General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1475 Views
  • 0 replies
  • 0 Likes

Panorama Dynamic Update overlap

Given the best-practices for Dynamic updates here, how do i configure this in Panorama and not have the commit warning for deployment schedule overlapping with 5 mins of another?

 

Its always going to be the case where Wildfire checking every minute wi

...

Restricted access to API?

Hi *,

 

I'd like to know if it's possible to restrict access to the API? (ex: to some IP addresses).

Example: if remote management is allowed from 192.168.0.0/24, is it possible to restrict the API usage to 192.168.0.1 by example?

Is it an option to

...

XavierMe by L1 Bithead
  • 4779 Views
  • 4 replies
  • 0 Likes

Proxy filtering or paloalto filtering

Hi All,

 

i have proxy in my network which is responsible for all filtering and categorizaing , also i bought a licnese for url filtering on paloalto so, is there any benefit to allow filtering and categoriziang on both ?

 

or no need for filtering on pa

...

Decrypting OPENVPN?

Is it possible to decrypt openVPN with SSL Forward Proxy? I'm pretty sure the asnwer is no, but I figured I would ask.

 

My problem is that I have a Ubuntu Server running openVPN client behind a VM-100. I would like to continue to use openVPN, but I wo

...

Hwinter by L2 Linker
  • 5720 Views
  • 4 replies
  • 0 Likes

L7 Inspection

Hi All,

 

i migrated my asa to paloalto , but i can see that all policies are assigned service port but not appliation , so how can i get benefit from from application field ?

 

how can i transfer all polices from l4 to l7

miners throwing errors

In both cases below, Minemeld is running via hosted Autofocus App.

 

It appears that the ransomwaretracker miners are running into an error. All three are throwing a "[Errno bad handshake](-1, 'Unexpected EOF'). The source URLs appear to be functioni

...

jchitsaz by L1 Bithead
  • 5094 Views
  • 4 replies
  • 0 Likes

Securing Access To Chef Deployment Servers

Currently we have a rule allowing the APP "ssl" from many different zones to our Chef Deployment Servers. I am trying to determine if there is a specific APPID for Chef but been unable to fine one. Since the server team says both port 80 and 443 are

...

PA200 time out - reason directory / 100%

Hi,

 

We have a cluster PA-200 with error "Session timed out". I just saw this link

 

https://www.pickysysadmin.ca/2015/02/08/palo-alto-firewall-displays-session-timed-out-when-you-try-to-login/

 

I tried to delete all core files but disk space is still in

...

Resolved! Suspicious TLS Evasion Found

PA-3020

 

Recently I've had several users get a "Virus/Spyware Download Blocked" page on random sites.  Normally they get it on google searches.  If they refresh, sometimes the error stays, and sometimes it just takes them to the page.  

 

It even happen

...

virusSpywareDownloadBlocked.png
Monitor_Spyware.png

Resolved! pa-500, os8.1, oid's missing in snmp

Hi, when I get MIBs from page below to os8:

https://www.paloaltonetworks.com/documentation/misc/snmp-mibs.html

 

I can find out there OID's related to active sessions counters, tcp/udp counters, used memory, etc. while in snmpwalk (v2) I see only some o

...

bkrajnik by L1 Bithead
  • 7964 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect Clientless VPN package update fails

Hello Community,

i have an issue with download the latest version of GlobalProtect Clientless VPN package update.

I have installed from scratch PANOS 8.0.0 and I have a valid Global Protect License but i'm not able to download the package from updates.

...

Updates.PNG
Updates.PNG

Resolved! Different Threat ID for Data Filtering and Wildfire

Hello all,

 

Once upon a time, I stumbled across a page with all the threat ID's used for Data Filtering.

From what I remember"PKG File Detected(52152)"  is the threat name and ID used when the firewall sees a PKG file.  Windows Executable (EXE) (52020)

...

Why paloalto-updates application is SSL now?

Since 03/April/2017 02:00 Firewall detect paloalto-updates application as SSL then firewall can't update new signatures because there is no SSL allow in policy.This problem occur to my 3 customer now.

 

Do anyone have the same problems?

 

Customer 1Custo

...

cust_1.png
cust_2.png
Sarun by L0 Member
  • 3155 Views
  • 3 replies
  • 0 Likes
  • 24203 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels