Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

saml-message-parse-error

Hi,

 

I saw this alert on our corporate firewall ; 'Failed to convert SAML message payload into xml tree', as a high level,

Is there anyone to explain what this means and what this situation effects to our SAML vpn configurations?

 

Please inform to

...

Error: update_rlog_mgmtsrvr_fwd_stats(panDeviceLogging_access.c:710): panDeviceLoggingMIB update_rlog_mgmtsrvr_fwd_stats(): No sysd node found

Hello community,

 

 I have encountered the SUBJECT error while t-shooting a SNMP connectivity issue on a PA-220. searching the internet I have not found a similar message anywhere therefor I thought I'd reach out to see if anyone can help with figuri

...

Kobiher by L2 Linker
  • 760 Views
  • 0 replies
  • 0 Likes

SSL No-Decrypt issues

Hello,

I'm testing on two different versions of PAN-OS (11.0 and 11.1).  There's a couple of issues I'm noticing with decryption/no-decryption.  I have a profile setup for no-decrypt in which healthcare-and-medicine is a category that isn't supposed

...

HIP Check on Patch Management

I want to check if we can block connections if a device is missing critical patch (released May 2024) or any other critical patches within the last n months (where n is a user-defined timeframe).

Can this be achieved with HIP configuration?

VPN over Multiple ISP connections

Hi,

 

I am new to the PA world and I have the following design been given to setup. I am trying to find the best way to do this. I have done in Fortinet by creating SDWAN interface and it worked but not sure if Palo has the same kind of setup. If som

...

gondolf by L1 Bithead
  • 1656 Views
  • 1 replies
  • 0 Likes

Log Retention for PA-1400

Hi,

 

Specifically for PA-1420, I aware the storage capacity is 240GB. Is there anyway I can know the duration of log retention for 700 users?

 

From what I understand, log retention is affected by the space on disk, not on the number of user. When y

...

Resolved! Distributed VPN attack

Recently we experience distributed VPN dictionary attack on our Palo Alto Global Protect from different countries, ISPs and hundreds of IP addresses. Since we have MFA the attack was unsuccessful so far but I want to stop it somehow. The malicious ac

...

  • 1432 Posts
  • 49 Subscriptions
Top Liked Authors