Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4679 Views
  • 0 replies
  • 1 Likes

When Pushing SDWAN config to fw got this error: pan_routed_cfg_altcfg_add_if(tunnel.902) failed

I am trying to do a SDWAN push for a newly imported fw. The interfaces is not existing on fw.It comes from another PN also configured with SDWAN, moved to new one and all except SDWAN config copied and working. Then added fw into SDWAN device and existing cluster (with 15'ish fws already). Commit to PN (other) is ok. when push to fw we got the e...

Amber LED on PA3220

Hi All, I am getting amber LED on the firewall PA3220. Observed alarm is active for Temperatur : Qumran Switch Core. Can anyone know what is causing this issue and how to resolve. all other alarms are False only this alarm is true. show system environmentals ---> ----Thermal---- Slot Description Alarm Degrees...

Decryption failed

Hi guys , PA820 . OS Version 10.2.9-h1 I am try using the decryption function to see more application informationI generated the CA certificate from PA and imported it locally. From the decryption log, I saw many errors with various URLs.Can anyone help explain how to eliminate this? error eq 'Received fatal alert CertificateUnknown from cl...

HY_Cheng by L1 Bithead
  • 3560 Views
  • 5 replies
  • 0 Likes

Panorama DLP Log error

Hello, I am testing it internally with a DLP PoC request from a customer. It was difficult because the conditions were not good, but I was able to activate DLP and check the log in Panorama. However, when I try to check the DLP report in Data Log, the following error occurs. Why does the error log below occur? - error log : No report ID availa...

sseo333111_0-1721728620228.png

[#20240701-0110] - anti-virus and threat detection within websocket connections

Hi, I just came across an interesting question regarding websocket connections running through an NGFW. How does virus inspection and threat detection work here? From what I know websocket connections aren't compatible with normal HTTP connections (ignoring wss for the moment which might be a different problem). So is an NGFW still able to sca...

TRisec by L1 Bithead
  • 5329 Views
  • 2 replies
  • 0 Likes

"Let's Encrypt" and geoblocking issues

Hi, we have a couple 3rd-party applications that use Let's Encrypt for certificate automation. We also use geoblocking rules on our Palo Alto firewall because we are local government, so we block non-US based traffic. I recently learned that Let's Encrypt requires global access due to its nature of validation, because our certificates are failin...

Maxstr by L1 Bithead
  • 3466 Views
  • 2 replies
  • 0 Likes

Plugins are not supported on this platform

Configuring a pair of PA-3410 and a couple of PA-415 firewalls. I've just noticed that I can't install the OpenConfig plugin on the P-415 firewalls. Refreshing the plugins yields this message: "Plugins are not supported on this platform". Until now I wasn't aware of this limitation and can't find anything about this in any documentation. Does an...

dmgeurts by L2 Linker
  • 2136 Views
  • 0 replies
  • 3 Likes

traffic log did not display user information

The customer uses GP to dial in and adopts LDAP authentication method.After the customer dialed in normally, they accessed internal resources, but the source user colums in the traffic log did not display user information, which was normal before. The customer did not make any other changes, and the user id in the area was also checked.How to in...

traffic log.png
user-information.png
Felixcao by L3 Networker
  • 1794 Views
  • 3 replies
  • 0 Likes

Resolved! PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an 'ms-update' application flow

I need to understand exactly makes a TCP flow identified as the 'ms-update' application. I found the Objects -> Applications -> ms-update app description. It shows the ports used, and other dependencies. But this does not explain exactly what makes one flow identified as the 'ms-update' application. And a second flow identified as some ot...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors