Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4560 Views
  • 0 replies
  • 1 Likes

PA-450 is not booting

Hi everyone, We are currently configuring a new Palo Alto PA-450 and the device is no longer accessible by web management and over console. At the first power on booting has been done normally and all led was blinking fine. We started access the WebUI and the device reboot automatically. Now it's not booting and the led status is amber in PWR,...

OOlivier by L0 Member
  • 2674 Views
  • 1 replies
  • 1 Likes

Validation Error for High availability

The error message when commiting is: Validation Error: deviceconfig -> high-availability -> group -> state-synchronization unexpected here deviceconfig -> high-availability -> group -> state-synchronization is invalid I configured high availability using yaml ansible code. After enabling high availability, and setting up a fe...

shanjing by L1 Bithead
  • 2561 Views
  • 1 replies
  • 0 Likes

Advertised static route on BGP over IPSEC.

Hi all, I have established BGP peer. I've created redistribution profile with interface that i want to advertised to BGP The subnet directly connected to interface could be reached/ appear in local RIB My next objectives : I have point-to-point from Palo interface 1/9 to Firepower ( my stagging room ) PTP 10.165.10.193 (PA) & 10.165.10.1...

ariiero by L1 Bithead
  • 1646 Views
  • 2 replies
  • 0 Likes

Firewall CLI showing call history

Hi, We running command show user mapping on our firewall PA5410 with PANOS 10.2.9-h1. Have anyone see this error? it always show when we running show ip user mapping all / with filter tried other command like show system info and show system disk-space it not showing any error from the CLI. Thanks, Denny

DennyChanditya_0-1721883040438.png

Resolved! Alternative Way for IPsec Tunnel in Palo Alto 850

Hello Team, As I am studying Palo Alto and am a newbie, I have created a lab setup where I use BGP peering between a PA 850 and ISPs. The PA's IP, used for BGP peering, is also used for the IPsec tunnel. I discovered a vulnerability where an ISP outage results in no IP connectivity between the IPsec local and remote IPs, causing both Phase 1 a...

Resolved! upgrade FW (PA-3420)

Hello dear team, I would like to upgrade my firewall to a stable version. Currently, my version is (11.0.4-h1). Can you please advise on the best and most stable version to upgrade to, based on your experience? Thank you.

aaljuaid by L0 Member
  • 2187 Views
  • 2 replies
  • 0 Likes

When Pushing SDWAN config to fw got this error: pan_routed_cfg_altcfg_add_if(tunnel.902) failed

I am trying to do a SDWAN push for a newly imported fw. The interfaces is not existing on fw.It comes from another PN also configured with SDWAN, moved to new one and all except SDWAN config copied and working. Then added fw into SDWAN device and existing cluster (with 15'ish fws already). Commit to PN (other) is ok. when push to fw we got the e...

Amber LED on PA3220

Hi All, I am getting amber LED on the firewall PA3220. Observed alarm is active for Temperatur : Qumran Switch Core. Can anyone know what is causing this issue and how to resolve. all other alarms are False only this alarm is true. show system environmentals ---> ----Thermal---- Slot Description Alarm Degrees...

Decryption failed

Hi guys , PA820 . OS Version 10.2.9-h1 I am try using the decryption function to see more application informationI generated the CA certificate from PA and imported it locally. From the decryption log, I saw many errors with various URLs.Can anyone help explain how to eliminate this? error eq 'Received fatal alert CertificateUnknown from cl...

HY_Cheng by L1 Bithead
  • 3362 Views
  • 5 replies
  • 0 Likes

Panorama DLP Log error

Hello, I am testing it internally with a DLP PoC request from a customer. It was difficult because the conditions were not good, but I was able to activate DLP and check the log in Panorama. However, when I try to check the DLP report in Data Log, the following error occurs. Why does the error log below occur? - error log : No report ID availa...

sseo333111_0-1721728620228.png

[#20240701-0110] - anti-virus and threat detection within websocket connections

Hi, I just came across an interesting question regarding websocket connections running through an NGFW. How does virus inspection and threat detection work here? From what I know websocket connections aren't compatible with normal HTTP connections (ignoring wss for the moment which might be a different problem). So is an NGFW still able to sca...

TRisec by L1 Bithead
  • 4941 Views
  • 2 replies
  • 0 Likes
  • 1589 Posts
  • 60 Subscriptions