General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 195 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 878 Views
  • 0 replies
  • 0 Likes

Custom SaaS report possible

Hi 

 

I just wanted to say that i love the SaaS report, and its a good way to look at whats been going on.

 

I was wondering if there is a way to make this a little less techincal and customize it more so i can present it in a meeting with people that do

...

Resolved! Replace 'srcloc' for RFC1918 IPs?

We are using the 'srcloc' field in our logs, and it's pretty handy for Out-->In traffic.  But for In-->Out traffic, we get the "10.0.0.0-10.255.255.255' value.  This is MUCH too large and a lot less useful.  Is there a way to edit the table so that w

...

ptrivino by L0 Member
  • 2351 Views
  • 2 replies
  • 0 Likes

PAN-OS 8.0 - Automatic SSL Decryption Exclusion

Out of curiousity...Doesn't seem too technically smart for a firewall / security appliance come built-in with 121+ Internet based domains to include foreign domains which are automatically excluded from SSL Inspection:

 

From the user help doc:

 

Predefi
...

SSL_Decryption.JPG

Problem wildfire logs after upgrade fw from 6.1 to 7.1

Hi all

i have 2 firewalls managed by panorama, everybody with 7.1.5 recently upgraded from 6.1.

I have a wildfire public cloud configured for an smtp rule to check any file contained in every mail.

A wildfire analysis object profile:

 

 

 

 

 

After the upgra

...

wildfire.JPG

Routing issue

Hi,

 

We are expecting a routing problem. Our Pa is learning router from eth1 from OSPF, so the VoIP traffic is going through this interface properly, on the another hand we have a VPN configured in another ISP just in case OSPF goes down. the problem

...

Captura1.JPG

Disable Hardware Offload

Hi All,

 

Whats the purpose of "Disable Hardware Offload" in Palo Alto Firewall ?

 

Any traffic that is offloaded to the field-programmable gate array (FPGA) offload processor is also excluded, unless you turn off hardware offload.

 

Can anyone please expl

...

Usage of Security Policy in Palo Alto Firewall

hi All,

 

I am bit confuse of the usage of rule no 2 and 3. Eventually they will deny the traffic. But which two benefits are gained from having both rule 2 and rule 3 presents? Any clarification please.

A.    A report can be created that identifies unc

...

PA1.JPG

PAN-OS 8.0 Updates

I've recently upgraded a lab 200 to 8.0 from 6.1.4.

 

After upgrade I couldn't get it to connect out for Software or Dynamic updates, getting an error saying no connectivity basically.

 

I saw the changes about where communication via the mgmt interface

...

Resolved! SIP aged-out session being left in the DISCARD state

Hi Guys,

 

Has anyone come across this when the aged-out SIP session being left in the DISCARD state and the only way you can fix the issue is to clear the session with > clear session id 380025 command.

 

xxxxxxxxxxxxxx(active)> show session all filter

...

Resolved! How do you do validation testing?

Hi all,

 

I'm wondering if any of you do your own validation testing of security patces for PAN-OS and vulnerabily signatures.  Example being, do you confirm your edge is vulnerable to a specific CVE, and then after patching do you confirm it's no long

...

Bug in GlobalProtect client

Hello,

 

Global Protect client MSI is not installed correctly. Uninstall string is not correct :

 

msiexec /I should be msiexe /X

 

 

Silent uninstall of current version (3.1.4-7) in my case : MsiExec.exe /X{6AC613AB-3F53-424B-BED2-570C7869F30F} /QN

 

Latest

...

  • 24011 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels