Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4507 Views
  • 0 replies
  • 1 Likes

Upgrade 5450 to 11.1.6h10

I am currently on 10.2.10-h9 going to 11.1.6h10 (preferred). Has anyone experienced any issue with the new release on 5450 FW? In the past I upgraded to 11.1.4-h7 and it went horribly BAD. Not the upgrade process but that release 11.1.4-h7 has bugs. Non of the websites we are hosting were accessible. sometimes it works and other time so mu...

BFP with OSPF graceful restart causing outages during failover

Dear community! In a active/passive configuration with OSPF graceful restart and BFD enabled, when we do failover we experience a downtime 1 minute after the failover and it takes about 10 seconds to be fixed. Checking the logs it looks like the firewall builds the new BFD sessions with the core switch, but after 1 minute after the failover th...

Carracido by L4 Transporter
  • 1778 Views
  • 1 replies
  • 0 Likes

About BUG PAN-226361 for PA-820 device running version 10.2.10-h9

HelloI wanted to ask you a question about a problem I just encountered, I have seen the BUG PAN-226361 reproduced in the PA-820 equipment is in version 10.2.10-h9 and yet this BUG has been corrected in the hotfix 7 of the same version, does anyone know if it has been re-activated in higher versions and what is the recommendation of Paloalto in t...

Alpalo_0-1754045210096.png
Alpalo by L4 Transporter
  • 1043 Views
  • 1 replies
  • 1 Likes

Paloalto firewall google drive blocking -- quic based problem

Hello,We are experiencing an issue with blocking Google Drive access through Palo Alto Firewall despite applying several mitigation steps.Current Setup:SSL Decryption is enabled and functioning.Security policies and URL filtering are configured to block:drive.google.comdrive.google**.drive.google.com*.google.com (selectively for Drive-related se...

OrkhanM by L1 Bithead
  • 2220 Views
  • 2 replies
  • 0 Likes

Subject: GlobalProtect Connection Issue After SSL/TLS Certificate Renewal

Hello Team, We’re currently experiencing an issue where GlobalProtect is not accessible after renewing the server certificate associated with the SSL/TLS profile used by our GlobalProtect portal. Error message:GlobalProtect: Connection Failed. The network is unreachable or the portal is unresponsive. Check the network connection and reconnect. T...

Jagdeep1 by L2 Linker
  • 1242 Views
  • 1 replies
  • 0 Likes

Resolved! Detect high bandwith consumption

Hello everyone! I´m looking for a way to identify a user or IP when they have high bw consumption Lets say a user is downloading something and is using all my ISP bw, how can I identify it in that moment? I was able to do this but when the session was finished, in my scenario my user downloaded something for 2hs an I had to wait until that to ...

procom by L1 Bithead
  • 2513 Views
  • 5 replies
  • 0 Likes

A commit is in progress. Please try again later

Running 10.2.13 on a PA-440. Current config issues mean a commit fails. The unit keeps trying to auto commit very frequently (which fails). If i try to change the config and commit, i get the message "A commit is in progress. Please try again later". If i try to install a different software version i get the same error. How can i disable auto co...

Resolved! My IPSEC tunnel not able to UP

less mp-log ikemgr.log [PERR]: Couldn't find configuration for IKE phase-1 request for peer IP 52.a.b.115[500].2025-07-25 00:32:54.452 +0700 [PERR]: Couldn't find configuration for IKE phase-1 request for peer IP 52.a.b.115[500].2025-07-25 00:33:35.355 +0700 [PERR]: Couldn't find configuration for IKE phase-1 request for peer IP 52.a.b.115[500]....

Application Shift and How to allow linkedIn but block specific linkedin-posting application

When you want to allow the linkedin-base application with a specific Security Policy Rule, for example Linkedin-Rule, the Implicit applications it depends to are automatically allowed by the firewall, this means that the Security Policy Rule Linkedin-Rule that matches the linkedin-base application will automatically allow the web-browsing and SS...

rmeddane_0-1708248019818.jpeg
rmeddane_1-1708248019825.jpeg
rmeddane_2-1708248019832.jpeg
rmeddane_3-1708248019840.jpeg
rmeddane by L2 Linker
  • 4093 Views
  • 1 replies
  • 1 Likes

UserID mapping for users usings Azure VPN Gateway and AzureAD

Hi All, I have a unique scenario. We have a PA VM Firewall in Azure. We use Azure VPN Gateway to allow users to VPN in if need be (mainly 3rd party support) to get to services on the other side of the FW. The user's credentials authenticate against AzureAD using MFA. I need to know if there is a way to implement UserID, or something similar, t...

Resolved! Can NGFW Block Trafic Depending on the client and source IP

Hello,We have a requirement to control connections from local virtual machines (VMs) to public endpoints. Specifically, we need to enforce access policies based on:The type of client submitting the request (e.g., web browser vs. desktop tool)The IP address of the VM from which the request originates Is it possible to implement such granular cont...

pan_iv by L0 Member
  • 1700 Views
  • 2 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions
Top Solution Authors