Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

PA-400 Check software not working

Hi, I have a standalone PA-440 device which I tried to check for upgrades to update its PANOS from 11.0.x releases to 11.1, but the check for updates never pulled any new updates from Palo Alto repositories, and all I am getting is an empty list. What I tried so far: I verified the connectivity to the Palo updates websites ( DNS and service ...

Resolved! [China] Can't get device certificate on PA440

Hi everyone, We are based in Shanghai and we encounter an issue to generate a device certificate. On the web interface, we don't have the "Get certificat" option And when i try to request via CLI, nothing happen with the cmd "request certificate fetch" and i have a invalid syntax with "request certificate fetch opt 'opt number'" Thank in a...

Sauneuf_0-1730856124382.png
Sauneuf_1-1730856248383.png
Sauneuf_2-1730856479672.png
Sauneuf by L0 Member
  • 1511 Views
  • 1 replies
  • 0 Likes

Palo Alto-certified SFP check

Hello,Normally we use the following commands to check an SFP by Palo Alto Certified or not. how system state filter sys.s1.p19.physys.s1.p19.phy: { 'link-partner': { }, 'media': SFP-Plus-Fiber, 'sfp': { 'connector': LC, 'encoding': Reserved, 'identifier': SFP, 'transceiver': 10000B-SR, 'vendor-name': OEM , 'vendor-part-number': PAN-SFP-PLUS-SR ...

PAN OS Issues with MPLS Link

We noticed that the customer’s environment had an upgrade of the PA-440 to PAN-OS 11.1.4-h1, but they experienced an MPLS link-down issue. The same issue was observed on the remaining four firewalls. After downgrading to PAN-OS 10.2.10, the MPLS link was working fine. Could you please confirm if this is a known bug?

problem in integration with clearpass XML API

while trying to integrate Aruba ClearPass with PA to send login info and user role to PA from ClearPass using XML API the following errors appears in ClearPass side, and no error appear from PA side unable to post request to PAN (IP address), error: (httpsession): unable to execute POST request url:xxxxxxxcontext deadline exceeded (Client Timeo...

Enhancing OT Network Security with a 2.5 DMZ:

In our OT network, we're considering adding a Level 2.5 DMZ to bolster security. This would serve as an additional layer of protection between the control systems (Level 2) and the enterprise network (Level 4).Specific Design:Level 2.5 DMZ: Host third-party servers and Engineering Workstations (EWS).Level 3.5 DMZ: Maintain existing role as a DMZ...

Norkk87 by L0 Member
  • 1451 Views
  • 0 replies
  • 0 Likes

How to configure GRE over Ipsec

Hi team, How to configure GRE over Ipsec between PaloAlto and cisco Router using ospf? I need sample document for configure? If anyone did it before please share... I checked whole live community but there have no exact configuration. Thanks Al Amin

Al-Amin by L2 Linker
  • 881 Views
  • 0 replies
  • 0 Likes

Unified Log Timeout Field

PA14010, PANOS 11.1.x. Have TCP and UDP idle timeouts configured for 900 seconds globally, and as high as 86400 for some applications. Development team would like to see when the firewall enforces timeouts, as they think the firewall is causing failures. The Unified log under Monitoring has a 'Timeout' field which never has data, even when we cr...

Paloalto FW HA(Active/Passive) OS Upgrade Procedure 10.1.X -> 11.1.X

HelloI have a question about upgrading the Palo Alto Fire Wall OS.From the 11.1.X version, we've seen that you can upgrade right away without a 10.2.X or 11.0.X install. ex) OS Upgrade(10.1.13-h1 -> 11.1.5)I ran the test on my Standalone firewall (10.1.13-h1) and verified that the upgrade was successful through 11.1.5 install after 11.1.0, 1...

sky95hhhh_0-1730177508043.png
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors