Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Error Index Protocol Error tlsv1 bad certificate status response. Received fatal alert BadCertificateStatusResponse from client

Hi folks, I'm using an SSL forward proxy policy and am getting this error:

 

Error Index
Protocol
Error
tlsv1 bad certificate status response. Received fatal alert BadCertificateStatusResponse from client
 
When a client attempts to connect to outlook.o
...

DHCP Fail

Hello Community,

I have a FW with eth0 configured as DHCP client and it gets IP, no problem. But then I see lots of DHCP Fail system messages between lease renewals:

 

 

Are these normal?

 

Thanks!

2022-11-28_16-22.png
Alex_S by L1 Bithead
  • 1404 Views
  • 4 replies
  • 0 Likes

Resolved! Cisco Twice NAT

I am working a migration of a Cisco ASA Firewall to Palo Alto and the NATs are confusing. 

 

Here are a couple of the NATs: 

 

(Outside) to (Vendor) source static 10.5.1.0/24 10.5.1.0/24 destination static (10.24.49.47 & 10.24.49.46) (10.24.49.47 & 1

...

PAN User-ID Agent

Hi All,

 

I installed User-ID Agent on the Windows DC, and it is working somewhat successfully. For some odd reason it recognizes the users from our domain but on the app's monitoring tab, where I can see the IP-User correlations, sometimes the users

...

Phase 1 compromise impact to Phase 2

Hi,

I would like to know if IKEv2 phase ia compromise because of weak encryption in proposal, malicious user can access to all data sent across the VPN connection, which may include passwords and sensitive file ?

 

Or

Malicious user only know phase 1

...

crypto by L2 Linker
  • 698 Views
  • 0 replies
  • 0 Likes
  • 907 Posts
  • 35 Subscriptions
Top Solution Authors
Top Liked Authors