Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4598 Views
  • 0 replies
  • 1 Likes

URL filtering response Page

Hi Friends, We have a requirement regarding the URL filtering response page. Currently, when a URL is blocked due to a predefined or custom URL category, the URL blocked response page is displayed. However, if the traffic is denied through the QUIC protocol, the predefined URL response page does not appear. Is it possible to display the URL fi...

Satyak by L3 Networker
  • 1136 Views
  • 1 replies
  • 0 Likes

Resolved! New error after power outage event: CloudAuthService Server certificate validation failed. Dest Addr: license.api.paloaltonetworks.com

Maybe I'm just low on sleep, but something doesn't seem to be lining up here. Had a power outage over the weekend and am now getting these High severity system notifications from a PA440 about every 10 minutes. > CloudAuthService Server certificate validation failed. Dest Addr: license.api.paloaltonetworks.com, Reason: self signed certificate...

How to check temperature sensors from GUI

Hi, I was wondering if it is possible to check the temperature sensors of a Paloalto PA-220 firewall from the GUI. I have seen that it is possible to check via the CLI, but I do not have immediate access to the CLI and was wondering if it could be done through the GUI. Thank you in advance

GRC_INF by L0 Member
  • 2080 Views
  • 1 replies
  • 0 Likes

User-id agent Servicer connection using Kerberos

Hi Our Palo NGFW connects to AD servers using Kerberos as part of the user-id feature. We have received advisories from other networking partners that MS is applying a change in the way it enforces certificate based authentication - KB5014754. Does anyone know if or how this may affect the user-id authentication on the Palo? Any advice on how ...

Joe_Ng by L1 Bithead
  • 665 Views
  • 0 replies
  • 0 Likes

Byte swapping needed on packet captures taken from tunnel interfaces

I noticed something odd with packet captures taken involving traffic originating from a tunnel interface (used for GP VPN clients) where the Ethernet Type header was byte swapped. Meaning instead of 0x0800 it was 0x0008. The screen snips illustrate the raw exported packets from a NGFW running 11.1.4-h1. Wireshark 4.4.3 with no packet dissector/d...

Resolved! Palo Alto Firewall Global Protect SSL VPN MFA OKTA Integration

Hello Community, I'm looking into integrating Okta's Multi-Factor Authentication (MFA) with GlobalProtect SSLVPN. May I know is the OKTA MFA is free for Palo Alto firewall global protect SSLVPN. Can anyone confirm if Okta's MFA is indeed free when used with GlobalProtect? If so, could you point me towards any official documentation, guides, ...

GWong4 by L2 Linker
  • 3149 Views
  • 5 replies
  • 0 Likes

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4598 Views
  • 0 replies
  • 1 Likes

GlobalProtect Machine based Certificate Access

Hi Long time listener, first time caller. Since we have so many brute force attacks with GlobalProtect lately, I wanted to do machine based GlobalProtect Certificate access. Meaning we use a third party Certificate server within our environment to create Certificate and I assume this server would also be Root CA. Then push cert to all devic...

Resolved! Virtual IP for Management Interface

I have two firewalls in an HA configuration. I need to be able to have one "virtual" ip address for the management interface of the active firewall. For instance: Firewall1 IP is 192.168.1.10 Firewall2 IP is 192.168.1.11 Virtual Address 192.168.1.9 points to 10 or 11, whichever one is active. Has anyone else accomplished this and how did you do...

client gp_broker phase 1 failure commit failed

Hello,If someone experiences an auto-commit failure after an upgrade with the error message "client gp_broker phase 1 failure commit failed," here i provide a workaround solution :show jobs allEnqueued Dequeued ID PositionInQ Type Status Result Completed--------------------------------------------------------------------------------------2025/01...

  • 1586 Posts
  • 61 Subscriptions