General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 309 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3651 Views
  • 2 replies
  • 14 Likes

Upgrade to 7.1.6 application-default issue

So the release notes for 7.1 say that "When you configure a Security policy rule with the Application setting Any and the Service setting application-default, all applications are now permitted only on their standard ports as defined in Palo Alto Net

...

jtuten by L0 Member
  • 2024 Views
  • 1 replies
  • 0 Likes

Resolved! Wildfire - Connection hold

Hi all,

 

Just a question:

 

I didn't understand Wildfire mechanism related to a single session.

Is there a connection hold when waiting for a response (benign, malicious) from PA cloud by default? Is that configurable?

If the answer is Yes, but where?

 

Bes

...

What should we buy for active passive HA?

Hi,

 

We are using pa-3050 running 7.1.x with 3 year premium partner support and 3 year threat prevention license for about 2 months. We want to setup active passive HA. So What do we need to buy? Will buying only pa-3050 hardware without any support o

...

Skype is not working properly.

I am using skype for my office work. As i can send messages to others but i am not reciving messages from there side. And they are sending. If i check skype on mobile than i am able to see all messages. But on PC i am not receveing any of messages.

Ca

...

Chroomebooks and Transparent Authentication

We are a school district with 2-3,000 Chromebooks.

 

Currently, we have a Palo rule based upon subnet that applies correct filtering policy.  The problem is that we can't see which user is logged in, only the IP address.

 

Does anyone have a solution for

...

dannon by L3 Networker
  • 3005 Views
  • 6 replies
  • 0 Likes

Custom Report for Phishing Attempts

Folks,

 

Trying to make a custom report for phishing attempts in PANO. At a loss on how to do it for our 60+ devices.

(LIke a daily report).

Anyone here have any input? Couldnt find anything on the web for "phishing" specifically.

 

Thanks folks...

upgrade path for 5020

Hi

 

we have a requirement to upgrade a 5020 HA pair from 6.0.5-h3 to 6.1.15.

 

Can I confirm that 6.1.0 is the only interim release needed?

 

thanks

Resolved! Time-out Rule

We get a bunch of threat alerts from a single source IP from time to time, like someone running a script on or scanning a specific host for vulnerabilities. Some traffic is allowed through to the host. Does anyone know of a way to put an IP in a time

...

MineMeld Miner's no worky...

MineMeld Guru's,

Any advice on why Miners aren't downloading indicators is much appreciated.

 

Here's where I'm at...

-Running version 0.9.30

-System tab says everything is running

-Nodes claim they are connected but haven't pulled in any additional indica

...

running.PNG
indicators.PNG
nodes.PNG

PA is sluggish

I have removed a lot of rules and am down to 400 rules, I am up to OS 7.0.10 and upgrade the OS every other month

In the las couple months the PA seems to be getting slow and not as quit to commit changes or to pull up the dashboard when I first login

...

jdprovine by L4 Transporter
  • 2850 Views
  • 10 replies
  • 0 Likes

Resolved! Traps Pricing

Does anyone have a rough idea of how much traps runs per endpoint. We run roughly 800 laptops and desktops that this would be deployed to but I'd like to get a rough idea of pricing to determine if this is something that management would actually try

...

BPry by Cyber Elite
  • 2864 Views
  • 6 replies
  • 0 Likes

BFD in Active Active HA

Figured this out the hard way.  If you create a custom BFD profile in Active / Active HA mode, the BFD profile names need to be unique to each device.  If you try to configure a BFD profile with the same name on both devices, BFD will not come up.  

 

...

Resolved! "decrypt-unsupport-param" error on Inbound SSL Decryption

I am trying to get inbound SSL decryption for our web server. I imported our web server's SSL certificate with private key to the Palo. It shows "Valid" and the "private key" checkbox is checked.

 

But the log shows it is not getting decrypted, and I'm

...

Maxstr by L3 Networker
  • 20194 Views
  • 18 replies
  • 0 Likes
  • 24185 Posts
  • 100 Subscriptions
Top Liked Authors
Labels