General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SSL Decryption issue (wrong certificate)

Hi All,

 

Having SSL Decryption issue with one of the websites at the moment (https://wiki.freeradius.org/Home)

So testing without decryption and checking certs chain:

 

 

Can see root CA on Palo:

 

 

So all looks good. Implementing SSL Decryption (test versi

...

PA1.PNG
PA2.PNG
CERTS.PNG
BBC.PNG

Resolved! Feed / data control

Use Case: Ofice 365 Access Control

 

What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked?

What happens on the firewall if there is no data from a feed wher

...

General question to software updates of Palo Alto Firewalls

Hey guys,

 

I have two PA-3020 firewalls with 7.0.7 installed.

 

I want to upgrade to a version of 7.1

 

Since I have never made an update before, I'm a bit worried about it.

 

How do you perform updates?

 

Can I just pick the latest version (currently 7.1.7)

...

MPI-AE by L4 Transporter
  • 3045 Views
  • 8 replies
  • 0 Likes

Resolved! IKE Gateway OK button is greyed out?

I'm trying to add an IKE Gateway on a PA-500 running 7.1.5.

After clicking the ADD button and filling out all the info on General and Advanced Options tab, the OK button is greyed out.

I have a few IKE Gateways set up already and they are working fine.

...

jgruman by L0 Member
  • 3547 Views
  • 3 replies
  • 0 Likes

EXE file type blocked

Hi,

 

I've one client complaining about exe file type get block without any file blocking profile configured.

I made sure we remove the whole security profiles from the security rule configured but still got the same.

I got File Transfer Blocked exceptio

...

PA-3050 CPU dataplane issue

We have a PA-3050 on softwarre 7.0.8 and are struggling with CPU dataplase issues during normal business hours.   80 % load is shown by dashboard in webgui.  Session count is approx. 80 000 when issue occurs.

 

 show system resources follow  - only say

...

TorC by L1 Bithead
  • 4741 Views
  • 6 replies
  • 0 Likes

Resolved! PA-5050 Google search engine issue?

Hi Guys,

 

Having an interesting same time strange problem. Don't think it is Palo issue but decided to post here if somebody has seen the same before. Trust > Untrust traffic NATed to the external interface. All users affected but for test we do have

...

no pop up.PNG
when working.PNG

Panorama location best practice

I have deployed Panorama in our LAN and plan to manage a global install. Now I realized that remote firewalls cannot reach it until they have their VPN setup (which I prefer to do using Panorama too).

 

What is the best practice to solve this? Should P

...

Download fails at 35mins mark

I am trying to download an ISO from microsoft site. It is around 5.2gb file and it has failed few times now around 4.7gb/35mins mark. Logs shows access allowed. using PA200 7.0.9.

Resolved! Policy lockdown question

Hi all, maybe obvious question but it there was to lock down a firewall policy to just a particular. Example only John Doe can make changes to Rule#1 and 2

Resolved! Github Pan-configurator tool

Trying to install and use Pan-migrator what does below mean and how does one resolve it


C:\Users\frankcl\Downloads\dev\dev\pan-configurator>git pull origin master
fatal: unable to access 'https://github.com/cpainchaud/pan-configurator.git/': Could n...

GP certificate differences in 2.3 and 3.1

Hi,

 

We have an internal CA, we have a certificate generated and it is used for GP portal/gateway only, clients are authenticating via usual credentials. Nothing fancy overall. So there are external clients who do not have CA cert installed, so they a

...

nikoo by L3 Networker
  • 1601 Views
  • 1 replies
  • 0 Likes
  • 23674 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels