Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4510 Views
  • 0 replies
  • 1 Likes

Resolved! New admin accounts could not login in web gui

Hello, I have done the setup of a new PA-445 running software version 11.2.3 I have added new device admins as superuser in Device-->Administrators But when I try to login I get the message "failed authentication for user \'adm-test\'. Reason: Authentication profile not found for the user. From: %ipaddress%.' How can I solve this problem? ...

M.Bock by L2 Linker
  • 1790 Views
  • 5 replies
  • 0 Likes

VPN PA-400 to PFSense

Hi all! I've created an IPsec VPN site-to-site between Palo Alto and PFSense.We are facing problems because the tunnel doesn't connect. We see the errors below on Monitor Logs: Error1 = IKEv2 IKE SA negotiation is started as responder, non-rekey. Initiated SA: IP_PALO_ALTO[500]-IP_PFSENSE[33848] SPI:1719700341f53997:4c83ee594abb7b38. Error2 = ig...

admin by L0 Member
  • 741 Views
  • 1 replies
  • 0 Likes

PA850 last supported PANOS 11.1.x

Hey Folks, The last supported version for the PA-850 is PAN-OS 11.1.0. The PA-850 has End-of-Support (EoS) until 2029. However, I want to confirm whether security patches, threat updates, and other dynamic updates will continue to be provided until 2029. We need to ensure that the firewall remains secure against vulnerabilities throughout its...

nsingh by L0 Member
  • 2884 Views
  • 1 replies
  • 0 Likes

Proxy IDs between Peers

Hi, if the remote peer require local palo alto to set proxy IDs, what happens if the proxy IDs at PAN side doesn't match the ones at remote? would this cause any issue i.e traffic gets dropped or does palo alto forward the traffic down the tunnel as long as there is a route. Thanks

AY_FASAR by L1 Bithead
  • 670 Views
  • 1 replies
  • 0 Likes

Support regarding query

Hi All, My current PA support is ASC (Authorized Service Center) where they open a Case on my behalf. How can i change my ASC or transfer my device ownership to some other support partner. Pls note: Support is currently valid and active to my existing ASC partner

URL Filtering Issue with Gaming Category

Hi Team, Good day to you! We are facing an issue with URL filtering. Specifically, we are unable to block gaming URLs through the filtering system. The customer has a specific user group called the Travel Group, for which a separate URL filtering category has been created. This setup is working as expected. However, the issue arises when attemp...

High availability failover: GARP doubts.

Hey guys!. First time poster here.To begin with, I am beginner to PA and learning my way through. I have just reached the HA part, and have a few questions.In an active/passive deployment, when the Active unit fails and the Passive unit starts taking over, it sends GARP and updates the downstream/ (upstream?) switches CAM tables with the new in...

Nadeem69 by L0 Member
  • 1078 Views
  • 1 replies
  • 0 Likes

Palo Alto Login issue though GUI " ERR_SSL_KEY_USAGE_INCOMPATIBLE " (Solved)

For the last few days, we have been experiencing an issue with logging in to the Palo Alto Firewall through the GUI. We are getting the below error from the browser during login. After that, we contacted TAC support but they were unable to solve this issue, and they suspected this issue happened due to the browser. Today morning we we...

abdulmunem_1-1702196767687.png

Finding Rootkits in Palo Alto

I was looking for information on finding and removing rootkits on Palo Alto, using the CLI commands. Reinstalling PANos isn't an option for me, but any help would be greatly appreciated. I know there is a rootkit installed, but I am not entirely sure what it does, beyond bricking the firewall when upgraded to a new base version.

Plugin-DLP mis-match on HA pair (HA not syning)

We recently had a firewall failure in a High Availability (HA) pair and replaced the faulty unit. However, there's a mismatch in the Data Loss Prevention (DLP) plugin versions: The working firewall is running DLP 5.0.1 with OS 11.1.6-h1 The replacement firewall has been updated to OS 11.1.6-h1 but only has DLP 5.0.4 available I do not want to ...

din100 by L3 Networker
  • 3105 Views
  • 1 replies
  • 0 Likes

IPSec Tunnels acting Strange

Version 11.1.4-h7 I am unsure if anyone else has experienced this. We are seeing IPSec tunnels suddenly showing errors in the system logs that IKE phases are just deleting one right after the other and not initializing. Originally one of the tunnels actually went down and caused some issues, but it was able to be fixed via the test commands to r...

BTS_MS by L2 Linker
  • 585 Views
  • 0 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions