General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4124 Views
  • 0 replies
  • 0 Likes

Resolved! Clarification around URL Filtering licenses

I just wanted a quick clarification around what you Can and Can't do without a PANDB license, I know you can create Custom URL categories without a license, but can you also use Dynamic External Block List, or can you create a security policy and manually define URLs you want to block? Or does anything around URLs require a PANDB license

nrobison by L1 Bithead
  • 10999 Views
  • 4 replies
  • 0 Likes

"icloud-base" excessive hits on firewall

Hi there, I have a question in regards to iCloud (application = icloud-base) and I was hoping someone could shed some light on or point me in the righht direction. I have a source address which is showing in the URL Logs as blocked due to our restriction on 'online-storage-and-backup'. normally I could see a source IP hitting this about 10,000 p...

Resolved! SSL Decryption not working in chrome

Trying to configure SSL Decryption and googled this to no end.I have an Enterprise CA, created the cert with that, I can see that the GPO's have deployed to the cert to the users.In my testing I only have decryption turned on for one user. Internet Explorer works fine as best I can tell it's not even noticing.Chrome on the other hand is not amuz...

DaleK by L1 Bithead
  • 6307 Views
  • 7 replies
  • 0 Likes

is there autofocus artifacts miner

Hi, I am looking for autofocus artifact miner, and in minemeld app, I found "autofocus.artifactsMiner". But when I check my vm ubuntu, I could not find it. How Can I copy and re-use this "autofocus.artifactsMiner" to my ubuntu minemeld ? Thanks.

Resolved! NAT configuration - DMZ zone to Trust zone

I've had a total brain fade, and am unable to figure this out. Hoping you guys can help. Network topology is relatively simple. Firewall has three zones - outside, inside and DMZ - DMZ has a /25 of "real" Internet addresses on it. Outside has a /30, also of "real" address, and most traffic from inside is translated to the interface address of th...

darren_g by L4 Transporter
  • 7634 Views
  • 2 replies
  • 0 Likes

Tcp service report for rules

Is there a report that I can run that will show me every rule that has tcp service applied? For example let's say migration tool is not an option and I do not want to scroll through 3000 rules to manually look. Or can I can export all rules and somehow use excel filtering on service field

Restrict Any Any from Security Policy

Hi There, At one of our sites we fell vicitim and have the dreaded any any security policy in place. We are trying to determine the best course of action to lock it down. Would I create tap firewall ports and span all the traffic, then create new rules based on it in tap zones? Any guides out them to assist for this specific situation?

nicford by L2 Linker
  • 3097 Views
  • 4 replies
  • 0 Likes

DOS protection rule

We are thinking of creating a DoS rule and I was wondering what the group thinks of this rule and what affect it would have.

DoSrule.PNG
jdprovine by L4 Transporter
  • 6271 Views
  • 14 replies
  • 0 Likes

Resolved! Content s and Apps Updates

We have two 3050 units managed by Panorama. I have two related questions: What is the difference between Apps and Contents in Dynamic Updates? If we have a support contract for the firewalls and Panorama but don't subscribe to Antivirus, Threats and Wildfire do we need Content updates or just Apps?Thanks for any help.Jeff

Moving from a single PA500 to HA pair of PA820

As the subject states we are single PA500 shop now moving to Dual PA820 in HA.What can I expect when moving to this type of setup coming from a single FW setup.Is there anything I need to look out for any "Gotchas"? So far I know I am using 5 copper ports on the PA500 and the PA820 only has 4 so I know I will need a module. Can anyone think of ...

CTaveras by L1 Bithead
  • 8842 Views
  • 15 replies
  • 0 Likes

Resolved! Panorama import config of firewall

Hi So setup my HA cluster woo hoo. So now I have setup panoram I have gone to managed devices and added in my 2 PA from above - by serial number, I can see then, I can change context into them. I went to each PA and add in the FQDN for the panoram in the setup panoram section Now I go Device / Setup / Oprations / Import / IMport device configur...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels