Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4693 Views
  • 0 replies
  • 1 Likes

Mist AP and user-id

Hello all, I'm trying to get our new Juniper Mist ap's to work with user-id on a PA440, from reading around I see that only AD joined devices will work with user-id, and that's how its been for us for a while now, but we got the Juniper AP's and looks like there's a challenge on getting user-id to work, I'm using our on premise AD radius server,...

cdcirexx by L3 Networker
  • 1576 Views
  • 2 replies
  • 0 Likes

Resolved! DNS-Sinkhole Injection

The DNS sinkhole option works perfectly well with a Microsoft DNS environment. Unfortunately, it fails if you try to perform DNS-sinkhole injection in front of a BIND DNS server running on Red Hat Linux. Requests to malicious domains simply time out: Test-Domain from PaloAlto (works fine):nslookup -query=cname test-c2.testpanw.comtest-c2.testp...

HeinzP by L1 Bithead
  • 1783 Views
  • 3 replies
  • 0 Likes

Header Fields for Syslog for Rapid7

I'm troubleshooting an issue with Rapid7 ingestion of our logs from our Palo Alto firewalls into what they call an "IDS log." We need to write a custom parser to properly parse the source data, but that means we need the headers for all of the fields so that we can translate them into Rapid7's lingo. It seems like this "IDS log" is a combinati...

Anti virus profile not able to scan a file?

While Studying PCNSE and the topic is Using PA FW AV & WildFire I notice that the anti virus profile was not able to block the eicar.com file that keith barker downloaded on the FW. He created a decryption policy in order to block that file. On our FW on office we don't use decryption services because it is a CPU memory intensive. Altho...

weezy_0-1759715485043.png
weezy by L3 Networker
  • 1136 Views
  • 2 replies
  • 0 Likes

2 LANs are not reachable to eachother

In Palo Alto Firewall, we are facing an issue. we have configured 2 LANs and 2 WANs. working fine even load balancing also works.But LANs cannot ping/reachable with eachother. even both lans having internet access.How can we configured that LAN can reachable with eachother and rest of configuration remain same.Thanks

Outbound SSL Decryption Quirk

Hello, I have established an outbound SSL decrypt policy that I have enabled for only myself as I test functionality. Over the past few months, I've noticed a quirk that I'm unsure of the reasoning behind. With the policy enabled, sometimes connections to certain destinations will require a reload of the webpage to establish connection. For ...

RH747 by L2 Linker
  • 2520 Views
  • 2 replies
  • 0 Likes

Regarding the support for Cisco ISE integration with PAN-OS 12.x.

Hello, ExpertI have a question regarding the support for Cisco ISE integration with PAN-OS 12.x. In the PAN-OS 11.0 (EoL) documentation, it appears that integration with Cisco ISE (TrustSec) is supported through the Panorama Plugin:https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/panorama-features/static-security-group-tag-sgt-s...

boyuzhan by L0 Member
  • 949 Views
  • 1 replies
  • 0 Likes

LSVPN Portal connection Failed

Hi We have around 500 sites and most of them are connected via LSVPN and a Site-2-Site VPN for backup. At somepoint the username for the portal connection has been changed which means all off the sites that are connected via LSVPN report that they have failed to connect to the portal. My question is, if the NGF fails the Portal connection a...

R.Moth by L0 Member
  • 722 Views
  • 1 replies
  • 0 Likes

VM firewalls can not join VM panorama all hosted in AWS cloud

Hello Team, We are having an issue connecting palo-alto VM firewalls in AWS to the panorama hosted in AWS as well. connectivity is successful between the firewall and panorama and we are using management port for this traffic. we ran below command show netstat all yes numeric-hosts yes numeric-ports yes | match IP and found the state established...

palocomunitypanorama.PNG
Jagdeep1 by L2 Linker
  • 1459 Views
  • 4 replies
  • 0 Likes

Resolved! Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy

Hi Team, I’m experiencing an unusual issue with my Palo Alto firewall. This problem started about a week ago. Prior to that, the website in question was functioning properly and being handled by the appropriate security policy. Currently, a public website is being blocked by a specific security policy in the firewall. Upon reviewing this polic...

  • 1607 Posts
  • 61 Subscriptions
Top Solution Authors