Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4680 Views
  • 0 replies
  • 1 Likes

BGP Route Advertisement /Export Rule

Need some help with advertising specific routes over BGP and hoping someone can help. I have a site-to-site tunnel setup between AWS and my on-premise PA Firewall. I am receiving routes from AWS over BGP as expected. No issue there and I am able to create a redistribution profile & redist rule and advertise an existing static route listed ...

Cobraflo by L1 Bithead
  • 11162 Views
  • 5 replies
  • 0 Likes

QOS issue error

any idea on below error. Enviorment:-OS - 10 2 8 h2Model - 5220 2024-07-29 19:25:19.349 +0800 Error: gryphon_qos_perform_set(5200/gryphon_sysd.c:389): Set shaper on port 42 index 0 failed with ret -4

Load Balancing in NGFW

Hello All, I am writing to request if there is a way to perform load balancing in a firewall. Case in point an organization has two traffic links for internet lets call them link A and link B. So i need social media traffic to be rerouted to link A at the firewall and general traffic to be rerouted to link B and vice versa. The firewall in place...

spyware alerts for <something>.fmb.la

this just started popping up for DNS queries inside going outbound, my PA440 is dropping the packets as a spyware threat. This is quite a new development, probably last 24 hours. Example action below: name-of-threatid eq 'generic:com.fresh.fmb.la' anyone seen this before? I can't find anything on a Google nor a LiveCommunity search. -Jeff

Device Certificate Issues.

Hi Friends, One of our customer is facing issues in fetching the device certificate on a PA-410 device running on PAN OS 11.0.4-h2. We are logging into the CLI of the firewall with Super User credentials and try to fetch the certificate with the below command &gt; request certificate fetch opt &lt; &gt;It shows us invalid syntax error. From ...

Resolved! Block access to countries outside the GlobalProtect VPN

Good morning, reviewing the GlobalProtect logs I see brute force attacks from outside my country Spain. I have tried to create security policies that prevent these attempts but none have matched. In the portal configuration (external) I have tried to put Spain as high priority and the others as None but the FW does not give me that option. I ...

ccortijo by L2 Linker
  • 20009 Views
  • 7 replies
  • 0 Likes

Validation Error for High availability

The error message when commiting is: Validation Error: deviceconfig -&gt; high-availability -&gt; group -&gt; state-synchronization unexpected here deviceconfig -&gt; high-availability -&gt; group -&gt; state-synchronization is invalid I configured high availability using yaml ansible code. After enabling high availability, and setting up a fe...

shanjing by L1 Bithead
  • 2710 Views
  • 1 replies
  • 0 Likes

Advertised static route on BGP over IPSEC.

Hi all, I have established BGP peer. I've created redistribution profile with interface that i want to advertised to BGP The subnet directly connected to interface could be reached/ appear in local RIB My next objectives : I have point-to-point from Palo interface 1/9 to Firepower ( my stagging room ) PTP 10.165.10.193 (PA) &amp; 10.165.10.1...

ariiero by L1 Bithead
  • 1780 Views
  • 2 replies
  • 0 Likes

Firewall CLI showing call history

Hi, We running command show user mapping on our firewall PA5410 with PANOS 10.2.9-h1. Have anyone see this error? it always show when we running show ip user mapping all / with filter tried other command like show system info and show system disk-space it not showing any error from the CLI. Thanks, Denny

DennyChanditya_0-1721883040438.png

Resolved! Alternative Way for IPsec Tunnel in Palo Alto 850

Hello Team, As I am studying Palo Alto and am a newbie, I have created a lab setup where I use BGP peering between a PA 850 and ISPs. The PA's IP, used for BGP peering, is also used for the IPsec tunnel. I discovered a vulnerability where an ISP outage results in no IP connectivity between the IPsec local and remote IPs, causing both Phase 1 a...

Resolved! upgrade FW (PA-3420)

Hello dear team, I would like to upgrade my firewall to a stable version. Currently, my version is (11.0.4-h1). Can you please advise on the best and most stable version to upgrade to, based on your experience? Thank you.

aaljuaid by L0 Member
  • 2366 Views
  • 2 replies
  • 0 Likes
  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors