Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4727 Views
  • 0 replies
  • 1 Likes

3 node cluster or HA

Hi community. I am setting up a palo alto firewalls for a customer and they need it as 3 nodes. they are going to be placed in three different buidling inside the same campus. I have gone through the documents and seeing that clustering is the only option as it is 3 in number. I want to know is there any way that i can make this into HA of ...

License expired

hello guru, what will happen if my either the support and CDSS license expired? I assumed the CDSS function will not work because no signature updates. how about Firewall, NAT and VPN? thanks,

Commit failed and firewall now down after reboot

Hi, I have a weird issue on a cluster of two firewalls on active/active mode. Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck. On the secondary I tried to commit localy and I had this error : Unable to generate IKE VPN transform(Mod...

pa-460 version 11.1.13-h7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 167 Views
  • 0 replies
  • 0 Likes

HTTP partial response - Security protection bypass

The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting. Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates. When HTTP parti...

DaMonk by L1 Bithead
  • 185 Views
  • 0 replies
  • 2 Likes

Resolved! Policy Optimizer not available in PAN-OS 12.1

Hello there, with the brand-new PA-520 and PAN-OS 12.1.4-h3 is the Policy Optimizer missing (see my screenshots). I have found this info "(PAN-OS 12.1.2 and later versions) To ensure the best performance, customize your view to display the Policy Optimizer, only when you need it. The system fetches data for this component on-demand, which prev...

J.Dhling by L2 Linker
  • 956 Views
  • 5 replies
  • 0 Likes

Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410?

Looking for sizing advice from anyone running PAN at a university/campus internet edge. Environment: University with 4,000–5,000 students plus staff/faculty Current internet bandwidth: 3 Gbps — expect this to grow substantially over the appliance's life (bandwidth per student keeps climbing; wouldn't be surprised to hit 8–10 Gbps by end of life...

simsim by L4 Transporter
  • 222 Views
  • 0 replies
  • 0 Likes

Best free Syslog server 2026

Hi everyone, we are currently trying to set up a syslog server as we would want to retain older logs in case we need it for auditing purposes. We are looking for a free one that's good in 2026. I'm currently choosing between an ELK stack and Wazuh, which would be easier? I have experience in setting up Docker containers. Was looking at Graylogs ...

Sizing PA-Series for internet edge — 3 Gbps today, growing to 8–9 Gbps, with SSL decryption. Which model?

Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale. Requirements: Internet edge only — no east-west/inter-VLAN (core switches handle that) Current internet traffic: ~3 Gbps, growing to 8–9 Gbps over the appliance's 5–7 year lifecycle Security profile: Threat Prevention (...

simsim by L4 Transporter
  • 206 Views
  • 0 replies
  • 1 Likes

Resolved! IPSec Dynamic Peer VPN, failure to send traffic over attached tunnel interface

Is anyone aware of a known issue with sending traffic over an IPSec tunnel interface when using multiple dynamic peers with FQDN (host) peer identification? I have multiple existing branch locations connected to the PA with IKEv2 IPSec tunnels using dynamic FQDN (host) peer identification from Cisco branch routers. Up to now it has worked fine...

Commit Protection – Automatic Restore Point Before Every Commit

The ProblemAs network technicians, we all know that committing a configuration is the most critical action on a firewall.Most commits complete successfully.Sometimes they don't.A wrong static route, a Virtual Router change, an interface modification or an incorrect NAT rule can immediately affect the firewall after the commit.The firewall is sti...

Is there a way to configure Pan-OS to integrate with an ACME server for certificate enrollment?

Hello, I am working with an IPsec VPN setup on my Palo Alto Networks firewall and am currently using certificate-based authentication. My organization utilizes an internal Certificate Authority (CA) that supports ACME (Automatic Certificate Management Environment) for certificate enrollment. However, I haven't been able to find any resources or ...

"Use Default Browser" option not showing in Strata cloud manager

Hello Team, We have client firewall managed with strata cloud manager. We were trying to use the default browser for SAML authentication. When we checked that option on firewall under GlobalProtect Portal > Authentication >"Use Default Browser" it worked. But we had to do that locally, because we do not see similar option in strata cloud m...

Jagdeep1 by L2 Linker
  • 1026 Views
  • 1 replies
  • 0 Likes
  • 1620 Posts
  • 61 Subscriptions
Top Solution Authors