Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4725 Views
  • 0 replies
  • 1 Likes

Cloud NGFW for AWS billing issue

Hi All, I have subscribed Cloud NGFW for AWS service(Palo Alto firewall) from AWS marketplace and used it from a learning perspective. Now I'm getting a higher billing amount on the AWS billing dashboard. I raised a case with AWS for billing issue they suggest talking to Palo alto customer care support for the same. On Palo Alto portal i am no...

Resolved! Best Practice for Root CA Self Signed Cert on NGFW

I have a question regarding best practices for creating Root CA self-signed cert(s) on a NGFW. Should one single self-signed CA root cert be used as the root cert for ALL certificate chains for firewall services such as SSL Decryption, GlobalProtect portal, Gateway Certificates, etc, etc? So I guess there are two specific questions: 1) Is there...

Looking to switch to PAN for NGFW, need insight into IPS, reporting and analytics, network visibility, etc

Hey all, I work IT security for a SMB in the financial sector and I'm looking into PAN, FortiGate and Check Point for a better NGFW solution than what we currently have, which is Sonicwall. For about 6 years we've been using an NSA 3600 to cover our main company network and then a TZ500 to connect back to the main branch via point to point VPN a...

NGFW PALO ALTO and Azure VPN Ipsec Issue

Hi All, We had observed an issue with Palo Alto and Azure vWAN IPsec tunnel. the Tunnel seems disconnected and getting following log messages time and again.2022-03-07 11:48:14.506 -0600 [PWRN]: 50.100.100.100[500] - 152.100.101.105[500]:0x1c787140 unknown ikev2 peer2022-03-07 11:54:17.013 -0600 [PERR]: { 4: }: 50.100.100.100[500] - 152.152.152...

Intermittent random packet drops to/from NGFW

What seems to be out of the blue, with no configuration changes on our firewall(s), we began experiencing random periods of "network outages" on our main data center firewall. The symptoms are as follows:Our pingdom test to our OWA website shows as down (i.e. the web page hosted behind the firewall cannot be reached from the internet)Users conne...

JPhilip by L1 Bithead
  • 19302 Views
  • 6 replies
  • 0 Likes

Resolved! FlexVM Licensing with Software NGFW Credits

Hi all, As you probably know, paloalto recently changed the licensing of VM firewalls. With greater flexibility (and higher licensing costs), there is now also the possibility to increase only the RAM for such a VM firewall which results in higher capacity for rules, zones, concurrent sessions. Some of the specs which change with a different mem...

Remo by L7 Applicator
  • 14246 Views
  • 9 replies
  • 1 Likes

Resolved! NGFW routing internet traffic help

I am setting up a very simple PA200 implementation and all I need at this stage is to be able to contact the Palo update server to update the PanOS. I have the FW plugged in directly from ethernet1/1 to the modem (subnet 192.168.0.1). The gateway is pingable. My machine is connected to the the management interface (172.16.30.35). I have vir...

ebryan_1-1625177055815.png
ebryan_0-1625176896772.png
ebryan by L1 Bithead
  • 21438 Views
  • 23 replies
  • 0 Likes

Searching for missing logs in Next Gen Firewall monitor log.

I am trying to firgure out two things. background I have a Cisco ASA VPN concentrator that comes to my PA-5220 then goes to an application server. I am having issues where i see logs in the ASA of traffic coming from the far end point of the tunnel on a constant basis, then going to the application server. I am not constantly seeing any ...

Resolved! NGFW CSV Export Question

Hi there, I'm trying to get the seconds counter to show in NGFW Threat Monitoring CSV log exports. Currently, despite the seconds counter being displayed in the logs on the NGFW, these are not recorded in CSV exports of the logs - only the hour and minute counter is recorded. Is there an option to enable this somewhere? I can't seem to fin...

Josh990 by L2 Linker
  • 4445 Views
  • 2 replies
  • 0 Likes

Resolved! NGFW PA820 9.1.4 Strange NAT issue

We have a simple basic setup: WAN1/1 Untrust IP 123.45.67.89/29 LAN1/2 Trust IP 10.9.8.1/16 We NAT our WAN interface out to a different IP in the same network. 123.45.67.90 NAT POL Trust to Untrust Int1/1 Any Any to 123.45.67.90 Security Pol is Any Any I ping 8.8.8.8 from the LAN1/1 and it NATs out correctly with the .90 address Devices behi...

MrFritz by L1 Bithead
  • 8292 Views
  • 8 replies
  • 0 Likes

Resolved! In case you missed it - The MOST Flexible Software NGFW Consumption Model

Hey there everyone.. I wanted to take a second and let everyone know that Palo Alto Networks has just released a Brand New way to consume Software NGFW. You may have seen the banner on the main page.. which will link you to this blog: The Industry’s Most Flexible Software NGFW Consumption Model The reason that this is so very important for ...

jdelio_0-1612892500664.png
jdelio by L7 Applicator
  • 7846 Views
  • 3 replies
  • 1 Likes

PA NGFW with WSA proxy

HiAm trying to integrate Palo Alto NGFW with proxy web security appliance (Forcepoint WSA). Can palo alto PBF used to send web traffic traffic requests.All we are trying is to implement proxy transparently. Is there any equivalent of WCCP in Palo Alto.

Resolved! Next gen features on port based rules

Hello , We are in process on migrating port based rules to APP -ID but as it is time taking process , it may take us sometime . Can we still enable Security profiles like AV, Antispyware , Vul Protection , Wildfire , Data Blocking ; URL filtering on Port based rules ? Or is there a preq to have APP ID for these features ? we want to sta...

  • 1621 Posts
  • 61 Subscriptions
Top Solution Authors