Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4602 Views
  • 0 replies
  • 1 Likes

Using external zone in DNAT policy

Hi Team, We have 2 VSYS configured to communicate. VSYS 1 has 172.25.80.254 zone L3 : DC VSYS 2 has 172.25.70.254 zone L3 : DMZ I added two external zone (DC to DMZ) and (DMZ to DC) to allow communication between vsys and also the routing between VR of both Vsys. In DC , i have DNAT policy allowing a load balancing to 2 SRV located in zone L3...

Configure PAN OS locally when panorama is down

Hello team, I want to ask if when the panorama VM is down , and we need to configure firewalls locally, in this case , when we turn on the panorama , how would be the behaviour : 1- Panorama will detect that configuration is not sync and will inherit from FW? 2- or , the changes will not apear in panorama , and how to add these changes to pano...

Resolved! External virtual network pointing to many internal ip

hello, We are migrating from forcepoint to PA. we face the case below: a virtual network (172.28.66.0/24) is assigned to multiple servers , behind it , there is a group for Such LB in FPT (pointing on 28.66.0 means : one for 172.28.72.2 and 172.28.72.3 for exemple). in PALOALTO, i created DNAT rules for dynamics load balancing between addresses....

Resolved! DoS Block Table API

Good Morning! I am looking to create a Powershell script to list and clear IPs that have been added to the DoS Block-Table. I have tried this through Powershell PoshSSH and OpenSSH but can't get neither to work fully. I looked around for the API to accomplish this but haven't been able to find it. So my question, is there an API to list and ...

Path error issue when performing SCP from CLI of Paloalto NGFW.

Hello, I'm currently trying to transfer Stat-dump to NAS using scp by specifying a desired period.I think the connection has been made since the NAS user authentication step has been completed through the CLI command.However, an error occurs saying that the path I've never seen before does not exist.The following is the error.Could not chdir to ...

"Use Default Browser" option not showing in Strata cloud manager

Hello Team, We have client firewall managed with strata cloud manager. We were trying to use the default browser for SAML authentication. When we checked that option on firewall under GlobalProtect Portal > Authentication >"Use Default Browser" it worked. But we had to do that locally, because we do not see similar option in strata cloud m...

Jagdeep1 by L2 Linker
  • 887 Views
  • 0 replies
  • 0 Likes

Issue with Intermittent Blocking of ChatGPT URL-Not-resolve

Hi Team, I’ve noticed that in my environment, the chatgpt.com URL is intermittently categorized as unresolved and is being blocked. For your reference, I am attaching a snapshot highlighting this behavior. Please let me know if additional information is needed to address this issue. PAN DB- Connectivity is there @Adrian_Jensen @mshama...

RoneyRajan123_0-1738049273140.png

Device transfer query

Hi All, Facing below error while registrating the device. " Device and support code do not match support account. Please contact super user to send you a registration link for approraite support account." Also what could be the steps to device transfer from one domain to another Example palo@xyz.com to alto@uvxyz.com

  • 1586 Posts
  • 61 Subscriptions