Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4692 Views
  • 0 replies
  • 1 Likes

Please Release App-IDs for IBM AS400 user traffic

Hi, we have noticed traffic from users connecting to mainframes/midranges is showing as "unknown-tcp" and "insufficient-data" for the following ports: TCP/449 (Server Mapper) TCP/8470 (License Management) TCP/8471 (Database Access) TCP/8475 (Remote Command)TCP/8476 (Signon Verification) TCP/23 is of course being correctly identified as tel...

P19991 by L2 Linker
  • 4233 Views
  • 2 replies
  • 0 Likes

PAN to rsyslog on Ubuntu 22 yields unusable file names

Hi. I have a default setup w/ Ubuntu 22 as a rsyslog server. I pointed my PAN 10.2 to it, and am getting log data, but I am not getting a usable / meaningful file name. I'd like the log file name to be something like "perimfw" or some such to start. Hoping that some other PAN users here are logging to rsyslog and have a usable template line = be...

dmurdoch by L0 Member
  • 2364 Views
  • 1 replies
  • 0 Likes

Palo Alto ALG (Application Level Gateway) SIP dissable just for a particular source and destination IP addresses in a Security Policy?

Hello to All, From what I read about ALG (Application Level Gateway) functions on the Palo Alto Firewalls this function if needed is disabled globaly for the SIP default application or with application overide policy but this will stop the SIP signature matches. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEs...

Palo Alto PA 5220 not login after password complexity changes

We changed the password complexity and history settings on our firewall a couple of days ago. After committing the changes the local users are not able to login on the firewall. So we tried to boot into maintenance mode by connecting through a console cable in order to roll back to a older running config. This did not do anything though, because...

Remote Admin via ISP connected interface

I have a PA-440 that I need to be able to manage via it's ISP connected interface. I did the intial setup via the MGT interface but when I had the device moved to it's permanent location, which is not connected to our WAN, I cannot get the login web page when trying to connect to it's internet IP address. I have set the an Interface-Mgmt profi...

Unable to take passive firewall access.

We tried changing the cable, switchport and VLAN and also connected the Management Interface directly to a laptop. There was no SSH or HTTPS access possibleWe also tried to restart the Management and Device Server and other related processes on the FW. There was no change in the access.We uploaded TSF to a new case for further investigation.We c...

FCI by L0 Member
  • 2694 Views
  • 3 replies
  • 0 Likes

Resolved! Adding Malicious IPs on security list manually on FWs which don't have threat protection license

Hi Guys, We have two firewalls with Threat prevention license and few other palo firewalls without threat prevention license. I have a requirement to create security rules to block malicious IPs. I can do this easily on FW which has Dynamic external list of malicious IPs because of license but I can't do same thing on other FWs which don't hav...

shafi021 by L2 Linker
  • 2780 Views
  • 2 replies
  • 0 Likes

Resolved! Cert Delete and Created new devicecert

Anyone run into this? We discovered around 0400 AM (outside business hours so no admins online) the following logs generated. They appear system generated as if the device is regenerating a cert. Problem is, it doesn't match the dates on the device certificate that is normally generated under the device tab and PAN has zero documentation to tell...

logs-cert.jpg

NAT rule

Hello I have a problem. I have a firewall Palo Alto. Eth1 (20.74.34.3) is configured on public zone and eht1/2 is configured in the internal zone (10.110.0.4). Inside the internal network, I have a dmz subnet 10.111.0.0/24 where I have 2 web servers for application (app1 10.111.0.10 and app2 10.111.0.11) How I can configure the NAT rule to a...

PA-VM HA Failover Procedure

hello dear forum members, i have a question regarding the cluster configuration. wer'e currently running a PA-VM in cluster (A/P Mode) in the organization within an azure enviornment, both are configured with different External ip address. my question is, in the case of the active node going down, how does the procedure happen? will...

v-wire security newbie

we have a v-wire setup where we are controlling traffic to a secondary firewall w our 820. as its sitting between ISP and the site secondary firewall (sonicwall) we created a rule that negates all but some countries we do business with and that negation drops the traffic. would it be possible to accomplish the same with just creating the allowed...

JGaitan by L0 Member
  • 1734 Views
  • 1 replies
  • 0 Likes

Resolved! Create Security Policy Allowing Access to Sharefile based on User while URL filtering is blocking "Online-storage-and-Backup".

We currently block access to Online storage using URL Filtering and make exemptions to online-storage sites like Sharefile using custom URL Category with list of URLs that we want to exempt. However, this setup lets everyone in the company have access to Sharefile. I am trying to figure out a way to instead of Sharefile being accessible to eve...

NormGala by L0 Member
  • 4620 Views
  • 2 replies
  • 0 Likes
  • 1607 Posts
  • 61 Subscriptions
Top Solution Authors