Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4523 Views
  • 0 replies
  • 1 Likes

All OSPF neighbors suddenly down

Hello all, Customer has a problem were their PaloAlto suddenly declares all neighbors adjacencies down, after that the PaloAlto will do a grateful restart and the OSPF neighbors will change to init, and then go full again, this OSPF flapping lasts 15 seconds or so so there is nearly no service impact at all, but customer would like to understa...

JMBerzal by L1 Bithead
  • 2178 Views
  • 0 replies
  • 0 Likes

PA 10.2.3, RADIUS Challenge caused timeout even it shows auth success on Monitor

Hello All, I have Palo Alto 10.2.3, and also 10.0.3 as a test. I used RADIUS to authenticate to the admin UI, then the RADIUS server sends a challenge, this is being handled normally by 10.0.3 but 10.2.3 seems to timeout although on Monitor it shows successful. Is this a bug? Can someone help me please this is very urgent. Also if I did want to...

Is it possible for Dynamic group containing all DHCP issued ip's from a palo reservation scope??

Hi All, I have a requirement. Palo DHCP reservations direct mac to ip- say 50 (changed occasionally enough to be annoying) I want a Dynamic group that skims the content of the reservations and permits in only those in an ACLs. Its painful to keep doing this manually in our multi FW / Panorama estate. is it possible?? Cheers in advance

Resolved! Application incomplete or insufficient-data when using NNTPS

Hello, I have been working with Cisco firewalls for the last 20 years, but I'm very new with Palo Alto and PANOS. At the moment I have a PA-460 in my lab for learning purpose. It's a basic setup with just a simple NAT/PAT rule for outgoing traffic to Internet and some basic access rules. Most things are working great, but I'm having some issue...

App-ID Override Policy Matching

Is there a way to identify what traffic is hitting a specific App-ID Override policy? We have several poorly configured App-ID override policies I'm trying to clean up and consolidate but they override to the same custom application, and it is not obvious from the logs which app-id override policy is actually being hit. 1) Good policy 2) Bad p...

SARowe_NZ by L3 Networker
  • 1570 Views
  • 0 replies
  • 0 Likes

Advance URL filtering - License - error "License required for URL filtering to function"

Hello team, I have a valid advanced URL filtering License - but when i navigate to URL filtering it says error "License required for URL filtering to function" Do i need to get PAN-DB url filtering license too ?? or is there some setting which i need to enable to get rid of this error ?? valid ADV URL filtering licensebottom you can see ...

URL Fl1.png
URL Fl2.png

Antivirus updates failing 9.1.15

Hi All. I am having issues where the antivirus updates are not checking the servers nor downloading. I have a valid advanced threat license and an expired threat license. Background running: 9.1.15 Observations: Content updates are functional and automatically downloading. If i delete the expired threat license, i am able to download the a...

Old-Roo by L1 Bithead
  • 3899 Views
  • 1 replies
  • 0 Likes

Please Release App-IDs for IBM AS400 user traffic

Hi, we have noticed traffic from users connecting to mainframes/midranges is showing as "unknown-tcp" and "insufficient-data" for the following ports: TCP/449 (Server Mapper) TCP/8470 (License Management) TCP/8471 (Database Access) TCP/8475 (Remote Command)TCP/8476 (Signon Verification) TCP/23 is of course being correctly identified as tel...

P19991 by L2 Linker
  • 3861 Views
  • 2 replies
  • 0 Likes

PAN to rsyslog on Ubuntu 22 yields unusable file names

Hi. I have a default setup w/ Ubuntu 22 as a rsyslog server. I pointed my PAN 10.2 to it, and am getting log data, but I am not getting a usable / meaningful file name. I'd like the log file name to be something like "perimfw" or some such to start. Hoping that some other PAN users here are logging to rsyslog and have a usable template line = be...

dmurdoch by L0 Member
  • 2238 Views
  • 1 replies
  • 0 Likes

Palo Alto ALG (Application Level Gateway) SIP dissable just for a particular source and destination IP addresses in a Security Policy?

Hello to All, From what I read about ALG (Application Level Gateway) functions on the Palo Alto Firewalls this function if needed is disabled globaly for the SIP default application or with application overide policy but this will stop the SIP signature matches. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEs...

Palo Alto PA 5220 not login after password complexity changes

We changed the password complexity and history settings on our firewall a couple of days ago. After committing the changes the local users are not able to login on the firewall. So we tried to boot into maintenance mode by connecting through a console cable in order to roll back to a older running config. This did not do anything though, because...

SSL/TLS decryption

Hello I would like to configure my Palo Alto to decrypt SSL/TLS inbound/outbound traffic. For Inbound, it's to control the traffic from Internet to our internal Web servers. Our internal Web servers is based on Apache or IIS with SSL. The certificate deployed on our Web servers are a wildcard *.compagne.com and provided by external public a...

  • 1795 Posts
  • 60 Subscriptions