General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Negate networks within an object group

Hi,

is it possible to negate certain networks within a rule?

 

example.. src (192.168.0.0/16) and dest (10.0.0.0/8) action Deny

but want to negate dest 10.200.0.0/24 in the same rule so that 192.168.0.0/16 cannot talk to 10.0.0.0/8 but can talk to 10

...

PA_nts by L3 Networker
  • 62 Views
  • 1 replies
  • 0 Likes

Help with XML api device configuration

I'm looking for a solution to automate sdwan deployments so I'm trying to do a couple of things with this api call:

 

1 - create the layer3 subinterface interface

2 - give the subinterface an ip and next hop ip

3 - enable sdwan on the interface and g

...

Certificate not valid

I am trying to setup Machine authentication, where it actually validates the machine certificate, I have a PKI infrastructure, that pushes certificates to the machines, with there name in Common Name, and SAN, of the machine hostname. 

On they Certif

...

Issue with PA-1410 platform disk size

Hello Team,

                  Recently we have deployed PA-1410 in our datacenter and since first day we are having issue with disk space in loggin.

and after contacting the support, logging is not more than a week which is not accepted from our side

...

Resolved! ION CLoudGenix Devices Offline

Hi Team, 

 

Has anybody experienced any issue with CloudGenix ION devices where you can SSH onto the device but actual on the Prisma Cloud Portal all the CG devices shows offline ? 

 

I have one of this issue where I can remote into every single ION

...

H.Suthar by L0 Member
  • 281 Views
  • 3 replies
  • 0 Likes

Decrypt STARTTLS SMTP protocol but not blocked Virus File

The mail server resides on the network inside PaloAlto.
I am trying to add a feature to use STARTTLS for SMTP/25 from the mail server to the Internet.

I implemented STARTTLS decryption (Forward Proxy) on the PaloAlto and sent an email with Eicar Virus

...

Hogewo by L1 Bithead
  • 376 Views
  • 2 replies
  • 0 Likes

Resolved! PANOS 8.0.4 warning ipv6 not enabled on tunnel interface

Hello All,

I just upgraded to 8.0.4 and now when I commit the tunnel interface associated with my external GP gateway gives a warning that "ipv6 is not enabled on the tunnel interface tunnel.1.  IPv6 address will be ignored!"

Did something change in th

...

dan731028 by L3 Networker
  • 13994 Views
  • 14 replies
  • 0 Likes

Block Exchange ECP externally

Hello team,

 

We are experiencing with our hosted exchange server on the cloud. Despite efforts from our Server team to block ECP access from external networks, it remains accessible. The team has suggested blocking ECP for external networks only.

I

...

GP issues after a fail over test

So we have an annual BCP fail over test, during the fail over test when we shut the primary TOKYO PA 850 it fails over to PA 850 SEC, however when we connect to the VPN we cannot on our TOKYO we are not able to connect. 

 

I'm a bit newbie on PA and

...

weezy by L2 Linker
  • 189 Views
  • 1 replies
  • 0 Likes

UserID Agent version compatbility

Hello,

 

I'm currently working through the Certificate Advisory.  We currently have firewalls running 10.1.11, user-ID agent is 10.1.1-102.   Started an upgraded firewalls  to current preferred version of 10.1.13h1.  The issue I have is I am simultan

...

Doubt about costomize config log paloalto

Hi team

The security auditors ask us if in the Config Log it is possible to have an additional field in the log that links all the events of a rule change with a ticket id external to Palo Alto.

That is to say that in the attached logs an additional

...

Alpalo by L4 Transporter
  • 232 Views
  • 2 replies
  • 0 Likes
  • 23587 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels