General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1959 Views
  • 0 replies
  • 0 Likes

Blocking Hexa Protocol (Hexatech VPN)

I just became aware of this yesterday, but we were seeing a rise recently in "unknown-udp" traffic on our Palo Alto Firewalls and have discovered what it was.  The amount of traffic was significant - always used the more bandwidth than anything else

...

SAML ADFS for GlobalProtect

Hi,

Is someone able to shed some ligh on the below.

 

1. Can SAML be used to map to an LDAP group, if so is there guidance?
2. Does PAN support using SAML AND prelogon/alwayson with GP?

 

 

Thanks

 

 

Resolved! custom report - "unknown" category

Hello

 

I observed that in my reports in pdf I have a lot of "unknown" in CATEGORY column.

My report looks like:

 

How is possible that google-base or linkedin-base have category=unknown ?

 

Regards

Slawek

2017-08-15_201653.png
2017-08-15_203202.png
_slv_ by L4 Transporter
  • 5455 Views
  • 9 replies
  • 0 Likes

Resolved! Traffic seen as application "authentic8-silo"

Hi,

 

On our PA device, we suddenly have this issue that lots of traffic is seen as application "authentic8-silo" which is not allowed.
Lots of services (Lync/Skype for Business, websites and other services) which use SSL do not work anymore.
There was n
...

Farzana by L4 Transporter
  • 2810 Views
  • 2 replies
  • 0 Likes

URL Filtering response pages never appear

Hi, 

 

My URL filtering response pages never appear, even the default ones.

Is there anything to do to activate them ? I always have the "This site can’t be reached" message with a connection reset.

 

Thanks

PorZik by L0 Member
  • 7844 Views
  • 4 replies
  • 0 Likes

Syslog miner not recieving the syslog messages

HI All,

 

I have used the below link to configure Syslog miner, but metrics are not showing up in stats.

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-the-syslog-Miner/ta-p/77262

 

I have tried to troubleshoot  using following discussi

...

syslog miner node.png
stats.png
rsyslog_config.png
rsyslog-logs.png

Clear Config on new Palo

Good Morning. Is there an easy way to clear out all configuration settings on a new Palo without having to go through the CLI to clear each item individually, or doing the same in the GUI? It is time-consuming to have to go in and delete the default

...

NAT very slow

PA-3020 Software Version 8.0.4
I have several policies U-Turn Nat and Destination Address Translation in the DMZ
Three times a day the acces to these Policies becomes very slow
If I send a ping to one of these servers the time is very large the 1000 to

...

Resolved! PA-VM-300 refuse to boot because master key expired.

Hi all,

 

today i found my PA-VM-300 in maintenance mode, refusing to boot.

 

Maitenance Entry Reason:

Cryptod failure. Caused by: Master key expired.


This firewall is a backup of our production firewall, in our Disaster Recovery Plan, in addition to VMwar

...

2017-08-16_171551.jpg

Virtual Panorama for Log viewing only

Hi all,

 

I hope someone already did something like that to answer my question 

 

We have a virtual Panorama on PAN-OS 8 with a local log collector. On this panorama we manage differdnt firewalls and also store the logs of these firewalls. This panorama

...

Remo by L7 Applicator
  • 1937 Views
  • 2 replies
  • 0 Likes

sync issues

My HA pair went into split brain so I rebooted the secondary and now they will not sync

jdprovine by L4 Transporter
  • 3397 Views
  • 7 replies
  • 0 Likes

site 2 site with Meraki NAT'd behind ISP router??

We have a remote site connected behind ISP router and Meraki receives 192.168.X.X IP from it, and all networks locally are connected further to Meraki. The main site has public IP directly on the firewall. Not sure how to make configuration work. 

raji_toor by L4 Transporter
  • 7030 Views
  • 7 replies
  • 0 Likes

Resolved! Issues with netflow.

We are having issues getting our information from our PaloAlto 5020's.  It looks like it is sending but we do not have any chartable information on either of our netflow servers.  We are using Solarwinds Netflow Traffic Analyzer as well as What's up

...

  • 24202 Posts
  • 117 Subscriptions
Top Liked Authors
Labels