General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

What's new in MineMeld 0.9.36

Release Date: 2017-03-21

 

How to update: Updating MineMeld

 

Nodes

  • JSON Miner now supports Basic Auth via prototype (suggested by @Kimwii)
  • TAXII Miner now supports subscription_id, client cert support has been improved, added support for LinkObjectTy
...

lmori by L7 Applicator
  • 5816 Views
  • 4 replies
  • 6 Likes

Resolved! DMZ to inside LAN

I know you need a security policy to go from dmz to Lan but do you need a nat statement.  On all the Palo Alto documents that I have seen no nat rule is used.  If I am wrong could some one send me a link.  

 

Thank you 

Global Protect: Two preferred NIC listed

Windows 7 laptops with global protect client installed.

 

When I plug my laptop into a wired(ethernet) connection, the wireless IP and the wired IP are showing up as preferred. If I remove global protect from these laptops the wireless IP goes away whe

...

image002.png

Resolved! Reset pass user admin via web

Hi,

 

How I do reset the password user admin again??? I have this messages "bad gateway" when I put the credencials on the access web.

 

I can't login

 

Do you kwon something about this, please?

 

 

Thx

 

SantiBT by L2 Linker
  • 4274 Views
  • 1 replies
  • 0 Likes

Resolved! Problems users with Windows 10 and User ID agent

Hello,

 

I need your help with the following scene:
I have some machines with Windows 10 Operative System and I have detected a problem with the PA Firewall. The Firewall is not detecting the user (UIA), so the policy rules are denying the access.

Panos

...

SOC_CSG by L4 Transporter
  • 6836 Views
  • 10 replies
  • 1 Likes

QoS theory / functionality

Hi,

 

We have an interface which is 100Mbps. There will never be more than 20 IP addresses connecting on this interface.

 

I wish to guarantee each connection 5Mbps and allow them to use the entire 100Mbps if the additional bandwidth is available.

 

I can

...

SARowe_NZ by L3 Networker
  • 2168 Views
  • 4 replies
  • 0 Likes

Resolved! Package minemeld not found

Refer to the KB below and install it.
However, even if you implement 5. Installing MineMeld,
The following error will be output.

 

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454

 

Sinc

...

package-error.png

connect-change

Hi,


I was getting "connect-change " and ha2-keep-alive error (severity critical) in pa

pa is in active -active mode . This happened almost same time in two different days . ha2-keep-alive error happened right after a commit.

When I checked there is no c

...

sib2017 by L4 Transporter
  • 1581 Views
  • 0 replies
  • 0 Likes

DNS traffic identified as sophos-live-protection

Some DNS traffic is classified as sophos-live-protection in our traffic logs. Has anyone else seen this? I only have logs 5 days back in time, so I cannot say when this started but it wasn't with the latest apps update. Our firewall is PA-5050 runnin

...

Globalprotect client

I want to do some testing on new global protect clients but I don't want to make it update anyone tell I can test it, How do I get the software to test with out making it the default cleint on the firewall?

jdprovine by L4 Transporter
  • 5337 Views
  • 25 replies
  • 0 Likes

Security policy: exception question

Hi, I'm trying to create a security policy that would block all critical traffic from source zone "A", to destination zone "B". However, I want to allow traffic from a specific IP in zone "A". How can I make an exception to allow that IP? I assume I

...

Resolved! message security over http

How does PA handle message security over http ?

Whereas https secures the communication, message security secures the content.

 

I would expect PA does not touch http content. But we are having issues with an application that connects to a partners serv

...

dieter_b by L4 Transporter
  • 6815 Views
  • 16 replies
  • 0 Likes

Resolved! Replace ASA5505 with PA200 Teleworker

I have a remote user that's setup with an ASA5505 configured for teleworker. They move around and don't always have a static IP address at their locations. It's configured to call home to my ASA5540s and create the tunnel.

My question is if the PA200

...

JeffDBO by L1 Bithead
  • 2548 Views
  • 4 replies
  • 0 Likes

Resolved! AutoFocus Miner Thought

Getting the minemeld engine up running the AutoFocus/TAXII redesign today, one thing I noticed while trying to create better and more targeted AutoFocus miners is that I cant create a list that maintains a specific “age”

 

Where many lists will allow

...

hallerr by L2 Linker
  • 4148 Views
  • 3 replies
  • 0 Likes
  • 24201 Posts
  • 100 Subscriptions
Top Liked Authors
Labels