General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 269 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3590 Views
  • 2 replies
  • 14 Likes

Resolved! Cannot find pan_packet_diag.log on PA VM

Hello,

 

I am new to this forum so please bear with me. I would like to use debug log feature on my PA VM. I am able to turn the logging on with the following commands:

debug dataplane packet-diag set log

debug dataplane packet-diag set log feature flow

...

HAL9000 by L1 Bithead
  • 4098 Views
  • 4 replies
  • 0 Likes

Discussion on most stable PAN-OS image as of July 2016

I am going through some cleanup of our PAN firewalls. We have 8 sites with active/standby pairs of PAN's. The sites are connected with IPSEC VPN's. The code varies from 6.0.3 to 7.0.4 versions.

 

What's your feeling on the most stable 7.X code as of no

...

rpugh1 by L0 Member
  • 3667 Views
  • 7 replies
  • 0 Likes

VPN question

Hey there,

 

I was curious if anyone successfully used another VPN client on their IOS or Andriod device that works.  I was told that with X-Auth/IP-Sec the Cisco Anyconnect client worked but it appears that the new 4.0 client does not (am I wrong?).  

...

mjillson by L0 Member
  • 1499 Views
  • 1 replies
  • 0 Likes

Resolved! Blocking .docm files

Hi,

 

we see a lot of files with extension docm attacking the mailserver via smtp and identified as malicious by wildfire. is there a way to simply block those files via File Blocking profile like we are doing for pe and other file types. The point is

...

Skype Enterprise

Hi,

I need to create a rule to make run Skype enterprise. I don't find an app for skype enterprise so i tried to create a rule with only skype and ms-lync-online but it's deny with the destination port 5061...I don't understand.

 

does someone has an id

...

ALC_Palo by L0 Member
  • 2043 Views
  • 1 replies
  • 0 Likes

TRAPS and Reverse Proxy

Hello Folks,

 

I have recently installed a ESM core and console server. I have added a URL re-write rule to allow my traffic to be proxied through this server. The issus is that the web based traffic is rewriting no problem. Its the communication on po

...

Pokemon-go

The following custom application can be created on the Palo Alto Firewall to identify Pokemon-go traffic

 

<application version="7.1.0"> <entry name="pokemon-go"> <default> <port> <member>tcp/443</member> </port> </default...

postscript-pdl application classification - buggy

We are setting up a new printing zone on the PA and have created a rule that allow the following applications , postscript-pdl, hp-jetdirect, lpd, snmp. It allows one page to print to the printer and then it stops. After much testing we added a secon

...

jdprovine by L4 Transporter
  • 2085 Views
  • 4 replies
  • 0 Likes

Source users no longer showing up in Monitor and ACC

A few weeks ago I noticed that in our firewall suddenly all the Source User fields are showing blank. This is very strange since it happened without any changes being made to the firewall or the Domain Controller. We populate user IDs using LDAP. All

...

TDag11 by L0 Member
  • 2878 Views
  • 3 replies
  • 0 Likes

vwire using a single physical interface possible?

Right now we use a standard vwire with 2 physical interfaces.

 

We're about to make some hardware changes that means that the vwire input and output will be from/to the same physical switch.

 

If I have to use 2 interfaces then on that switch I'll just b

...

GP user access using internal DNS

Hi all,

when GP user need to access internal resource, i want them to use vpn assigned internal dns server, but currently user
still go to ask local dns on their PC. and if user access via ip, it is OK. How to break it out ?

Yue.Ma by L1 Bithead
  • 1607 Views
  • 2 replies
  • 0 Likes

HA issues

I have 5060 pair (pan1 and pan2) with 7.1.2 in HA. Whenever pan2 interfaces are up, not shutdown, sooner or later we experience issues. It doesn’t matter if pan2 is active or passive. Could it be h/w ? Config is in sync

niuk by L3 Networker
  • 2381 Views
  • 5 replies
  • 0 Likes
  • 24172 Posts
  • 100 Subscriptions
Top Liked Authors
Labels