General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 261 Views
  • 0 replies
  • 1 Likes

Confused over EBL size limit

We have a 3020 running 7.0.8 and are experimenting with MineMeld.

 

As soon as we get close to 5k IPs on the combined EBLs we get an error on a EBL refresh that it's been truncated as it's over the limit.

 

Palo Alto's own KB suggests that on an entr

...

Resolved! Migrating old FW Config to new device

I have 2 PA-500's and have been planning to purchase a new device.  Perect timing with the new PA-800's, fits my needs and then some.  Is it possible to migrate my current configurations from the 500 to the 850?

 

Network-ethernet-Radius-Users wtc as w

...

Resolved! Is the Intel Atom c2000 platform in any Palo Alto Products?

There is an advisory released by Intel (and probably Cisco) about the Intel Atom c2000 platform and a clock signal component failure that can brick devices using that platform.  The Atom c2000 was marketed towards (among other uses) networking equipm

...

bshelton by L0 Member
  • 3157 Views
  • 2 replies
  • 0 Likes

License Transfer

Hello,

 

I am not sure if this is the right place to seek this type assistance.

 

Is it possible to transfer subscriptions from PAN-3050 to VM-300 or VM-500?

 

The client has a pair of PAN-3050 with TP, URL4 and Wildfire subscriptions which will be expired

...

MiZhang by L0 Member
  • 2552 Views
  • 2 replies
  • 0 Likes

Resolved! Skype is not working with allow rule

Hi,

 

We have a demand to allow skype for internal employees. However, we've created a security rule to allow the following applications:

 

-skype

-skype-probe

-ssl/web-browsing

 

Still skype couldn't connect with an error message "please check your internet

...

URL Reclassifications to Unknown in 20170207.20264

Hello,

 

I was just wanting to see if anyone else has noticed that in URL DB 20170207.20264 many sites are being reclassified to Unknown?

 

sites include 

www.maxtend.com.au 

fairfaxstatic.com.au (used for Australian Financial Review website)

cdn.newsapi.co

...

PhilH by L2 Linker
  • 3091 Views
  • 5 replies
  • 0 Likes

Natting issue with new subnet.

I am applying destination nat. Natting public ip(untrust zone) to internal ip(trust zone). Public ip subnet is /28.

When access public ip in the monitoring logs it shows me dst zone as Untrust whenit should show dst zone as Trust.

I have policy in plac

...

Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0

Hi.

 

I've been running PAN-OS 8.0 since release, and immediately got problems with Cisco AnyConnect over IKEv2. Even if the session is very much alive, PAN-OS 8.0 kills it of after a random amount of time, usually a couple of hours.

 

If I change the An

...

GI-1 by L1 Bithead
  • 2708 Views
  • 5 replies
  • 0 Likes

Light blue vs dark blue IP's

I have noticed that in the policies that some IP addresses show a dark blue and underline all the time and then there ar IP's that are a lighter blue and the underline only appears when I have my cursor over the IP. anyone else seeing this and is it

...

jdprovine by L4 Transporter
  • 3934 Views
  • 12 replies
  • 0 Likes

Multicast questions

Hi,

 

I am not famliar with Multicast at all, please forgive my ignorance.

 

I need to replace Fortigate firewalls with Palo Alto devices and the Fortigates are currently running Multicast. There are no "groups" defined on the fortigate, and if I run "ge

...

Resolved! SSL Decryption issue (wrong certificate)

Hi All,

 

Having SSL Decryption issue with one of the websites at the moment (https://wiki.freeradius.org/Home)

So testing without decryption and checking certs chain:

 

 

Can see root CA on Palo:

 

 

So all looks good. Implementing SSL Decryption (test versi

...

PA1.PNG
PA2.PNG
CERTS.PNG
BBC.PNG
  • 23628 Posts
  • 107 Subscriptions
Top Liked Authors
Labels