Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

PaloAlto base config, not able to commit config after removing vwire references

Hi Folks, I am using Palo-Alto 3260 without panaroma. i want to take base config from it, so we have reset the firewall to factory default and trying to commit config by removing vwire from interfaces and zones. but config is not getting commit and giving error as interface is missing default config. How can i take base config then

Resolved! ssl inbound inspection in a reverse proxy scenario

Dear Community, I need to configure ssl inboud inspection in a scenario with 5 web services running behind a reverse proxy. The flow of traffic is as follow:Internet (same_public_ip) =>> PA ==(nat)=>> Reverse Proxy =>> Web Services Since PA will not be able to peek into the sll traffic to grasp which one is the aimed internal s...

How to avoid split brain in active passive cluster

Hi, We've got a installation with active-passive devices in different datacenters. We need to ensure that the primary device is always the active device when there is some problem between datacenters. We have configured virtual router path monitoring in the secondary device so it can check that the primary device is not reachable. But for so...

LACP load balancing algorithm

Hello Team, Where I can find information about how traffic balance between physical interfaces in case when LACP used?Can I choose balancing method in configuration (source/destination, MAC/IP Addr, L4 Ports)? I found information about traffic distribution mechanism in LAG for early versions of software (prior 6.1😞https://knowledgebase.paloalto...

EDL and Custom URL

Hi There, Problem Statement : We have custom URL lists(To allow Azure Endpoints only), also we have EDL(With Minemeld) integrated. As per our Infosec Policy we should not use Minemeld feed for Microsoft as it has some of many wildcard. So desperately creating custom URL for each MSFT end points(viz Defender, AAD heath etc,,) But some of URL is ...

Ramakrishnan_0-1656531514731.png
Ramakrishnan_1-1656531743034.png
Ramakrishnan_2-1656531871704.png

Resolved! Permit statement isn't capturing all the traffic

We have a school tied to our organization that's using a PA-850 and is running 10.1.6, and we're trying to get Battle.net working. After considerable troubleshooting, I put in a rule at the very top to permit the "zESports" zone to get to any IP on any zone. See the eSport_to_all_rule image. For some reason, some packets completely bypass this r...

PA dropping certain MSSQL EXEC statements for no apparent reason

Having a weird issue with a remote client connection to over VPN to multiple internal MSSQL servers. A particular SQL EXEC query packet is getting dropped in the middle of an SQL session. Security ruleset allows the communication under a VPN to TRUST mssql-db-unencrypted rule (made a separate test rule with explicit any/any allows and no filteri...

Firewall tries to close a BGP/TCP connection with switch

Hi, The following problem involves a firewall (10.249.0.13) wanting to close a BGP connection with its neighboring switch (10.249.0.14). The switch answers with a BGP NOTIFICATION message that contains 'No supported AFI/SAFI'. (separate issue) The firewall then sends a FIN to the switch to close the TCP connection. Follows a series of FIN ...

Upgrade 9.0 to 9.1 Question

I have two palo vm's (managed by panorama 10.1.3) in azure running 9.0.13 and I want to get them up to 9.1.14. I have a question regarding order of operations. Can I use Panorama to upgrade them directly from to 9.1.14 by downloading 9.1 and downloading and installing 9.1.14? Or do I have to install the 9.0.16 maintenance release before moving...

dac6d4 by L0 Member
  • 2612 Views
  • 1 replies
  • 0 Likes
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors