General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

APP-ID and HIgh Port range

Is ther a range of tcp/udp ports that do not have a APP-ID in appipedia? I ask b/c as we are migrationg over 10k rules we are aware not all of them will have PA app-id assoicated so we are trying to filter out those ports and jsut curious is there a acutal port range or specific ports that do not have APPID's

Resolved! Enabling a Systems Maintenance page for systems at the PA?

Hi folks, We have a public IP that NATs to an internal Barracuda Load Balancer VIP that represents several sites, content rules, etc.I am being asked if we could temporarily change the NAT translation at the firewall to redirect to a maintenance page while we take these servers down for patching, instead of editing rules at the Load Balancer. It...

OMatlock by L4 Transporter
  • 2743 Views
  • 2 replies
  • 0 Likes

Resolved! PAN 7.1.9 aes-256-cbc vs PAN 6.1.10 aes256

I need to move a tunnel from a PAN with 6.1.10. The tunnel today uses aes256 for IPSec crypto and for IKE. The tunnel established fine to our biz partner. In configuring the tunnel on the other PAN with 7.1.9 I notice that my options are aes-256-cbc or aes-256-gcm for IPSec and IKE Crypto, Add offered aes-256-cbc. My question: If I select aes-25...

palomed by L3 Networker
  • 2560 Views
  • 1 replies
  • 0 Likes

Resolved! Configuring destination NAT with DHCP public IP

I only get a dynamic public IP from the ISP on the outside interface of the PAN box. I'd like to configure Destination NAT to use the single public IP for number of servers running inside network on different ports. I've followed the documentation online to configure Destination IP and Port Translation. I received the following error when trying...

PAA at Jul 11 16-22-22.png

S2S VPN Between PA and Cisco ASA

Hello! I've spent the last 2 days trying to get an IPSec tunnel working between a PAN 200 and Cisco ASA5505 but all my attempts have failed. I am not sure what the issue is and would reall appreciate any assistance to point me in the right direction. This is a very simply setup. I've configured both sides properly but for some reason the tunne...

Problems with Traps conditions after update

Hi all, One of our resellers has reported a problem to us. A condition, configured in a Traps environment, is not working anymore after they updated from version 4.0.0.24417 to 4.0.1.25216. Is there something known about this problem? This is the condition: Could someone help with this? Thanks and Regards,Federico

Condition.jpg

Blocking apps

Hi At the moment what is most annoying is the blocking external emails, for example, Gmail, depending on which browser you open appears as "gmail", as "ssl" or as quic. We have configured a block list for that, the problem is that users are starting to place them in the mail clients of W10 and Outlook, and we return to the same, Palo Alto sees i...

Recorded Future 401 access error

Hello,I am currently in the process of moving our threat feeds into Minemeld. One of our providers is Recorded Future, which i have enabled as a node, and set the API access key. when i go to run a the mode, it gives me a 401 client Error: Unauthorized naturally, i checked if the API key was incorrect, but i am still able to manually grab the fe...

JonasE by L1 Bithead
  • 8457 Views
  • 5 replies
  • 0 Likes

Resolved! Per-User URL Filtering Process

Can someone give me a break down of what the process flow is like? For example, Is a lookup done for the user then an IP mapping happens? Are the user-ip mappings being used for the decision in the filtering process? The reason I ask is that I have users connected via a VPN device the filtering doesn't seem to work.

Best Practices for Site-to-Site IP/Interfaces?

Hi all, I've currently got a site-to-site VPN tunnel already configured for one of our cloud services but we've got a request to add another service from another provider. Our current config has a single floating IP address with the associated tunnel configuration and assigned to a "Site-to-Site" security zone. I'm wondering what best practices...

jsalmans by L4 Transporter
  • 9996 Views
  • 10 replies
  • 0 Likes

Resolved! Security policy conflicts between the Application and Services?

Hi all. I am playing with security policy, and seeing a result that I am not expected.Basically I would like to allow connection from the Local (trusted) zone to a specific server in the DMZ zone to allow port 443 (ssl) traffic onlyIn the Source section, to simplify things a bit, I set to "Any, Any" (all user in the Local zone is allowed to acc...

Error "An instance of GlobalProtect is already present on the system."

Hello, 1. I unstalled the GlobalProtect for Windows 7(64 bits) then tried to install ProductVersion = 3.1.5. But I encountered the same error as follows over and over even after I followed up the comment in the link(https://live.paloaltonetworks.com/t5/Configuration-Articles/GlobalProtect-Error-During-Installation-quot-An-instance-of/ta-p/51937)...

GlobalProtect_error.png

Resolved! can't login to web console

The web console throw the bad gateway error, also status of minemeld-web service is FATAL except for minemeld-engine and minemeld-trace which has RUNNING status. How can I fix this?

Sergey_R by L1 Bithead
  • 23069 Views
  • 15 replies
  • 0 Likes

Resolved! Prototype to pass additional 'fields'

Hi, new user here trying out a local instance of minemeld. I would like to know if there is any way to set up a miner node that will parse and pass along more than just the 'indicator' from the source feed. Specifically, some source feeds contain more information along with each indicator such as ASN info and country codes. An example of a proto...

nickd5 by L0 Member
  • 4069 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels