General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! How to specify which program generates malicious traffic?

Hello all, I know this question is outside of the PAN device matter. But my customer asked me how to specify the program on his computer for removing malicious program.Let me tell you exmaple: When I see threat log, it showsSrc 192.168.1.1:12345 Dst 100.100.100.100:80 We can understand that we need to investigate 192.168.1.1 device.On this devic...

emr_1 by L6 Presenter
  • 3043 Views
  • 1 replies
  • 0 Likes

Resolved! PA cannot distinguish between Dropbox and Cloudfront

Hi, PA does not seem to be able to distinguish between Dropbox and Cloudfront. In the Traffic logs, all sessions are identified as dropbox-base. Outputs from show session id: DROPBOX:start time : Thu Aug 3 09:58:15 2017timeout : 120 sectotal byte count(c2s) : 4843total byte count(s2c) : 6128layer7 packet count(c2s) : 11layer7 packet count(s2c) :...

Farzana by L4 Transporter
  • 4565 Views
  • 3 replies
  • 0 Likes

Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs

Hi...i have two PA Boxes(4.1.9) and one User-ID Agent(5.0.4-5)i've got unknown message from User-ID Agent log. ===== UaDebug Log ===== 06/17/13 08:57:50:139[Debug 911]: Unable to probe IP 172.19.73.93, list is full with 201 entries, currently probing 40 IPs 06/17/13 08:57:50:139[Debug 911]: Unable to probe IP 10.201.120.66, list is full with 2...

willstech by L3 Networker
  • 7635 Views
  • 5 replies
  • 0 Likes

Problem rebooting/shutting down firewalls through Panorama

We are running Panorama 8.0.4 with TACACS for authentication.I have noticed that when I switch to the context for a device, or Panorama itself, the options for rebooting/shutting down a device are missing.If I navigate to Device->Setup->Operations, the only options available are for manipulating the configuration.I have checked and the adm...

Resolved! policy drop with icmp not sending icmp

I have a catch all before the default/inbuilt rulesmy action is drop with icmp but when i test and run a tcpdump at the same time I see no icmp packet to say unreachable . Very strange ? Anythoughts ??

MSFT Office365 Domain As Phishing?

I was running a 228 PAN-DB version and have since noticed the content version updated. Did anyone else have any issues with Office365 services? ME @firewall(active)> show running url secure.aadcdn.microsoftonline-p.comDP dp0:secure.aadcdn.microsoftonline-p.com phishing expires in 380 secondsDP dp1:secure.aadcdn.microsoftonline-p.com content-...

PA-220 boot Error?

Received this Unit today and on 1st boot, N0.LMC0 Configuration Completed: 8192 MB Warning: Board descriptor tuple not found in eeprom, using defaults KINGFISHER board revision major:1, minor:0, serial #: unknown OCTEON CN7130-AAP pass 1.2, Core clock: 1000 MHz, IO clock: 500 MHz, DDR clock: 800 MHz (1600 Mhz DDR) SPI stage 1 bootloader SPI ID: ...

Resolved! Query on L2 bridging over a L3 network

Hi, We have a pair of PA-500s separated by a L3 MPLS IPVPN network. We require to bridge a layer 2 segment across the two sites. One option we would like to explore is going from PA to PA on a new physical port at each end. We need to bridge HSRP and GRE traffic from third party vendor routers at each site. Does PAN-OS8 have the ability to bridg...

Farzana by L4 Transporter
  • 3000 Views
  • 1 replies
  • 0 Likes

PA apps

Hi, We are expecting problem with PA identifying apps.We have sessions in port 13000 being identified as play-station network. These sessions are not related to Pstation. On the another hand, we also have sessions in port 80 being identified as unknown-tcp. why PA is idenfitying like this?? how can we solve this app problem??

Resolved! Problems with assiging ip address to vm-50 on hyper-v

I have some problem with assigining ip address and other parameters to vm-50 on Hyper-V.I have downloaded vhdx file of pan-os 8.0 and installed it.but after i set the ip address it doesnt save the setting.i type commit but nothing changes.unknown ip address.

Screenshot_1.png
Screenshot_2.png
Radmin_85 by L4 Transporter
  • 3963 Views
  • 1 replies
  • 1 Likes

Resolved! Security polices and nat and cluster

Hi So I have a active / active cluster, but I am not sync my VR config. I am connected to an OSPF network lets say my internal network isOSPF int ae1.19 192.168.19.0/24loopback.1 192.168.255.25/32 and 192.168.255.26/32 - ospf routerid (one for each PA)appserver int ae1.25 192.168.25 .2 .3 .1 (.2 & .3 are the router ips, .1 is the HA VIP...

DSRI on IPSec/VPN traffic

We have a rule allowing VPN traffic (IPSec) from our Guest environment. This traffic is non-decryptable. We would like to reduce CPU by disabling Server Response Inspection for this traffic? Do we lose anything from a security perspective if we do so? If there is a change in the application, will app-id still detect it?

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels