General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

Resolved! High DataPlane CPU at PanOS 7.1.9

Hi everybody I have upgraded a Pa-3050 from 7.1.8 to 7.1.9, all seems to be OK but the DataPlane CPU is above 90% Management CPU 16%Data Plane CPU 95%Session Count 37023 / 524286 I noticied if the session count is lower, the CPU also decrease , but this behaviour didn't happens in the previous release. Do anybody knows if there is a problem with...

SOC_CSG by L4 Transporter
  • 8649 Views
  • 8 replies
  • 0 Likes

DNS Sinkhole and Honeypot to Record URLs accessed

We've set up DNS sinkhole and it works as expected. We're able to find out which IP addresses tried to access malious sites. However, we won't be able to see the URLs these IPs were trying to access. We're thinking of building a honeypot (or maybe something else) to accept access requests from these IPs and set the sinkhole IP addrss to this mac...

Global Protect Internal Gateway- Prompt a user with remaining login/lifetime.

We are planning to use Global Protect to learn user-ip-mappings. Straight forward Internal Gateway/s Architecture with 2-FA.User Logins to the portal(LDAP) and 2FA prompt, a succesful login will update the ip-user-mapping on the firewall. However, In the early testing stages found out that GP-Client/Agent doesnt give a 2FA prompt once the sessi...

SuryaR by L3 Networker
  • 2232 Views
  • 1 replies
  • 0 Likes

Resolved! 8.x UserID Agent - Two installers

Why does the 8.x user agent install have two different installers. Can somebody explain the purpose of the two? In the case of the latest version I see: UaCredInstall64-8.0.2-20.msiUaInstall-8.0.2-20.msi Thanks!

bbilut by L3 Networker
  • 8331 Views
  • 1 replies
  • 3 Likes

PA-200 and PANOS Version 8

Hello everyone, A few days ago I was testing version 8 with a few PA-200s that we have in our lab, tested new features mostly with user credential Submission. I found that the performance of the devices were impacted (Data Plane CPU was around 70%-95%) only having one or two devices connected to it, is there any advise of using version 8.0.x f...

Resolved! DUO MFA Issues

I am trying to test the DUO MFA and have followed the instructions in the youtube video, and in the admin guide. I can reach the https site under normal circumstances and I can see traffic in the traffic logs. As soon as I enable the authentication policy, the site cannot be reached, no new traffic logs are generated, and no authentication logs ...

PF by L1 Bithead
  • 2832 Views
  • 1 replies
  • 0 Likes

Resolved! HA pair App and Threat sync to peer question.

Hi All, Apps and threats on the currently active box are set to download and install, on the passive to download only. Active box received and installed new updates. Will that automatically be synced to the passive? If we have a revert scenario where the Passive device has its apps and threats configuration to download and install, but the Acti...

Sophos Install & Updates From DMZ

Anyone create a policy allowing a Sophos AV install and then Updates form a DMZ? I have created such a policy but still seems to be an issue. The security policy has all the source and destination zones and the destination host are any. I am then allowing the following applications (not using ports at all)dnsms-ds-smbmsrpcnetbios-ccsophos-live-p...

Resolved! PanOS 8.02 and UAgent 7 vs UAgent 8

Hello. I have recently upgraded our PA-5050 to PanOS 8.0.2. I went to upgrade our UserAgent from v 7.0.7-13 to the new 8.0.2-20 version on our Windows Domain Controllers I was getting errors during the install process and then realized our DCs were NOT 2008R2, only 2008 Service Pack 2. I also noticed we do not run any "read-only domain controlle...

dannon by L3 Networker
  • 2858 Views
  • 1 replies
  • 0 Likes

Source Users don't show up in Traffic & Threat

My problem is the Source User in Monitor > Logs > Traffic & Threat don't show for all users. All other columns including Source and Destination IP are displayed properly. The unshown users can be from trusted lan/wlan/vpn zones and is going to trusted lan or untrusted wan zones. The application they run can be ssl, facebook or dns.....

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels