General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Data Exfil Blocking policy

Hi All, We were planning to implement some egress rules to protect any king of large uploads/data exfil activities from inside network.And when thinking through it, the first though came to my mind is to block all outgoing connections, except web-servers and some legit services like ssh etc.But then thought, that it might get lot of pushback and...

Fatema by L2 Linker
  • 2783 Views
  • 2 replies
  • 0 Likes

Resolved! Is it possible to create custom role in PAN-OS that allows management of administrator accounts?

I would like to create a custom Admin Role in PAN-OS 7.1.9 that is like a system admin for the device with the ability to configure and manage authentication, logging, licensing, certificates, dynamic updates, software, and administrators; however, when I am creating a new Admin Role, the Administrators and Admin Roles items can only be set to R...

Resolved! Support dial in number

Hi I have tried to use the australian number 1 800 002 378 after wating 50min plus with no contact and also using their leave your number we will call you back and not having done that in the last 3 times. I'm wondering how the other regions call in supports numbers are working. Thinking I might call US, but not if I am going to be waiting mor...

Resolved! commit failed with configurations invalid!

Hi PA Community, I got one issue with client where the commit is failing with details of only "Configurations Invalid" without any further details.We wanted to change the management interface IP to a different one and the commit is not accepted, even the validation is failing.I tried to made any other changes rather than mgm IP change and got th...

Problem in making palo alto test lab

Dears ,i installed palo alto ova and windows xp client and host is windows 10 , i am trying to make a test lab using cbtnuggets and my configuration as the following :1- windows XP is on VMnet3 and has IP : 10.3.3.11/242- i added all VMnet to palo alto virtual machine to be able to make inside , DMZ and outside3- i configured interface 1/1 in th...

Resolved! IKEv1 phase-2 SAs increasing

Hello, We are trying to clear and initiate IPsec connection using the following commands: clear vpn ike-sa gateway <value>clear vpn ipsec-sa tunnel <value>test vpn ike-sa gateway <value>test vpn ipsec-sa tunnel <value> However, the SA’s are not clearing , instead they are increasing. Any idea how to stop and clear them? I...

Farzana by L4 Transporter
  • 2397 Views
  • 1 replies
  • 0 Likes

Inbound SSL Decryption issues

Wondering if anyone has an idea on why I might be getting "decrypt-error" on an Inbound SSL decrypt rule? This service only runs a few times at night so I haven't done a packet capture yet... tonight I did some debug commands and found this in the log: 2017-07-31 22:00:15.865 -0500 Error: pan_ssl3_client_process_handshake(pan_ssl_client.c:871): ...

jsalmans by L4 Transporter
  • 7191 Views
  • 9 replies
  • 0 Likes

What is the long term plan for MineMeld

This project seems to be a very capable platform and I'm considering incorporating this into our environment. However, I have concerns about viability of this as a long term supported solution. Does this community provide any executive summery type documentation for management level with regards to what's supported by palo alto and what's commun...

Resolved! Export CSR via SSH

Hello, I have created a CSR: request certificate generate country-code DE days-till-expiry 1100 email NOC@DOMAIN.COM locality BERLIN signed-by external organization MYORG ip 1.1.1.1 algorithm RSA rsa-nbits 2048 certificate-name testcert name test.domain.de Looks fine and I can also see it in the WUI. Now I would like to export it via SSH: ...

OCEDTRA by L1 Bithead
  • 4586 Views
  • 2 replies
  • 0 Likes

File blocking

I have setup file blocking object but it does not seem to stop all downloads.. (Ex.. Try to download file from cnet.com it gets blocked.. If I go to adobe and download adobe reader the setup file downloads). Also is there a way to block all files except pdf without setting up file type rules?

rmsdip3 by L1 Bithead
  • 2103 Views
  • 1 replies
  • 0 Likes

VPN implementation best practice

I have a VPN configuration and testing with my vendor during business production hours. I am new to PA, so I am just wondering if I should schedule this during a maintenance window.The VPN implementation includes:- tunnels- IP addresses- static routes- BGP routes Thanks

jac101 by L2 Linker
  • 1896 Views
  • 1 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Labels