General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Custom Report Query Building Help Needed

I'm having a hard time getting my URL report built and sorted. I want to accomplish the following 1. category must match ADULT or NUDITY2. source user must not be a member of FILT_STAFF or M_FILT_STAFF active directory groups (basically students)3. search all IPs in 10.0.0.0/8 EXCEPT the following subnets 10.10.0.0/21 10.10.8.0/22 10...

dannon by L3 Networker
  • 2179 Views
  • 1 replies
  • 0 Likes

Resolved! Don't Port that thing at me!

Hi All, Heres my problem, I am setting up a L2TP/IPsec remote access VPN for staff and I am having issues with the IKE traffice on port 500. We are using an internal RRAS server which I have set the palo up to NAT all port 500 traffic and IKE services to once it hits our outside interface. We also currently have 2 Site-to-Site VPNs setup and run...

Route all traffic through the firewall

I have one HA pair that sits at the edge of the network running internet traffic outbound. I want to also run all other traffic through this pair as well, but don't want to use it for default gateways for networks. I have done this before, but in one scenario we had edge and core PAs so it made it easier for routing. The other scenario was runni...

Quick diagram.png

Palo Alto Networks Logs in real time

Hello, I have a problem with the Palo Alto Networks logs . The logs are appear every 10 seconds . I need to see the logs in real time. There is any command that let me see the logs in real time? Thank you very much.

ra7oub4 by L2 Linker
  • 2681 Views
  • 1 replies
  • 0 Likes

Building New Polices for New Firewall Implementations

Is anyone using simple applicaiton filter groups to build policies for new firewalls? I find myself looking at tap traffic all day trying to build policies on what I see users hitting and its cumbersome. Is anyone just creating a applicaiton filter called business applicaitons and adding all the business applications to it, risk level 1-4 maybe ...

Policy with user ID don't work in palo alto networks

Hello, I have configured the users in the office to be identify with Active Directory. I can see the users identification in the Monitor tab. But when i set a rule with user AD identifier don't work! I add two rules : rule 1: deny access for a specific AD users to social networksrule 2: allow access to any users (internet access). The first rul...

ra7oub4 by L2 Linker
  • 5324 Views
  • 7 replies
  • 0 Likes

Resolved! Report bug to Palo Alto support

Hi, I think we are hitting a bug in versions 8.0.4 and 8.0.5. In firewall with several Vsys, only admins can see the logs (traffic, threats...). If you create an admin for one vsys, they cant see any logs. If any PA team read this 🙂

Resolved! Global Protect at the inside truted interface

PAN 5060Outisde untrusted interface 5.5.1.77Inside trusted interface 10.10.1.1 Wifi guest network inside 10.10.5.0/24 Most Global Protect corporate users go to ourvpn.foo.com 5.5.1.77. WiFi users normally PAT to the Internet using that same interface IP 5.5.1.77. So all source addresses to the Internet appear to be 5.5.1.77. Like most guest netw...

palomed by L3 Networker
  • 2848 Views
  • 2 replies
  • 0 Likes

Resolved! Content Apps & Threats Unknown

Hi, We just several FWs in which we see any content package as "unknown" and we can not delete it???Why this package is unknown and why it can not be deleted??? Here an example:

MG.JPG

Vulneability SQL Injection

Hi, we have done some Vulnerability assessment on firewall with PAN-OS version 7.1.8 version. And found below vulnerability for which we are not able to find CVE or solution. Help me to find a solution for below: Vulnerability : CGI Generic SQL Injection (blind) - 443/tcpSynopsis :A CGI application hosted on the web server running on this host i...

using cli to enter x509 certs

Trying to useset template TemplateName config shared certificate "CertName" public-key "xxx" I am getting it from a show template . but the string value is multiline so when i try and copy and paste. it fails on the second line How do I work around this ? A

Citrix Offloading

Hi,I'm having several problems with suddenly disconnections between users and xenapp citrix through PAN. Looking some information about that I think that is related about ASIC treatment of traffic... Is possible turn offload traffic only for citrix traffic?Another solution for this case?Regards!

nanukanu by L2 Linker
  • 3669 Views
  • 2 replies
  • 0 Likes

Resolved! Total Application Time

I'm trying to figure out the total application time of some specific applications. For example, for the last 7 days I'd like to know for a particular subnet how much time was spent on YouTube. Is this possible? So I'm looking for something to tell me that there has been a total of 8 hours, for example, of YouTube sessions for the last 7 days. I ...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels