General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! MS O365 Dynamic IP addresses/Urls of Endpoints Url for MineMeld

In effort to understand the processing of the Microsoft Office 365 MS O365 Dynamic IP addresses/Urls of Endpoints Url (see MS url below) by the MineMeld application, where is the configuration file with this MS Office 365 url stored for the Minemeld application? https://support.content.office.net/en-us/static/O365IPAddresses.xml The Minemeld YAM...

Trek333 by L0 Member
  • 11482 Views
  • 2 replies
  • 1 Likes

User-ID suddenly stops recognizing Users

I'm using PA-5020 as a Perimeter firewall with User-ID implementation for 5000+ users with multiple User-ID Agents across network.Palo Alto Version : 7.1.8User-ID Agent Version : 7.0.7-13 Problem i'm facing is the User-ID Agent, all of a sudden it stops recognizing users and it causes the users distruption in services accessing different applica...

Screen Shot 2017-06-28 at 11.12.41 AM.png

Using new MineMeld file hash indicators?

I see that new indicator types for file hashes (MD5, SHA256, SHA1, SSDEEP) were added in MineMeld 0.9.26 this is awesome, but should those indicator types be selectable from the ( NODES > ADD INDICATOR > TYPE ) drop down menu? I don't see them listed so I'm just trying to figure out how to employ the use of these new indicator types. I'm...

Resolved! Determining safe starting thresholds for Zone Protection

I've been asked to investigate Zone Protection on one of our PAN firewalls. I'm trying to determine what safe values would be for me to begin with for syn, icmp, udp and other ip protection types. Since this is a production firewall, I need to be certain I'm not going to generate any issues when the profile is applied. Is there a way for me to...

epeeler by L2 Linker
  • 3631 Views
  • 2 replies
  • 0 Likes

Resolved! Large amounts of google-base traffic

I am looking into abusers of our bandwidth and have found one person who has 11GB in a day reported as google-base and from the low number of sessions (18), I suspect it's file transfer. I could understand tht much traffic being google drive but surely that would be reported as that sub category and not "base". Why would large amounts of traf...

djr by L4 Transporter
  • 5086 Views
  • 2 replies
  • 0 Likes

Resolved! Palo Alto VM-100 installed on VMWare workstation is unable to connect to internet.

Hi All, I have installed a Palo Alto firewall on my vmware workstation 8.0, with current settings i am able to access the Firewall GUI from my machine browser. But unfortunately, i am unable to connect to internet via firewall interface. I have 3 interfaces namely - mgmt, Untrust and Trust. I am trying to update license on firewall which require...

Diagram.PNG
error.JPG
virtual network editor.JPG
network interfaces.JPG
shafhuss by L0 Member
  • 4356 Views
  • 1 replies
  • 0 Likes

Resolved! Firewall not advertising the public IP

Hello, We want to allow traffic from outside to come inside our server however cannot see any traffic unless loopback is used. This server is behind DMZ. We can solve the public IP address of the server when we go to www.whatismyip.com Traceroute stops at 13th hop before we added loopback for the public IP. We are using Source NAT like below: In...

Farzana by L4 Transporter
  • 3639 Views
  • 4 replies
  • 0 Likes

PA Traffic is logged under different users other than the logged in user

Hi guys, We have a security rule that grant a certain app access to users based on AD group. User complained that sometime they can access the app and sometime they cant. Checked the firewall and found out that some of the traffics are logged under different user accounts, hence the right policy didnt get applied. User is using OSX (mac) and has...

2017-08-22_13-44-18.png
ESutedy by L1 Bithead
  • 3558 Views
  • 4 replies
  • 0 Likes

Microsoft blogs page cannot be loaded though paloalto

Hi, I have constructed Palo Alto on Azure and now all connections are allowed to connect.However it seems Palo Alto blocks below website. https://blogs.technet.microsoft.com/ I already checked I can access without palo alto and i think it is the cause of this issue.I think I should contact support but i am unable to create my support account. I...

キャプチャ.JPG

Need help on PaloAlto OID

Hi Experts , Looking for OIDs to monitor below mentioned list , using SNMPv3 for Palo Alto on AWS cloud but unable to locate any MIBs or OIDs. BGP (Established , down)Tunnels ( IP , Status , Traffic Stats)SSH (User IP , Count) Any help will be highly appreciated. RegardsFaiz.

How to terminate Live community account?

Last month I have created this account and today i have deployed Palo Alto from Azure...In order to get teachnical support from PA, it seems I need to register account but I cannot use this LIVE community account.So i think i better terminate this account first and create new one with new CID.. Please help me...

error.png

Dual ISP, ECMP, PBF, PAT to access internet, Destincaton NAT to Local Server

Dear Collegues, Need your help & clarify some douts. G1/1 - xxxxx/30 (ISP 1)G1/2 - xxxxx/30 (ISP 2)G1/3 - xxxxx/24 (LAN) Both the ISP have also provided xxxxxx/29 range of usable IPs Have Configured Dula ISP Redundancy with single virtual router by enabling ECMP and link monitor for static routeHave configured source NAT to access internet f...

Unable to connect to a PA 500 using the management IP.

Hi, I have just configured my PA 500 and I set up the management IP to be 10.2.82.3/24. I connected the PA 500 to a switch that has VLAN 80 (10.2.80.x) and VLAN 82 (10.2.82.x) my laptop is ip'ed 10.2.80.40/24, from the laptop I can ping 10.2.82.1 (default gateway for the management vlan), but I can not ping 10.2.82.3. I consoled into the PA and ...

Resolved! GP-VPN traffic is slow

GP VPN configured properly with IPSec enabled.But all the GP-clients are fall-back to SSL tunnel mode soon after connected.For testing purpose, give full access any-any allow in policy. one time connected as IPSec and when disconnect & connect again another time gp-client automatically fall-back to SSL mode. Port 4501 UDP & TCP are allow...

PA System Alert Reports

I am wondering if it is possible to create a report based on the number and type of "System" (Medium, High, Critical) alerts generated by the PA firewall?

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels