Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4693 Views
  • 0 replies
  • 1 Likes

Issue with Intermittent Blocking of ChatGPT URL-Not-resolve

Hi Team, I’ve noticed that in my environment, the chatgpt.com URL is intermittently categorized as unresolved and is being blocked. For your reference, I am attaching a snapshot highlighting this behavior. Please let me know if additional information is needed to address this issue. PAN DB- Connectivity is there @Adrian_Jensen @mshama...

RoneyRajan123_0-1738049273140.png

FQDN resolution mismatch

I have a connection to a destination FQDN allowed via Palo Alto firewall PA 440.Palo alto shows a different IP to the FQDN than one on the host machine when I do a nslookup. Connection to the destination is getting reset Please advise on the steps and procedure to resolve this issueError on the browser: ERR_CONNECTION_RESETWhere can I see this o...

PA-1410 - secondary IP unreachable

I have an issue where the secondary IP-address is unreachable on PA-1410.The deployment looks like.2 PA-1410 HA (active/passive) Aggregated layer 3 interface with sub-interface (vlan tagged) Management profile allow ping only Firewall policy is allowing ping in- and outbound Advanced Routing is enabled I tested the troubleshooting tool ping wi...

Factory 5220

There are two drives on the 5220. The factory reset for version 10 says to select maintsys-root1 and reset. Why not root0 as well. The device has two drives so wouldn't maint-syroot0 need to be ran as well? It looks like the drives are setup in a raid that mirrors the drives (not sure exactly). With this being said I don't know the different way...

DJDN12 by L0 Member
  • 1038 Views
  • 0 replies
  • 0 Likes

License and dynamic update query

Hi All, I have panorama integrated Palo Alto devices and need help on below query1) Can we perform dynamic update of Palo alto from devices itself instead of panorama. Does this practice unsync the Palo Alto from panorama ? 2) panorama having only management license but when I do check dynamic update it shows latest update. Should I move to upda...

NTP Not synced but got time-learn in Logs

Hi Team, Ntp not synched but got initiate time-learn in logs.>show ntp ntp not synched, using local clock status : rejected reachable: yes authentication-type: none Have tried to set it to public server still the same. And also when try to set manually, it reset the time to the previous time. So is it sync or not sync I am getting time-le...

Design suggestion

Hi All, I'm from network team not Firewall team. Presently we have ASA FW which we are planning to replace with two Palo's. Presently we have one WAN link going to the FW and one link to LAN router. Now how to connect two Palo's when we have one WAN link This is what i thought of but in this i have a question that will the FW support Layer 3 p...

anee4285_1-1737725715924.png
anee4285_2-1737726251355.png
anee4285 by L0 Member
  • 1020 Views
  • 2 replies
  • 0 Likes

PA 5250 Factory Reset failure

Hello, I wanted to reset a PA5250 via CLI. Nothing special. However, this was aborted at 0% with the message “Factory reset failed”. After the error, I am no longer able to access the CLI, as the message appears permanently as soon as I write something. Not even access to the maint works. Unfortunately I cannot open Case because Palo Alto no lon...

m.Barman by L1 Bithead
  • 1432 Views
  • 4 replies
  • 0 Likes

HA (active Passive) 10.1.X to 11.1.X upgrade path

Hi, I will upgrade a paranoma VM in 10.1.5 and a pair of managed firewalls in HA Active passive from the same verstion to 11.1.XThis guide indicates I need to go through every feature release when upgrading HA firewalls:"When upgrading HA firewalls across multiple feature PAN-OS releases, you must upgrade each HA peer to the same feature PAN-OS ...

  • 1607 Posts
  • 61 Subscriptions
Top Solution Authors