General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Block http traffic to numeric URLs

Hi,

 

I was ordered to block all http and hhtps traffic to addresses without a dns name. In other words user have to put in a network name in the browser and are not allowed to type an IP address in the address field.

 

As the thinking behind is bloc

...

PA identifying traffic from AKAMAI as BruteForce.

Hi guys,

 

Context: For the past 24 hours we've had constant reports of a Brute force attack on our servers originating from the Akamai CDN's.

 

I'm unsure whether this is simply a false positive, or if there something to actually worry about.

 

I've

...

MIGAS by L1 Bithead
  • 4987 Views
  • 8 replies
  • 0 Likes

Panorama not generating summary logs

Hi,

 

I have an unlicensed Panorama (for the sake of testing) to aggregate logs from the Palo Alto. I've set up log forwarding on the firewall, Panorama is receiving logs and detailed traffic is showing up properly, but there are no summary logs genera

...

nikoo by L3 Networker
  • 1570 Views
  • 1 replies
  • 0 Likes

Resolved! How to downgrade HA pair from 7.1.X to 7.0.X version.

Hi Guys,

 

What is going to be a right way/steps to downgrade PA from the version mentioned above?

 

1) Disable "preemption" on the both nodes. Commit changes.

2) On the "passive" node load config that matches your version. Let say l am going to inst

...

Resolved! EBL Issues

I've just started to test working with an EBL to quickly update a block list without having to apply the URL Filter to all of the different groups that we have. I've verified that I have connection to the document and that the Palo Alto sees it but I

...

BPry by Cyber Elite
  • 5329 Views
  • 11 replies
  • 0 Likes

HA pair on different os version

I have a HA pair (active/passive) that I want to upgrade from 6.1.11 to a stable version of 7.  I also am using global protect with certs. According to some information I gathered from the community if I upgrade to what I was told was the current mos

...

jdprovine by L4 Transporter
  • 4960 Views
  • 14 replies
  • 0 Likes

Where to apply Anti-Spyware Profiles

I've looked around in various places and can't seem to find a definitive answer on this. In regards to anti-spyware profiles, is there any need to apply these to security policies with a source of the outside Internet zone bound for your inside netwo

...

Resolved! Anyone having issues with Threat ID 40059 (HTTP Brute Force)?

Palo Alto pushed out an update to the HTTP Request Brute Force Attack signature (40059) on 06-15. Since then I've seen a rash of threats being identified from Akamai Technologies IP addresses (about 8 different addresses). I'm wondering if anybody el

...

BPry by Cyber Elite
  • 2991 Views
  • 2 replies
  • 1 Likes

IPsec Phase 2 Lifesize Coutdown

On an Phase 2 IPsec SA with a non-zero lifesize, I see the proposed initial lifesize in the "show vpn ipsec-sa" output,

crclark@<redacted>-pa5050b(active)> show vpn ipsec-sa tunnel <redacted>-cisco-gw

GwID/client IP  TnID Peer-Address           Tunnel(

...

cosx by L2 Linker
  • 6980 Views
  • 5 replies
  • 0 Likes

Identifying Applications

Hi guys,

 

Got an odd one here. Traffic is being identified as a completely different application to what the traffic actually is. For example, see below.

 

I've cleared the dataplane cache and re-downloaded the DB categorisation as per the document

...

traffic application.png
  • 24211 Posts
  • 99 Subscriptions
Top Liked Authors
Labels