Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4514 Views
  • 0 replies
  • 1 Likes

Resolved! Capwap Active Sessions in 2 ISP topology

Kind regards Team We currently have a topology in which the remote site has 2 VPNS configured (each VPN established by a different channel). The VPNs are configured against our Perimeter FW and the switching between them is done with Path Monitoring. The remote site has some Access Points that established a session (Capwap) against a controller ...

aalfaro by L2 Linker
  • 3905 Views
  • 5 replies
  • 0 Likes

Preferred version for update

Hi, Just looking for advise on suggested upgrade versions I have two VM-100s running 10.2.8-h3 and a PA-820 running 10.2.8. I need to upgrade them all in response to the CVE below. I'm a bit confused as both the Palo Alto preferred versions 10.2.9-h1 and 11.1.4-h1 listed here Support PAN-OS Software Release Guidance | Palo Alto Networks ...

Autocommit loop error and interfaces 'connected but down' after upgrade from 11.0.4-h2 to 11.1.4-h1

After upgrading my PA-VM VM-100 appliance from from 11.0.4-h2 to 11.1.4-h1 i was met with the following errors: - Constant failed 'autocommit' jobs spawning, similar to https://live.paloaltonetworks.com/t5/next-generation-firewall/auto-commit-stuck-at-11-0-2-h2-pa-410/td-p/563107. This prevents any admin action from the Web UI, - All interface...

OKelly by L1 Bithead
  • 974 Views
  • 0 replies
  • 0 Likes

NAT Config

Hi Team, In Checkp[oint we have an option to configure the dummy IPs in the NAT and use Proxy Arp to get it working. For example. Source: 10.10.10.1 Destination: 10.100.100.1(Dummy IP) Translation: Source: 172.16.10.1(Dummy IP) Destination: 172.17.25.1 And then configure the Proxy Arp and get this NAT working. This kind of NAT are used only t...

Device telemetry error "Failed to send: file" caused by "certificate doesnt exist.

Hello TEam, I am getting critical logs :- Failed to send: file \'PA_x.x.x.x.x.x_dt_10.2.3-h9_xxxxxx_1230_1-hr-interval_HOUR.tgz once i checked i found below articles. Device telemetry error "Failed to send: file" caused by "Client Certificate issue" (paloaltonetworks.com) i gone through the command details and found exact issue :- i wou...

jhussain1_0-1728325621127.png

Client Server SSL Decryption

Hi Folks ; I have a distributed software on my internal network and everyone is using it. It's like endpoint and it has a server .this server sometimes sends something to the server in the direction of the internet. I want to look into the data that it sends. I don't know if it is leaking critical information or what. I opened SSL Decypt and got...

susipicious.JPG
Fly_Al by L0 Member
  • 1356 Views
  • 1 replies
  • 0 Likes

Firewall creates seperate sessions for C2S and S2C

Hi folks, I was troubleshooting SSH connection and want to know if I missed something. The topology is following: Client ---> PFSENSE <====ipsec tunnel ====> PA VM ==== ipsec tunnel ==== AZURE ---> Server Client tries to establish SSH session with linux server. After some timeout the connection fails and we see app incomplet...

SSHconnect.png

SDWAN BGP over pre-existing BGP internet.

Hi Guys. We're deploying SDWAN in a customer who already has two ISPs connected in his hub, and talking BGP ECMP with them, using his public ASN and his own prefixes. According to documentation, the SDWAN plugin requires the same BGP Router ID and ASN when declaring the hub in devices, but it won't allow to use the public ASN here. So, my qu...

Debug process LDAP User-ID

Hi all, I am learning about Paloalto, however there are some parts I still wonder about, the process of checking accounts and mapping accounts with palo's ip. Is there any way for me to debug and see this process clearly? Currently, I can debug the LDAP part as attached file. TCPDUMP: LDAP Debug User-ID authentication: cảm ơn trước

ChungNX3_0-1727948529599.png
ChungNX3_1-1727948572904.png
ChungNX3 by L0 Member
  • 1638 Views
  • 0 replies
  • 0 Likes

Sd wan for dual Isp

Hi can anybody suggest me the step for configuration of dual ISP in palo alto. If primary goes down secondary will automatically has been up. My primary link is lease line with static ip and secondary link is brodband on DHCP. So kindly tell me how I configured it.

How to solve the Administrator Certificate-Based Authentication with issue of Redirection to prompt the username and password

The Certificate-Based Authentication for administrators to access the firewall through the web interface transparently authenticates the admin with a client certificate instead of prompting and entering manually the username and password. The Client Certificate must be generated and signed either by the built-in CA of the Firewall or an Enterp...

6.png
3.png
1.png
2.png
rmeddane by L2 Linker
  • 2058 Views
  • 1 replies
  • 0 Likes

postfix server nat rule on panos -9.-0.4

Hello , I cant update panos , i want simple bi-direction nat configuration i have rocky9 as a web,mail,dns server on kvm what is best nat rule sequence to work mail server correctly (after change nat rule sequence i am getting varity of erros 🙂 ) i am newly configeing nat and postfix that make me more diffecult to understand where is problem (p...

shrikant by L2 Linker
  • 1014 Views
  • 2 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions