Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4680 Views
  • 0 replies
  • 1 Likes

IPsec Tunnel Down!

Hi Team, I'm a newbie at the Palo Alto firewall, and I've been checking the IPsec connection between PA850 at my sites. I'm encountering issues with the IPsec tunnel, which is not coming up. I tried establishing IPsec using the IP used for BGP peering, and it established without any problems. However, the problem arises when I us...

Decryption: Received fatal alert CertificateUnknown from client

Hi Folks, I'm seeing some instances of "Received fatal alert CertificateUnknown from client" errors in the decryption log when the root\issuer certs are clearly in the FW's cert store. Attached are screenshots of the error and the FW's cert store. Any ideas on what could be going wrong here? I'm seeing this on PAN OS 11.0.2-h3 & 10.2.7-h3...

Resolved! X-Forwarded-For displays wrong ip (v6) in logs

Hi. We have a azure setup, web application, where an agw first terminates traffic and applies xff and then forwards to firewalls which then decrypt the session. We have X-Forwarded-For enabled and usually works fine and displays the correct ipv4 address in logs. From time to time though logs instead display ipv6 addresses which we dont use and...

Firewallcrash because of Application cloud Engine (ACE)

Hi community Since about 2 weeks a vm firewall started getting problems with random crashes. Our setup is a firewallcluster but so far the active firewall crashes almost completely silent. At least the firewall does not initiate a failover to the passive node. So far we had about 4 crashes at random times and in one case the firewall crashed "...

Remo by L7 Applicator
  • 1071 Views
  • 0 replies
  • 1 Likes

Resolved! Not able to ping ISP B interface -10.2.9-h1

Hi team, We are facing an issue where we are not able to ping the secondary ISP's external interface when the default route is set for the primary ISP to take preference.We have two ISPs: ISP A and ISP B. The metric is set to prefer the ISP A route. When we try and ping the external interface of ISP B, we can see a weird behavior where when tr...

Migrating configuration from the firewall running PAN-OS 9.1 to new firewall running PAN-OS 11.1 directly

Hi LIVEcommunity I plan to migrate the configuration from a PA-3020 firewall currently running PAN-OS 9.1 to a new PA-1410 firewall running PAN-OS 11.1. I'd like to know if it's possible to directly import the configuration from the older firewall to the newer one, despite the difference in PAN-OS versions. If direct import isn't recommend...

Zscaler Traffic Pattern

My company users are using ZCC on their laptops. Recently, there has been an issue where Zscaler traffic is being denied by the Palo Alto Firewall.Upon checking the logs, it appears that the ZCC traffic pattern changed into web browsing and HTTP Proxy, which is being denied by the firewall. We have configured the firewall to allow Zscaler Privat...

madu2609 by L0 Member
  • 3828 Views
  • 1 replies
  • 0 Likes

Unable to Block Personal Gmail on Ubuntu Machines.

Hi Friends, We have a customer who is facing issues in blocking Personal Gmail on Ubuntu Machines. I have followed the below mentioned discussion and created the URL filtering and Policies. https://live.paloaltonetworks.com/t5/general-topics/block-access-to-private-gmail-but-allow-corporate/td-p/195686 Personal Gmail is blocking as expected ...

Satyak by L3 Networker
  • 1031 Views
  • 1 replies
  • 0 Likes

FW Policy Skipped When Either App-Based only or SMTP-BASE app and 587 Port is Defined

Firewall is skipping policy when the traffic has smtp-base port 587 on it. I created a firewall policy application based with smtp-base as application but it skips the policy goes to the implicit interzone deny policy. So I created it with by just port based, 587, it sill skips the policy and goes to interzone default deny. So I explicitly defin...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors