General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 589 Views
  • 0 replies
  • 0 Likes

vsys CPU utilization

Just wondering if the more vsys you add, how much more CPU utilization or resource utilization will be used?  Does the more you add degrade the system at all?  I'm looking at a 5060 or a 5560 with at least 7.0 OS.

 

Is there any documentation that stat

...

Anyway to block Webex plugin?

After hearing the news that the Webex extension in Chrome has a serious vulnerability is it possible to block this at the Palo Alto?

 

http://arstechnica.com/security/2017/01/ciscos-webex-chrome-plugin-opens-20-million-users-to-drive-by-attacks/?commen

...

pmc by L2 Linker
  • 4801 Views
  • 4 replies
  • 1 Likes

Use wildcard in user/group based policy

Hi,
We have a Splunk Server that sends to your id-agent (on a windows server) the information of guest users.

Now on PA We can se user@acme.com in the logs, is possbile for us create a rule for all users from acme, without define each user?

 

So a group

...

Resolved! ssh problem on mac os x

Hey guys,

 

I have such a weird problem.

 

A user has to connect to a samba server. He does it on his mac with cyberduck, Port 999 and ssh.

 

in the monitor, the application is "incomplete", the action is "allow", and session end reason is "aged-out".

 

Curr

...

MPI-AE by L4 Transporter
  • 6464 Views
  • 12 replies
  • 0 Likes

Netflow bandwidth usage and link-aggregation

We've added a netflow server profile to 4 sub-interfaces on ae1 that connects ISP. The netflow is then reported to Solarwinds where we have poll and collect netflow from these sub-interfaces. But we are also seeing notifications i Solarwinds that all

...

one globalprotect client two portals

I have two global protect portals one for staff and one for contractors. I regularly have to test both and the only way I have found to do it so far it to change the portal name on the client. Is there anyway to add both portals and toggle between th

...

jdprovine by L4 Transporter
  • 2897 Views
  • 5 replies
  • 0 Likes

Virus/OSX.WGeneric.lcwwz

IP address (IP: 4.35.21.146) is pushing out a Google update (url:GoogleSoftwareUpdate-1.2.7.43.dmg) but Palo Alto show it as Virus (Virus/OSX.WGeneris.Icwwz)

shekeba by L0 Member
  • 1793 Views
  • 1 replies
  • 0 Likes

Firewall optimizer

Any one out there using firemon or algosec to optimize your firewall? I am interested in your opinions whether you like it or not and which one is better or if there are other options

jdprovine by L4 Transporter
  • 2656 Views
  • 6 replies
  • 0 Likes

HA in Virtual Systems

Can high availability be controlled per virtual system?

In other words, is it possible to have an active/passive HA pair with 2 virtual systems, where one virtual system has unit 1 active - unit 2 passive and the other virtual system unit 1 passive -

...

Resolved! SSL Inbound Inspection not working with decrypt-error message

Hello,

 

I'm trying to setup, for the first time, our SSL Inbound Inspection, but I've some difficulties to achieve the setup.

 

The configuration seems really simple, and I followed this guide:

https://www.paloaltonetworks.com/documentation/71/pan-os/pan

...

FTBZ by L1 Bithead
  • 10330 Views
  • 6 replies
  • 0 Likes

Embedded Minemeld UI Logs Issue

Currently using a Docker version of Minemeld, which is embedded in a web application using an iFrame.

All works fine except for the Logs page, which times out.

Looks like it maybe be a restriction enforced which is not allowing frames.

Any tips on where

...

calamari by L1 Bithead
  • 2635 Views
  • 1 replies
  • 0 Likes

Resolved! unable to open SMB share (TSA user mapping issue)

Hi Guys,

 

Within a Poc with a PAN Firewall we ran into the following issue:

 

A terminal server (with TSA) in network a ist connected to a PAN Firewall. Fileserver in network b is also connected to the PAN Firewall.

 

Everything is configured proper

...

Zencon by L1 Bithead
  • 3806 Views
  • 4 replies
  • 0 Likes
  • 23927 Posts
  • 113 Subscriptions
Top Liked Authors
Labels