Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

The allow security policy configured with the app-ID "netbackup" and an "application-default" as a service doesn't work correctly.

Dear and valuable Live Community Members,

 

I have a problem understanding the below-described behavior in regard to the security policy used in the firewall: 

 

We have a firewall policy configured to allow NetBackup traffic, but if we configure it

...

image001.png
Standard Ports_netbackup.PNG

Resolved! Firewall cloning for DR

Hello,

I have a Panorama that manage 2 cluster. Each one have a dedicated Device-Group and Template.

Now the cluster 2 must be recycled as a DR of the cluster 1. 

My idea is to reassign the cluster 2 to the same DG and Templ of the cluster 1. Should

...

Path Monitoring - latency

I'm not using PAN SD-WAN.

 

I have static route path monitoring configured for multiple ISPs.  If pings fail, the path goes down as expected.

If the pings succeed, but latency is abnormally high, the path stays up.

 

How can I set a latency threshold

...

getting system alerts

Hi Team,

 

frequently we were getting system alerts as " PANDB: Authentication or Client Certificate failure"  after restarted the management server we didn't get error for PANDB, but now we are getting " failed to resolve host wildfire paloaltonetwo

...

sujithGovindaraj_0-1681716245223.png

DNS Proxy

Hey,

 

i am configuring an isolated Vlan and i need some static DNS entries to be "supplied" to the clients instead exposing our internal dns servers.

i thought about using the DNS Proxy feature, but i seam to be stucked.

1) when DNS Proxy is enabled

...

DorMarcovitch_0-1681807912675.png
DorMarcovitch_1-1681808292449.png

Palo Alto Migration

Currently, we have 2 3020s in our production network but I am also tasked with setting up two new 3410s to replace the current setup. I have gone through the initial setup and committed the admin password change. I have a current config backed up, I

...

Proxy ARP for Private VLAN?

Is there a 'proxy arp' interface command (or equivalent) to allow l3 communication between isolated devices on private VLANs?

 

I am looking to move our DMZ to a private VLAN. I would like all ports to be isolated, but allow some communication betwee

...

  • 1059 Posts
  • 42 Subscriptions