Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4510 Views
  • 0 replies
  • 1 Likes

Resolved! Can we use 10GbE SFP+ on PA-3220 to connect directly to NetApp SAN over optical connection

Hey all. We're kind of in a bind. We procured a NetApp AFF A220 SAN that only have 10GbE optical transceivers for data access. We have no network hardware (no fabric or network switch) that support 10 gigabit except potentially our PA-3220 that have 4 x SFP+ ports capable of 10GbE. Is it possible to connect the SAN directly to the SFP+ ports o...

Resolved! App ID base load balancing dual isp

Hi, I have 2 ISP links failover mode. I wants Lan users Apps base traffic forwarding . For example all users whatsapp and instragam traffic forwarding backup isp path, and others content will passing primary path. Is it possible to forwarding if possible what is the procedure.

Resolved! Problems with URL-DB (it's missing!)

Hi! We've been having on going issues after an upgrade (since downgraded) with our standby firewall - when made live it only functioned at about 10% (i.e. most legitimate traffic was blocked for one reason or another). We fixed an issue with DNS resolution - apparently the domain string being present broke DNS resolution(!), but there remains ...

Block File upload on facebook Messager and instagram

I get a request to allow users to access facebook and allow users to use text chat and comment only. If users want to upload or send files, the firewall has to block them. Instagram as well, does not allow users to upload anything, but they can log in view, and comment. I have configured SSL Description, created a policy to allow facebook-chat...

PA-820 slow gui

Hi all, We're using a PA-820 machine running version 10.1.6. Ever since upgrading to 10.x version the GUI is extremely slow, while the management CPU is showing very low utilization. The slow GUI is in every screen, not just logs screens. I don't know if it's relevant but we're using several EDL objects, some of them have thousands of entries....

arnona by L1 Bithead
  • 2174 Views
  • 0 replies
  • 1 Likes

PAN-OS XML API filtering question

Does the PAN-OS XML API for Global Protect previous users have a time filter option? I didn't see one documented. This query returns all previous users in the firewalls logs, but really I just want the last hour: https://<firewall _address>/api/?type=op&cmd=<show><global-protect-gateway><previous-user/></global-pr...

mgreer by L1 Bithead
  • 1752 Views
  • 1 replies
  • 0 Likes

URL Filtering Categorisation Justification

Hi! We're running URL filtering on our PanOS campus firewalls and I very often get asked to add domains to our 'allow list' - almost always because they're newly registered domains. On occasions we've had sites requested that fit into more serious categories - the latest being 'grayware'. These are very often personal web sites used for teachi...

Resolved! HA Port on PA-5220

Dear All, Is there any way to see the physical status of the HA1 Port through CLI or GUI ? HA1-A and HA1-B —Ethernet 10Mbps/100Mbps/1000Mbps ports used for HA1 traffic in both HA Modes. For HA1 traffic —Connect the HA1-A port on the first firewall directly to the HA1-A port on the second firewall in the pair or connect them to...

Power Supply Comparison - PA-220 vs PA-440

Hello, all - We have several remote locations running about a dozen PA-220 FW units which we are replacing with PA-440s. I would prefer to make this as painless as possible and may even have the non-technical onsite staff do the hardware swap. I'm just having a bit of a quandary when it comes to the power supplies. The spec sheets are a little...

T.Wedell by L0 Member
  • 4019 Views
  • 0 replies
  • 0 Likes

Pancast: Have an Idea for an Episode?

Hey Everyone! Have you listened to the PANCast podcast? PANCast is a Palo Alto Networks podcast that provides actionable insights from cybersecurity experts to customers, helping ensure each day is more secure than the one before it. Since launching last September, PANCast has produced and published 10 episodes — including titles like “Shou...

Screen Shot 2023-02-01 at 7.41.19 AM.png
Screen Shot 2023-02-01 at 7.45.27 AM.png
JayGolf by Community Team Member
  • 1609 Views
  • 0 replies
  • 0 Likes

GotoWebinar WebCam Issue

Hi Team, Users are trying to enable webcam when they are on gotowebinar meeting. However, they are unable to enable the CAM and other things works absolutely fine. Below are the steps i followed to tshoot this issue. > Created a rule with the APP-ID gotowebinar and gotomeeting to allow access.(This did not help) >Tried checking logs and fo...

Export Management Permitted IP Access List

I have been looking through posts but cannot seem to find what I am looking for. There are some Management Interface Permitted IPs on our Firewalls that do not match the Template that we have for them in Panorama. Is there a CLI command where I can export the Permitted IP list for a firewalls' Management access? From the GUI there doesn't seem...

NelsonE3 by L0 Member
  • 6096 Views
  • 1 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions