Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4560 Views
  • 0 replies
  • 1 Likes

Resolved! In PAN version 9, public IP addresses and the VPN were accessible from the Intranet.

Hello everyone, I have a question: In PAN version 9.0, public IP addresses and the VPN were accessible from the Intranet. However, now that it has been updated to versions 10 and 11, access is no longer possible. Why did this happen, or is there anything else I can do with the firewall with these new versions?

Resolved! HA1-Backup Failing when setting to Management

I have a pair of 1410's configured for HA. Because the firewalls are not in the same room, I need to use the management interface for the HA1 backup. When I do the commit in Panorama, it commits without error. However, when I go to push it out, I get: Details: . Validation Error: . deviceconfig -> high-availability -> interface -&...

jwill2 by L2 Linker
  • 1712 Views
  • 5 replies
  • 0 Likes

Limit IP address range bandwidth during recurring time period

Need to limit residence hall users bandwidth to Internet monday-friday 8:00 a.m. to 5:00 p.m. The following is how it was done previously on Cisco ASA. Need to translate to PA5430. object-group network MV_NETWORKnetwork-object 192.168.0.0 255.255.0.0 access-list MV_TRAFFIC extended permit ip object-group MV_NETWORK any time-range RegularHours ...

What is Certificate Pinning and how to deal with SSL Decryption

Certificate pinning was developped to help prevent man in the middle attack. But what is the Certificate Pinning? Traditionally, SSL Handshake consists on the validation of the server’s certificate, let’s say collab.com. The validation is done using the CA’s certificate located in the certificate store of the web browser. The certificate sto...

Capture d'écran 2024-05-02 171322.png
SSL Decryption exclude.png
rmeddane by L2 Linker
  • 23860 Views
  • 3 replies
  • 2 Likes

VPN Performance over Prisma Access : slow downloads

Hi, Can somebody tell met what you can expect from downloading a file over prisma access backbone. Our datacenter is connected to service connection and when I try to download a 200 Mbps file from the datacenter to a remote network located in the same region, I am getting a download speed of 500Kbps per second.(smb transfer) Within the remote ...

zGomez by L3 Networker
  • 8357 Views
  • 8 replies
  • 0 Likes

LACP LINK DOWN FW PALO ALTO

Hi, I have a customer who's firewall unexpectantly failed over recently, looking at the logs before failover LACP links appeared to fail negotiation right before which triggers failover. Unfortunately HA logs don't stretch back enough! Looking at the l2ctrid.logs (LACP log files on TSF) See the bellow error constantly thrown leading up to ...

Traffic hits policy with URL Category even though the traffic is not for that URL

We have several policies that permit traffic to 80/443 with no specific destination address, but with a URL category set for a specific URL. For example, we have a post-rule for VPN users to access our internal Splunk server via the URL. The issue I'm seeing is that I am trying to connect to another device using https://ipaddress and the traf...

jwill2 by L2 Linker
  • 1250 Views
  • 3 replies
  • 0 Likes

Resolved! Users with multiple devices: more than one ip per username

The gating question is: is it true that user-id on the firewalls support only one IP address per username at a time? The followup question is: if so, what is the recomended solution for users logged into more than one device simultaneously with the same username to have all devices have policies applied correctly? Thank you!

uvdes by L2 Linker
  • 969 Views
  • 1 replies
  • 0 Likes

Palo Alto QOS configuration question

created the below QOS configuration to limit the bandwidth to wasabi to 10 mbps on PA 440. When I checked the QOS statistics, the default group is getting used and not the one I created and also the default group is restricted to 10 Mbps. Please guide me how do I fix it.Interface Ethernet 1/6 has a subinterface Ethernet 1/6.201. Create the QoS P...

ciscojuniperf5_1-1754548028266.png
ciscojuniperf5_2-1754548044354.png
ciscojuniperf5_4-1754548077387.png
  • 1589 Posts
  • 60 Subscriptions