General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

TI automation - architecture and hardening [part 1]

Hi everyone, I'm Giovanni Mellini and I work in ENAV (Italian Air Traffic Control provider) Security dept. One of the topics I've been working on over the last few months is threat intelligence‍ automation, or how to automatically integrate threat intelligence feeds into our near-real-time Information Security Operation Center SOC‍ Splunk‍ eng...

soc_enav by L1 Bithead
  • 19738 Views
  • 8 replies
  • 3 Likes

FileZilla & SSL Decrypt

The auto-update feature in FileZilla will break if SSL Decryption is turned on in the firewall. The following URL must be excluded from decryption: update.filezilla-project.org

kalakai by L2 Linker
  • 3680 Views
  • 1 replies
  • 0 Likes

Resolved! Panorama Virtual Appliance V.8

Hi Guys, I wanna update our VM panorama currently running the v 7.1.10 to version 8.my Panorama currently manages less than 10 Devices. Could someone provide me with the requirements (like storage, CPU, RAMs) i need to consider? P.S : Not having Log Collectors enabled and currently running on Panorama- Mode VG,Gilo

big_Gilo by L2 Linker
  • 4828 Views
  • 5 replies
  • 0 Likes

Resolved! Miner to collect AWS IP

I would like to setup a new Miner to collect AWS Ips from the following http://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html, using URL https://ip-ranges.amazonaws.com/ip-ranges.json. How would that be accomlished, I can't seem to locate a good example.

Resolved! Global Protect 4.0.2 -19 only connects with Windows Administrator Account

Hello everybody, recently I am facing a strange Problem with Global Protect. If I log into a Windows 7 Machine (64-bit) with an Administrator Account and enter Credentials of a NON-Administrative Account in Global Protect everything works just fine.But if I log into the Machine with a NON-Administrative Account and try to connect with a NON-Admi...

husetech by L2 Linker
  • 11901 Views
  • 21 replies
  • 0 Likes

Resolved! Importing a WildCard SSL to use with GlobalProtect

Hi All, Im trying to import a WildCard SSL to use for our Palo Alto GlobalProtect VPN. Im Having some trouble as this is my first time using SSL. I can import the WildCard but im not able to link it to its Root CA (GoDaddy). Do i have to have this signed by the CA before using it? We have also added an (A) hostname e.g. example.companyname.com.a...

DNS proxy to GP clients

DNS configured in GP settings: Primary DNS 10.250.1.1, secondary DNS 10.250.1.2 Access route: split tunnel- 10.250.0.0/16 allowed in GP. Once clients are connected to globalprotect, they are getting the above DNS settings. so the traffic going to internet also resolving in above Internal DNS server. Now i have the requirement for GP users, when ...

Resolved! GP Clientless VPN setup

Hi, i have a PA200 for a testing purposes i want to enable clientless VPN access. Went to Device/licences and i see i do have a licence enabled.then going to Device/dynamic update i do have clientless software uploaded: but when i try to activate it by going to device/ssl vpn client i cannot see it. Looks to me i have it all there but... Do you...

PANSSL.jpg
PANSSL2.jpg
PANSSL3.jpg

URL Filtering of Active Sync

HelloThere is some problem concerning url filtering of Active Sync.we create url rule which must allow Active Sync but it doesnt work.we exclude this rule it is working.is there any particular configuration about Active Sync?

Radmin_85 by L4 Transporter
  • 2243 Views
  • 1 replies
  • 0 Likes

Resolved! Palo Alto global Protect setup issue

Hi All,I'm currently trying to set up an SSL VPN using the global protect client on a Palo Alto FW.I have:-- issue a self signed root CA and CA to the palo- set up VPN tunnel- created VPN zone- setup an authentication profile using RADIUS and directed it to our NPS server which currently policy to allow access to an AD group "VPN Users"which i a...

Resolved! Response pages not always presented to users

My response pages work when users attempt to browse to a blocked category but when the blocked item is buried within the page users just get a blank screen until the connection times out. Any ideas or suggestions would be greatly appreciated!Thanks!

sturek by L0 Member
  • 3634 Views
  • 3 replies
  • 0 Likes

Zone Protection Profile - testing

I've setup a Zone Protection network profile and applied it to our DMZ zone. I changed the default for port scan on the Reconaissance Protection tab to 30 events in 3 seconds. TCP port scan is enabled, and the action is set to block-IP. I run a test by scanning a host in the DMZ, 10,000 ports in 166 sec. That's a rate of ~ 60 port / sec, and ...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels