Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ?

Hi all,

 

Can I check with you the following Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ?

If yes, May I know which released signature version and threat id is covered f

...

http-req-user-agent-header

Hello,

 

SSO is requesting to me to add a rule on policy to alert http request without user-agent (empty) on header.

i know I can use vulnerability by adding a condition when « http-req-user-agent-header » is equal to a regex. 
i tried to use the rege

...

Using XFF for Logs Only

Hello,

 

I have an application behind a WAF, without XFF the source IPs are always my WAF and for auditing reasons I need to get and log the real client IP addresses.

 

Traffic flow is like this:

 

Client -> WAN -> NAT -> DMZ - App Server

My security

...

Tenant ID change on NGFW

Hi all,

We have a set of NGFWs that somehow are pointed to an old tenant ID and therefor not dropping the logs into the CDL. We have put in a TAC case but haven't gotten any resolution as of yet. 

 

Is there a way in the CLI to change the tenant ID?

...

2 PA-850s and 1 PA-440

Hi,

I received a quote from a supplier for 2 PA-850s with Wildfire , Partner enabled premium support and GlobalProtect subscription.
Then for the PA - 440 - Wildfire , GlobalProtect , advanced Url filtering , advanced threat protection and premium supp

...

Calc66 by L1 Bithead
  • 2391 Views
  • 5 replies
  • 0 Likes
  • 1199 Posts
  • 45 Subscriptions
Top Solution Authors