 Linker
  • 5233 Views
  • 3 replies
  • 0 Likes

Resolved! Low Forwarding 8.0 (7050)

When following white paper. When i get to verify i get below: Not sur ewhat this means as I only have 1 collector . Please adivse admin@PALO-TIA-03P-HA(active)> show log-collector preference-listLog collector Preference List is malformed

How to delete all unused rules?

Hi Guys! I am looking for an way to delete all unused rules. On CLI, I can list all unused rules: > show running rule-use rule-base security type unused vsys vsys1 After that may it is possible to delete the rules from it. Thanks!

User-ID Mapping To Not-Domain-Joint Devices

Hello, What would be the best way to enable User-ID for devices that aren't joined to the domain? We have a number of contractors whose laptops aren't members of the domain but we would like to enable User-ID to be able to monitor their User-IDs? Thanks in advance. Best, ~zK

Resolved! User-ID for Non-AD Operating Systems?

I'm curious what others out there are doing for user identification for systems that don't integrate with AD? My understanding for Mac OSX was that some are popping up a GlobalProtect client login that requires them to enter their domain credentials to continue but then just uses it for ID purposes and does not establish a tunnel. I was curious...

jsalmans by L4 Transporter
  • 5073 Views
  • 4 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels