Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4507 Views
  • 0 replies
  • 1 Likes

NFS 4.0 vs 4.1

Looking for guidance around configuring a firewall for NFS 4.1 traffic. NFS traffic using NFS 4.0 works fine but when switching over to NFS 4.1 there is a huge amount of latency. To my understanding NFS 4.1 uses parallel nfs which is structured differently than previous nfs. Instead of the NFS Filer head (Server) being the gateway between the st...

Making PA-820 quieter??

Hi, I have an opportunity to grab one of company's Palo Alto PA-820 firewalls for free. It would be shame to dispose of perfectly operational hardware just because topology has changed and we have no use for it anymore. But - had one at home when I was learning PAN-OS and found it to be quite loud, and because my home lab setup in in living ...

R.Tryba by L1 Bithead
  • 1447 Views
  • 2 replies
  • 0 Likes

Migrating to multi-vsys environment

We recently decided to migrate to a multi-vsys environment for two of our data centers. The main reason for this is the shared gateway feature. We are starting to do a lot of disaster recovery planning, and need a segmented environment (with overlapping IPs), that can also share the internet connectivity. We were just using virtual routers to...

buck1 by L1 Bithead
  • 1539 Views
  • 1 replies
  • 0 Likes

Standby firewall restarting on 11.0.4-h1

Upgraded my 5250 firewall pair last week to 11.0.4-h1 for CVE-2024-3400. Since then, have seen my secondary/standby firewall reboot twice over the course of a week after a error of "HA Group 52: Dataplane is down: too many children exited". This never happened prior to this release. I am currently working with support, just waiting on a resp...

Smithm by L1 Bithead
  • 4633 Views
  • 6 replies
  • 1 Likes

Issue Nat Outbond Palo Alto

i got an issue, while sometimes my fortimail is unable connect to internet, and for my fortimail to able connect to internet again i disable and enable my nat policy, is there any bug related to that because i got this every day here is my nat policy

niam77_0-1720093967736.png
f.niam by L1 Bithead
  • 2710 Views
  • 5 replies
  • 0 Likes

Resolved! Block PDF sites

Hello there, I need to every pdf converter sites. Examples like pdf.io, tools.pdf24.org, lightpdf.com. I need to block that site url that contains "pdf" How to configure it ? Any help please ?

Tuguldur by L1 Bithead
  • 3981 Views
  • 4 replies
  • 0 Likes

Resolved! Software update library is stripped, missing a lot of OS versions?

I had a very strange issue this morning regarding VPN configuration, and it's obviously a GUI bug. I checked for Software updates for my Panorama and the library came up with a very small list. It doesn't even include 11.1.3 or 11.1.3-h1 which is what the appliance is running. I went out to the Software Updates section of the customer support ...

Active/Passive connection with Cisco Stack switches

Hello I would like to have confirmation. I need to connect my Palo Alto cluster firewall (active/passive) to a Cisco stack (with 2 members). If I want a fully redundancy, I need to create, on a each firewall, an aggregate with 2 interfaces and each interface is connected on a port on each Cisco member ? Are you agree with my schema bellow ? ...

JeromeC_0-1661760904358.png
JeromeC by L1 Bithead
  • 6135 Views
  • 5 replies
  • 0 Likes
  • 1794 Posts
  • 60 Subscriptions
Top Solution Authors