Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4560 Views
  • 0 replies
  • 1 Likes

Unable to take passive firewall access.

We tried changing the cable, switchport and VLAN and also connected the Management Interface directly to a laptop. There was no SSH or HTTPS access possibleWe also tried to restart the Management and Device Server and other related processes on the FW. There was no change in the access.We uploaded TSF to a new case for further investigation.We c...

FCI by L0 Member
  • 2586 Views
  • 3 replies
  • 0 Likes

Resolved! Adding Malicious IPs on security list manually on FWs which don't have threat protection license

Hi Guys, We have two firewalls with Threat prevention license and few other palo firewalls without threat prevention license. I have a requirement to create security rules to block malicious IPs. I can do this easily on FW which has Dynamic external list of malicious IPs because of license but I can't do same thing on other FWs which don't hav...

shafi021 by L2 Linker
  • 2695 Views
  • 2 replies
  • 0 Likes

Resolved! Cert Delete and Created new devicecert

Anyone run into this? We discovered around 0400 AM (outside business hours so no admins online) the following logs generated. They appear system generated as if the device is regenerating a cert. Problem is, it doesn't match the dates on the device certificate that is normally generated under the device tab and PAN has zero documentation to tell...

logs-cert.jpg

NAT rule

Hello I have a problem. I have a firewall Palo Alto. Eth1 (20.74.34.3) is configured on public zone and eht1/2 is configured in the internal zone (10.110.0.4). Inside the internal network, I have a dmz subnet 10.111.0.0/24 where I have 2 web servers for application (app1 10.111.0.10 and app2 10.111.0.11) How I can configure the NAT rule to a...

PA-VM HA Failover Procedure

hello dear forum members, i have a question regarding the cluster configuration. wer'e currently running a PA-VM in cluster (A/P Mode) in the organization within an azure enviornment, both are configured with different External ip address. my question is, in the case of the active node going down, how does the procedure happen? will...

v-wire security newbie

we have a v-wire setup where we are controlling traffic to a secondary firewall w our 820. as its sitting between ISP and the site secondary firewall (sonicwall) we created a rule that negates all but some countries we do business with and that negation drops the traffic. would it be possible to accomplish the same with just creating the allowed...

JGaitan by L0 Member
  • 1685 Views
  • 1 replies
  • 0 Likes

Resolved! Create Security Policy Allowing Access to Sharefile based on User while URL filtering is blocking "Online-storage-and-Backup".

We currently block access to Online storage using URL Filtering and make exemptions to online-storage sites like Sharefile using custom URL Category with list of URLs that we want to exempt. However, this setup lets everyone in the company have access to Sharefile. I am trying to figure out a way to instead of Sharefile being accessible to eve...

NormGala by L0 Member
  • 4354 Views
  • 2 replies
  • 0 Likes

Certificate revocation / OCSP not working

I've set up one of our PAs (a 5260 running 10.1.6-h3) to use as a certificate authority and OCSP responder for use with GlobalProtect remote access. I'm able to issue and verify certificates with no problem, but revoking a client certificate has no effect on whether the able to connect. I'm able to browse to http://<PA IP>/CA/ocsp, but th...

Resolved! Twice NAT of ASA FW , equivalent NAT rules on Palo Alto FW

Hi Experts , We have twice nat rules (nearly 608 NAT rules) configured on ASA FW and we are planning to refresh them with Palo Alto 5020 soon.Below is one the NAT rule of ASA FW. nat (Internet,Inside) source static any any destination static h-197.29.23.83 h-10.30.2.74 unidirectional I would like to know what kind of nat rule(s) we should ...

EMEA-FW by L1 Bithead
  • 6150 Views
  • 2 replies
  • 0 Likes

unknown traffic pcaps just stopped happening one day around 2 weeks ago

I have a PA-460 that stopped doing pcaps for unknown traffic about two weeks ago. I played around with the application dump setting and I think I may have broken something: Application setting:Application cache : yesSupernode : yesHeuristics : yesCache Threshold : 16Bypass when exceeds queue limit: noTraceroute appid : yesTraceroute TTL thres...

  • 1589 Posts
  • 60 Subscriptions