Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

application based rule

Hi All ,
We are planning to implement application based rule like under application tab add required app and under service tab add application default.
However what would be best approach to apply rule where application is showing "incomplete".
Currentl

...

Resolved! SSL Forward Proxy Not Working

Hello all, another problem on my road to learning! I have created a self-signed CA Cert on my Palo Alto firewall. Exported to my Windows 10 box, imported into root CA store etc. I have set the cert as a Forward Trust Certificate, created a decryption

...

GWynn by L3 Networker
  • 2010 Views
  • 7 replies
  • 0 Likes

URL Lookup Returns IP Address

We use a URL filtering profile to limit outbound traffic.  Occasionally known good traffic will fail because an IP address, instead of the FQDN of the URL, is presented.  The traffic is blocked because the URL (IP address) is in the "Unknown" URL cat

...

Syslog issue

Hello All,

When we are using 9.1.14 Pan os we are getting below "" between ,, after upgrading 10.1.10-h2 it  is missing.....

 

 

Is there any way to get back the double quote like early?

 

KhaleelE_0-1700376553593.png
KhaleelE by L4 Transporter
  • 403 Views
  • 0 replies
  • 0 Likes

Custom URL category matching

Hello,

I'm trying to block a domain but allowing specific URL.

like:

test.com/ - block

test.com/test - allow

 

I made two custom categories and rules, first rule for allowing "test.com/test" and second rule for blocking "test.com"

The connection is h

...

yhlee1 by L2 Linker
  • 598 Views
  • 0 replies
  • 0 Likes

10.1.11-h1 broken on PA-410

Just lost 2 devices far away from home, seems to be the same bug described in https://www.reddit.com/r/paloaltonetworks/comments/17rjzfm/pa410_10111h1_no_ethernet/

 

440s and 3220s running fine with 10.1.11-h1. Is there no one at Palo testing their H

...

thah by L0 Member
  • 533 Views
  • 0 replies
  • 0 Likes

Resolved! portal-auth vs gateway-auth

Hi,

I’m trying to understand Palo Alto VPN client, Global Protect login process with logs and I’m a little bit confused. What I can see in logs:

  1. First is: portal-auth.
  2. Then usually portal-gen-cookie
  3. Next gateway-auth
  4. And finally, gateway-register

I woul

...

  • 1206 Posts
  • 45 Subscriptions