Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

HA Configuration with network provider router

Hello In case where I haven't switch between network provider router and our cluster of Palo Alto (Active/Passive), only a cable between router (eth1) and Eth1 of Active firewall, if the active FW is broken, the communication will be cut or not ? What is the best design to connect a sigle router of network operator to our FW cluster if we c...

JeromeC_0-1662024189356.png
JeromeC by L0 Member
  • 1882 Views
  • 1 replies
  • 0 Likes

how to allow NordVPN after done suggestion of BPA for advanced threat license

how to allow NordVPN after done suggestion of BPA for advanced threat license? I use flashrouter of nordvpn but page.asp can not load and even blank white page shown. I remove high risk and medium category blocking but can not solve PA220 configured C2 command and control traffic blocking but cannot find the reason of blocking and can not find w...

MavioLee by L2 Linker
  • 4944 Views
  • 3 replies
  • 0 Likes

PA firewall treated NBSS Continuation Message as Worm/Win32.vobfus

Hi all, Recently the PA firewall received massive threat alert with family Worm/Win32.vobfus. (Application: ms-ds-smbv3, Port: 445, thr_category: pe) I have submitted the file samples and the files are clean, we also scan the server and there is no virus. Which we confirm this alert is a false positive. Then I take a Threat Packet Capture, P...

MarcusLeung_0-1661915171950.png

Wildfire detecting phishing (severity high) but action is allow

Hello all, I am seeing multiple Wildfire submissions that have the same source IP and are being detected as smtp-base with the verdict of phishing, high severity but the action is "Allow". I have noticed in the Antivirus profile that for SMTP the "Wildfire signature action" and the Wildfire Inline ML action" is set to "default (alert)". How do ...

ccfritz by L1 Bithead
  • 2001 Views
  • 1 replies
  • 0 Likes

PA-HDF issue

After factory reset as suggested i get the following Has any one come across this type of error and how can it be resolved I am trying to learn and get comfortable with the device but getting these errors Please help Dalton

Dalton by L0 Member
  • 1917 Views
  • 1 replies
  • 0 Likes

Dual dynamic ISP with single VR

Hi , have 2 dynamic isp at site 1 with single vr and ECMP and 1 public ip at site 2 paloalto at OCI cloud , i have setup dual tunnels from site 1 to site 2 but its not stable at all and most of times if we simulate failover using either path monitoring or tunnel monitoring we can see that vpn is stuck in initiating phase. We used below guide h...

PA-HDF issue

I have purchased a PA 200 to get some practice for my exam i configured it but forget my pw so i done a factory reset and since getting PA-HDF login. i entered admin admin and getting incorrect pw I have attached the file please advise

Dalton by L0 Member
  • 4973 Views
  • 2 replies
  • 0 Likes

Can not change

Hello Every one I was trying to build a Site to Site Vpn. I can only select limited interfaces when creating a new Zone. The selection option does not even include the main gateway interface (Ethernet1/10. I have attached a screen shoot of the scenario.

Habte01_0-1660835482512.png
Habte-01 by L1 Bithead
  • 3404 Views
  • 6 replies
  • 0 Likes

Resolved! Issue with license

Hello Mr. We have renewd our subscription for the PAN-OS features all gone ok but issue with the PAD-DB URL filter. PAN-DB URL has not retrived the service subscription in the license page. 'when I tried to user online license retrival' but when I tried to upload the key it added a new windows 'Advanced URL fiter' with the new subscr...

Distribution of licenses across multiple vSys

Dear All, We have a PA-5200 series firewall. I have a small question which I couldn't find an answer in the public documentation, blog or discussions. My question is that how licenses are distributed among the vSys in the same firewall. The license(s) that I am interested are below: Threat Prevention Subscription Global Protect Subs...

mune3b by L0 Member
  • 2315 Views
  • 1 replies
  • 0 Likes
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors