Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4518 Views
  • 0 replies
  • 1 Likes

Byte swapping needed on packet captures taken from tunnel interfaces

I noticed something odd with packet captures taken involving traffic originating from a tunnel interface (used for GP VPN clients) where the Ethernet Type header was byte swapped. Meaning instead of 0x0800 it was 0x0008. The screen snips illustrate the raw exported packets from a NGFW running 11.1.4-h1. Wireshark 4.4.3 with no packet dissector/d...

Resolved! Palo Alto Firewall Global Protect SSL VPN MFA OKTA Integration

Hello Community, I'm looking into integrating Okta's Multi-Factor Authentication (MFA) with GlobalProtect SSLVPN. May I know is the OKTA MFA is free for Palo Alto firewall global protect SSLVPN. Can anyone confirm if Okta's MFA is indeed free when used with GlobalProtect? If so, could you point me towards any official documentation, guides, ...

GWong4 by L2 Linker
  • 2883 Views
  • 5 replies
  • 0 Likes

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4518 Views
  • 0 replies
  • 1 Likes

GlobalProtect Machine based Certificate Access

Hi Long time listener, first time caller. Since we have so many brute force attacks with GlobalProtect lately, I wanted to do machine based GlobalProtect Certificate access. Meaning we use a third party Certificate server within our environment to create Certificate and I assume this server would also be Root CA. Then push cert to all devic...

Resolved! Virtual IP for Management Interface

I have two firewalls in an HA configuration. I need to be able to have one "virtual" ip address for the management interface of the active firewall. For instance: Firewall1 IP is 192.168.1.10 Firewall2 IP is 192.168.1.11 Virtual Address 192.168.1.9 points to 10 or 11, whichever one is active. Has anyone else accomplished this and how did you do...

client gp_broker phase 1 failure commit failed

Hello,If someone experiences an auto-commit failure after an upgrade with the error message "client gp_broker phase 1 failure commit failed," here i provide a workaround solution :show jobs allEnqueued Dequeued ID PositionInQ Type Status Result Completed--------------------------------------------------------------------------------------2025/01...

Finding FQDNs for blocked IP's or SSL-Inspection

Once a week, someone reports having issues accessing a site. Today that issue involves a credit card processing page that is aging-out because there is no SSL inspection exception. FW Logs of course show an IP address (no URL/FQDN), and the rule to allow access or exclude from ssl inspection requires using an FQDN. The page URL in address ba...

ppeeters by L0 Member
  • 1233 Views
  • 1 replies
  • 0 Likes

Dual ISP setup on 1 virtual router kb issue

Hello. so I need to setup a dual ISP setup and found below kb. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAOI know there is also one using different virtual routers but for this specific setup it seems this one is a slightly better match. however 1 thing in the kb bothers me and in the past when I did this set...

PA-445 on PAN-OS 11.1.2-h3

First time posting so please bare with me. Currently running into an issue that looks like a potential bug or an issues specifically with the PA-445 model (Support Case has been submitted and is in the works; but we'll see what happens) Two different PA-445s that we've tested with have shown this issue (both PAs are on PAN-OS 11.1.2-h3). Below...

PA-445-issue.png
  • 1795 Posts
  • 60 Subscriptions