Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4552 Views
  • 0 replies
  • 1 Likes

Migrating configuration from the firewall running PAN-OS 9.1 to new firewall running PAN-OS 11.1 directly

Hi LIVEcommunity I plan to migrate the configuration from a PA-3020 firewall currently running PAN-OS 9.1 to a new PA-1410 firewall running PAN-OS 11.1. I'd like to know if it's possible to directly import the configuration from the older firewall to the newer one, despite the difference in PAN-OS versions. If direct import isn't recommend...

Zscaler Traffic Pattern

My company users are using ZCC on their laptops. Recently, there has been an issue where Zscaler traffic is being denied by the Palo Alto Firewall.Upon checking the logs, it appears that the ZCC traffic pattern changed into web browsing and HTTP Proxy, which is being denied by the firewall. We have configured the firewall to allow Zscaler Privat...

madu2609 by L0 Member
  • 3471 Views
  • 1 replies
  • 0 Likes

Unable to Block Personal Gmail on Ubuntu Machines.

Hi Friends, We have a customer who is facing issues in blocking Personal Gmail on Ubuntu Machines. I have followed the below mentioned discussion and created the URL filtering and Policies. https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/td-p/195686 Personal Gmail is blocking as expected ...

Satyak by L3 Networker
  • 976 Views
  • 1 replies
  • 0 Likes

FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined

Firewall is skipping policy when the traffic has smtp-base port 587 on it. I created a firewall policy application based with smtp-base as application but it skips the policy goes to the implicit interzone deny policy. So I created it with by just port based, 587, it sill skips the policy and goes to interzone default deny. So I explicitly defin...

Resolved! Alert ID 95501 Microsoft Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Hello, After installing the last content update (https://proditpdownloads.paloaltonetworks.com/content/content-8880-8907.html?__token__=exp=1724141521~acl=/content/content-8880-8907.html*~hmac=1db8a0453380feaed30e6acb96df65d1a9c07f4e7ebe53abb34ad3cffda87f9d) I have a lot of traffic blocked from my servers to the licence microsoft server. But the...

Resolved! Suspect false positive matching for threat ID 95501 (Remote Desktop Licensing RCE)

Hello! Not yet sure if this is a false positive or not, but since latest content update one of our customers is having issue with the new signature 95501 related to CVE-2024-38077. It looks like it's blocking legitimate traffic between RDS server and licensing server. Wonder if anybody is having the same issue. Thanks!

emyl_79 by L2 Linker
  • 2115 Views
  • 2 replies
  • 0 Likes

Migrate OpenBDS firewall to Palo Alto

What would be the best approach for migrating the OpenBDS firewall? In a scenario where there are 4 units of OpenBDS and consolidating into 2 units of Palo Alto. Would the Expedition tool able to merge the policies? Any other things to note for the migration? Please advise.

Packet51 by L0 Member
  • 973 Views
  • 1 replies
  • 0 Likes

Looking for someone familiar with Palo Alto Firewalls

Hello all, I'm with a company that has just been offered a project to review a certain university's firewalls but we can't take it on as none of us are familiar with Palo Alto systems. However it would be nice to be able to take on projects like this to expand our scope of services. I thought I would come on the community site in hopes of luck...

Global Protect Integration with Azure SAML w/ Multiple Gateways

I'm trying to setup an integration with 2 firewalls at different locations. The portal and 1 gateway reside on 1 of the firewalls, and i've used this: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE to get that going successfully. The 2nd firewall, which has a certificate w/ a different FQDN, doesn't allow...

DJ_1924 by L2 Linker
  • 3794 Views
  • 3 replies
  • 0 Likes

ospf neighbour adjacency is flapping continuously

Hi Team, Reaching out for help to identify the main cause of this problem. I can see that the OSPF adjacency is flapping continuously and I have no clue how to move further and how to identify the cause. While collecting the routed.log, I can see below: **** AUDIT 0x0309 - 57 (0001) **** I:0087de60 F:00000002i3emuif2.c 484 :at 15:13:10, ...

Palo Alto and Microsoft NLB multicast

Hi I have an issue to contact the VIP of our Microsoft NLB. We have a cluster of 2 PA-1410 (active/passive). On this cluster, I configured interface aggregate with sub-interfaces with ID vlan (ex :vlan10, vlan 50, vlan193..). Each IP of the interface VLAN is the gateway configured on my servers. On the VLAN193, I have 2 Windows servers with ...

Resolved! Open-Source External Syslog Server

Hi all, So we just found out that PA-1410 only has a limited storage log capacity of 18GB. Thus, our traffic logs can only last a day, as the firewall already deletes the oldest logs due to limited log storage space. This poses a problem because we have to generate log reports on a monthly basis. We are trying to configure a Log Forwarding i...

zedexxx by L1 Bithead
  • 5729 Views
  • 2 replies
  • 0 Likes

Checkpoint Firewall migration to Palo Alto firewall using Expedition Tool

Hi Team, We want to migrate the Checkpoint firewall with Palo Alto NextGen Firewall using Expedition Tool. I've gone through couple of forums also few of them listed on this community as well but I don't get more appropriate way to do this migration. Can someone please provide a documentation or way to do this migration that works just perfect...

  • 1588 Posts
  • 60 Subscriptions