Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4789 Views
  • 0 replies
  • 1 Likes

Firewall with L2 Interfaces and dual uplinks to switch.

Question on L2 Interfaces and internal VLANs. We are connecting a 220R with all interfaces in L2. We have 2 gateway switches so this firewall with have dual uplinks (one to each GW). How do I apply a VLAN to these interfaces? Do I even need to? One some other deployments where we've had dual uplinks (but usually to the same switch, not sep...

jwill2 by • L2 Linker
  • 1423 Views
  • 1 replies
  • 0 Likes

GW ARP reply..

From the tcpdump output, the device with the MAC address b4:0c:25:e0:40:10(FW being the GW) is repeatedly broadcasting ARP requests, asking for the MAC addresses of multiple IPs within the 10.248.8.x range. It is sending these requests to identify the MAC addresses of devices associated with those IP addresses. This is resulting connectivity iss...

MS Teams Aplication Performance Issue –Intermittently

Hi Team, We have received reports from three customers experiencing intermittent performance issues with the MS Teams application, specifically with audio and video not functioning properly. Troubleshooting Steps Performed (Palo Alto Firewall): ✔ Removed all security profiles from the policy✔ Configured QoS and assigned guaranteed bandwidth for ...

Resolved! ERROR DURING THE BOOT PROCESS( Suggest the resolution)

Configuration file format is too old, syslog-ng is running in compatibility mode. Please update it to use the syslog-ng 3.29 format at your time of convenience. To upgrade the configuration, please review the warnings about incompatible changes printed by syslog-ng, and once completed change the @version header at the top of the configuration fi...

VM-Series Esxi and KVM

Hi guys I have received a 30-day trial vm series for ESXi and KVM to my official email ID to check its features, we have deployed it in our virtual environment in ESXi and KVM, but it shows an error during the login as shown in the screenshot, I have sent an email but no response from PA, rather they some link there login unexpected error to in ...

Are there any cases where certificates are marked as UNKNOWN other than when using CRLs with IDP extension?

Hello everyone, From the following knowledge, I understand that in CRLs with IDP Extension, certificates not listed in the CRL are marked as UNKNOWN. PAN-OS Behaviour for CRLs with IDP Extension: Certificate marked Unknown" if not listed in the CRL"https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldJCAS Are there ...

Static route path monitoring using a destination within a different virtual router

Hi, Is it possible to set up path monitoring for a static route using a destination IP address in a different virtual router? My scenario is within virtual router 'A' I have a static route with a destination of a NAT range pointing to an interface to get it in to the routing table and then advertising it via BGP. Traffic destined for the NAT IP'...

PMoore by • L0 Member
  • 839 Views
  • 0 replies
  • 0 Likes

potential issue with RADIUS traffic passed through Palo devices

Hi all, There is a good chance this is not in fact a firewall issue at all. But I just wanted to ask people who have more experience than me. Has anyone experienced an issue where despite RADIUS traffic being passed through a Palo appliance successfully, RADIUS authentication has still failed? The scenario I describe is from Meraki AP's to a w...

Resolved! Inter-VR Routing issue with public IP addressees

Hi Team, I’m running into an issue with inter-VR routing and need some help. Here are the details: PA-1410 is connected to two ISPs. A /27 IP range is advertised from both ISPs to the firewall. We have P2P links between the firewall and each ISP, where the additional /27 and default route are advertised to our firewall. Current Configuration...

Ikev2 liveness check

Hello, I have a couple of questions regarding IKEv2 Liveness Check and DPD (Dead Peer Detection) on Palo Alto Networks firewalls. I’ve come across some conflicting information in various articles. Some mention that DPD is always active and cannot be disabled in IKEv2, while others suggest that the Liveness Check is the new version of DPD in IKEv...

Do you know why you cannot check the Block IP list in other models except PA3200 , PA5200, PA5400 and PA7000 Series

Hi I should look at 'monitor > Block IP List' However, the tab could not be checked in the VM series and 3400 series. And after checking the document, I found that only the 3200, 5200, 5400, and PA7000 Series support H/W Block IP List. Are there any differences between the models mentioned above and the 3400? And is it correct that there ...

  • 1633 Posts
  • 62 Subscriptions
Top Solution Authors