Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4507 Views
  • 0 replies
  • 1 Likes

Panorama DLP Log error

Hello, I am testing it internally with a DLP PoC request from a customer. It was difficult because the conditions were not good, but I was able to activate DLP and check the log in Panorama. However, when I try to check the DLP report in Data Log, the following error occurs. Why does the error log below occur? - error log : No report ID availa...

sseo333111_0-1721728620228.png

[#20240701-0110] - anti-virus and threat detection within websocket connections

Hi, I just came across an interesting question regarding websocket connections running through an NGFW. How does virus inspection and threat detection work here? From what I know websocket connections aren't compatible with normal HTTP connections (ignoring wss for the moment which might be a different problem). So is an NGFW still able to sca...

TRisec by L1 Bithead
  • 4677 Views
  • 2 replies
  • 0 Likes

"Let's Encrypt" and geoblocking issues

Hi, we have a couple 3rd-party applications that use Let's Encrypt for certificate automation. We also use geoblocking rules on our Palo Alto firewall because we are local government, so we block non-US based traffic. I recently learned that Let's Encrypt requires global access due to its nature of validation, because our certificates are failin...

Maxstr by L1 Bithead
  • 2976 Views
  • 2 replies
  • 0 Likes

Plugins are not supported on this platform

Configuring a pair of PA-3410 and a couple of PA-415 firewalls. I've just noticed that I can't install the OpenConfig plugin on the P-415 firewalls. Refreshing the plugins yields this message: "Plugins are not supported on this platform". Until now I wasn't aware of this limitation and can't find anything about this in any documentation. Does an...

dmgeurts by L2 Linker
  • 1967 Views
  • 0 replies
  • 2 Likes

traffic log did not display user information

The customer uses GP to dial in and adopts LDAP authentication method.After the customer dialed in normally, they accessed internal resources, but the source user colums in the traffic log did not display user information, which was normal before. The customer did not make any other changes, and the user id in the area was also checked.How to in...

traffic log.png
user-information.png
Felixcao by L3 Networker
  • 1660 Views
  • 3 replies
  • 0 Likes

Resolved! PanOS 10.1.14-h2 - How does Palo identify if traffic belongs to an 'ms-update' application flow

I need to understand exactly makes a TCP flow identified as the 'ms-update' application. I found the Objects -> Applications -> ms-update app description. It shows the ports used, and other dependencies. But this does not explain exactly what makes one flow identified as the 'ms-update' application. And a second flow identified as some ot...

Trial Software Esxi Download

Hello All, I am trying to get PA trial images for ESXI delpoyment, on supportal am not able to software update option to download the image. Can you please guide me how to prceed further or download the PA images for trial period. With Regards WATSQ

uniquewaheed_0-1721038413735.png

License registration

Hello , We have a customer . they had 1 PAlo NG FW and it is registered in their support account . Now customer had purchased 5 Palo clusters and Panorama through us ( Integrator) with 5 year Premium Partner support and we have our own ASC support account . Can we customer devices in our ASC account ? I know that devices should be only r...

Resolved! Management Interface and In Band Network Overlap

Hello, I have the management interface of some PAs in the 10.10.10.0/24 management network. This is the a corporate management network for network devices etc. I also want to inspect traffic on this network and have assigned a interface/security zone with the default gateway for the management network on the PAs. I am having trouble getting the ...

NSutfin_0-1699885772086.png
NSutfin by L2 Linker
  • 2977 Views
  • 2 replies
  • 0 Likes

Massive alets from PAN NGFW Source

Hello community, I need your help, At my last 30 days im getting alot of alerts to my XSIEM from PAN NGFW source about Prevented action from bad URLthe category is (Spyware Detected via Anti-Spyware profile) After block Url's and Domain and added them to Black List, i still get the same Url and domain trigger agine. Someone have idea what to do?

Y.Zalsov by L1 Bithead
  • 1264 Views
  • 2 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions
Top Solution Authors