Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

Resolved! DGA Threat Alert

First off, I am fairly new to Palo Alto firewalls. Yesterday we received a number of alerts over a one minute period related to a Domain Generation Algorithm threat. The source was an internal IP address, the destination was an external IP address. The action taken was sinkhole. The rule was DNS Forwarders. I don't fully understand what this i...

Dataplane Crashes on PanOS 10.2.2 when DNS-Servers not set

We've encountered an issue on PanOS 10.2.2 when DNS Servers are not set on the Management-Interface, the Dataplane crashes when jumping from the Panorama to the local context of the firewall. Older version of PanOS do not have this issue. Setting the DNS-Servers seems to resolve the problem. Looks like an issue with the name resolution and dnspr...

mattlede_0-1662715637110.png
mattlede by L1 Bithead
  • 3059 Views
  • 2 replies
  • 2 Likes

Getting errors While commiting the config from panorama to Palo-Alto

We have on-boarded new standalone firewall of model 410 to Panorama and tried to configure them via templates. In Template stack we have added FW template (as priority )+ global. and we are getting below error while commiting the configurations to firewall.devices -> localhost.localdomain -> template-stack -> FW_stack -> config ->...

Sujanya by L3 Networker
  • 2759 Views
  • 1 replies
  • 0 Likes

Resolved! TCP session timeout

Hello Team, Just a query - wanted to understand few things related to PA- sessions timeout. We have a server - which needs to connect to a specific port say 8xxx or 9xxx but unfortunately it requires connection to be established till more that 10 hours say 12 hours for example. So how can i achieve this ? 1. can i change global setting...

Best practice to unblock NUPKG

Looking for suggestions to unblock NUPKG files, as it is not a populated file (I already tried whitelisting the url it originates from): File Transfer Blocked The file you are trying to download or upload has been blocked in accordance with company policy. Please contact your system administrator if you believe this is an error. File name: Te...

Resolved! Permitted IP address for management interface could not access HTTPS or SSH

Hello PA team, I have configured permitted IP list for my management IP list and I am unable to access my firewall via GUI https or CLI - ssh. I have enabled - PING , HTTPS, SNMP, SSH on management interface. when i remove all permitted IP addresses then i am able to access - https ssh and able to ping as well. but when i add permitted I...

PA-220 antivirus db will not show via manual or dynamic updates.

Hi all, I have setup a PA 220 at home and have all licenses showing as functional. I manually installed the apps and threats DB successfully. (it is seen under dynamic updates) I manually installed the antivirus DB successfully. (it is not seen under dynamic updates) When i try to upload the anti virus DB again, it says it already exists. ...

Old-Roo by L1 Bithead
  • 2595 Views
  • 2 replies
  • 0 Likes

Multiple GlobalProtect profiles based on LDAP groups

I have tried multiple searches, but can't seem to find the answer that I am looking for. I am migrating from Cisco ASA firewalls to a PA-440. The PA-440 is running PanOS 10.1.6-h6. On the Cisco we have multiple VPN profiles. Each profile has access to only specific networks and/or hosts. When you initiate a VPN session, you select the sessi...

darisb by L0 Member
  • 2359 Views
  • 1 replies
  • 0 Likes

NGFW Application catagory

Afternoon all, Been looking at an application called "SimpleHelp" - according to google ... " it allows Any technician to log in using the following steps: Open your web browser and navigate to the technician address of your installed SimpleHelp server (http://<your server>/tech). Download and run the Technician application. Log in using...

how to know which informational level log related with hackers and invasion?

how to know which informational level log related with hackers and invasion? when this can be found, how to deal with this kind of attack and informational log? For example, in the past, smart install security incident , there kind of log are not crtiical level and not alert level some security event evidence can be any level of log

MavioLee by L2 Linker
  • 2722 Views
  • 1 replies
  • 0 Likes

Resolved! Sub-interface and zone || IPSec tunnel with AWS

Hi Team, 2 queries. 1. I have 2 physical interfaces on which i have configured multiple sub-interfaces. say for eg eth1/7 - eth1/7.1, eth1/7.2, eth1/7.3 eth 1/8 - eth1/8.20, eth1/8.21, eth1/8.22. and my both physical and subinterfaces are in same zone - say trust zone. Now i have an urgent requirement and i cannot addup new physical in...

Anyone else seeing ublockorigin.pages.dev and malware-filter.pages.dev being blocked in the phishing category?

This morning I noticed some hosts on our network were blocked from visiting ublockorigin.pages.dev and malware-filter.pages.dev because the URL filter categorized those pages as phishing. These URLs appear to be associated with the uBlock Origin adblocker extension. Does anyone know why these pages are categorized as phishing now by Palo Alto?

Resolved! How to best interpret blocked URL events for malware and C2

We recently started issuing a daily report from our PA-5220s detailing which hosts on our network were blocked from visiting certain URL categories of interest to us (malware, phishing, C2, ransomware) during the previous calendar day. I am the person on our team who scans those reports in the morning and decides which events to investigate. M...

  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors