General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! how to whitelist an URL with a wildcard in the name ?

I'v got a question about whilesiting URL's

 

I want to whitlist the following URL, github-production-user-asset-*.s3.amazonaws.com.

but, it's only possible to use a wildcard to replace full hostname spaces of the URL ( like *.s3.amazonaws.com )

 

how do I

...

DaxVC by L2 Linker
  • 2775 Views
  • 1 replies
  • 0 Likes

Minemeld install error on RHEL

I am attempted to perform an ansible install of Minemeld on RHEL 7. I am receiving the following error. Anyone seen this and have any suggestions for remediation?  Thanks

 

I receive the following message when I run the ansible playbook:

 

TASK [mine

...

taustin by L1 Bithead
  • 2744 Views
  • 2 replies
  • 0 Likes

invalid interface

hello have getting a lot of 802.1q tag not configured and invalid interface message in global counters. I'm trying to find the cause, I have configured subinterfaces I see traffic in rx.pcap with properly tag, all traffic is dropped, I see as destina

...

Marivi by L3 Networker
  • 5832 Views
  • 8 replies
  • 0 Likes

Feature Request - Reporting

I just spoke to Jim Silha about reporting.  Palo Alto comes with a user activity report.  Under the section 'Browing Summary by Website' there is a 'Host' column.  It is much more report friendly than say 'URL'.

I would like to be able to use that in

...

HA Active/Active and VPN

Hello,

 

We have a scenario where a customer wants to deploy two PA3250s in two different locations which will be an Active/Active cluster. There will be a layer 2 link between the two sites and also customer wants a VPN as a backup if the layer 2 link

...

sajidsil by L0 Member
  • 2783 Views
  • 3 replies
  • 0 Likes

LDAP interval

Hi,

I have a question in reference to the LDAP interval time. Specifically what my goal is I want to be able to let the firewall know about my AD group membership changes quicker. For example if I have a specific AD group that is configured on the fw

...

Resolved! URL domain reports

Hello,

I'd like to produce URL reports. I noticed that you can get report on the comlete URL but not based on the URL domain.

i.e i get entry for www.pippo.com/cpp/layout.css and another entry for www.pippo.com/img/pippo.jpg and for report purpose is o

...

Resolved! Meaning of different Interface states

I have scourred everywhere......

 

What are the differences between the interface states? I can't find anything anywhere!!

 

ukn/ukn/down(power-down)

disabled/down

forced/ukn

forced/down

 

If there are others I have missed, I'd love to be enlightened.

 

 

Weirdest thing I have seen

Having a weird issue. I installed an 820. I have internet traffic being NAT'ed. My gateway is set to the Palo. My hops to the internet look like this 

 

Windows Box ---> Palo 820 --> Cisco Pix --> Internet Provider

 

Pretty basic.. I have a rule in place

...

Bad certificate _ inbound ssl inspection

Hi All

 

we are using 3rd party singed certificate for inbound SSL inspection , once we imported the certificate it is not showing any error and commit is working fine . once we add the certificate to decryption policy it is showing error as bad certif

...

Rameshwar by L3 Networker
  • 2493 Views
  • 3 replies
  • 0 Likes

Resolved! URL Category and URL Profile in same Rule

We have a default URL Filtering Profile that we use for general use.  The default URL Filtering Profile has a couple dozen URL Categories which are set to alert.  I need to allow EXEs from only five of the URL categories.  If I add the five URL Categ

...

GlobalProtect remote access - some pointers

Dear All,

 

I'm relatively new to Palo Alto firewalls and I am attempting to implement GlobalProtect to provide remote users with access to our internal network through the Palo Alto firewall and I am striggling to get even the most basic system workin

...

GlobalProtect Best Practices

I searched through previous threads to see what the best practices are for securing GlobalProtect but the only thread I saw was dated and didn't have too much information. Could anyone share what their best practice is with setting up GlobalProtect?

...

  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels