Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4789 Views
  • 0 replies
  • 1 Likes

Load Balancing in NGFW

Hello All, I am writing to request if there is a way to perform load balancing in a firewall. Case in point an organization has two traffic links for internet lets call them link A and link B. So i need social media traffic to be rerouted to link A at the firewall and general traffic to be rerouted to link B and vice versa. The firewall in place...

spyware alerts for <something>.fmb.la

this just started popping up for DNS queries inside going outbound, my PA440 is dropping the packets as a spyware threat. This is quite a new development, probably last 24 hours. Example action below: name-of-threatid eq 'generic:com.fresh.fmb.la' anyone seen this before? I can't find anything on a Google nor a LiveCommunity search. -Jeff

Device Certificate Issues.

Hi Friends, One of our customer is facing issues in fetching the device certificate on a PA-410 device running on PAN OS 11.0.4-h2. We are logging into the CLI of the firewall with Super User credentials and try to fetch the certificate with the below command &gt; request certificate fetch opt &lt; &gt;It shows us invalid syntax error. From ...

Resolved! Block access to countries outside the GlobalProtect VPN

Good morning, reviewing the GlobalProtect logs I see brute force attacks from outside my country Spain. I have tried to create security policies that prevent these attempts but none have matched. In the portal configuration (external) I have tried to put Spain as high priority and the others as None but the FW does not give me that option. I ...

ccortijo by • L2 Linker
  • 20752 Views
  • 7 replies
  • 0 Likes

Validation Error for High availability

The error message when commiting is: Validation Error: deviceconfig -&gt; high-availability -&gt; group -&gt; state-synchronization unexpected here deviceconfig -&gt; high-availability -&gt; group -&gt; state-synchronization is invalid I configured high availability using yaml ansible code. After enabling high availability, and setting up a fe...

shanjing by • L1 Bithead
  • 2881 Views
  • 1 replies
  • 0 Likes

Advertised static route on BGP over IPSEC.

Hi all, I have established BGP peer. I've created redistribution profile with interface that i want to advertised to BGP The subnet directly connected to interface could be reached/ appear in local RIB My next objectives : I have point-to-point from Palo interface 1/9 to Firepower ( my stagging room ) PTP 10.165.10.193 (PA) &amp; 10.165.10.1...

ariiero by • L1 Bithead
  • 1875 Views
  • 2 replies
  • 0 Likes

Firewall CLI showing call history

Hi, We running command show user mapping on our firewall PA5410 with PANOS 10.2.9-h1. Have anyone see this error? it always show when we running show ip user mapping all / with filter tried other command like show system info and show system disk-space it not showing any error from the CLI. Thanks, Denny

DennyChanditya_0-1721883040438.png

Resolved! Alternative Way for IPsec Tunnel in Palo Alto 850

Hello Team, As I am studying Palo Alto and am a newbie, I have created a lab setup where I use BGP peering between a PA 850 and ISPs. The PA's IP, used for BGP peering, is also used for the IPsec tunnel. I discovered a vulnerability where an ISP outage results in no IP connectivity between the IPsec local and remote IPs, causing both Phase 1 a...

Resolved! upgrade FW (PA-3420)

Hello dear team, I would like to upgrade my firewall to a stable version. Currently, my version is (11.0.4-h1). Can you please advise on the best and most stable version to upgrade to, based on your experience? Thank you.

aaljuaid by • L0 Member
  • 2509 Views
  • 2 replies
  • 0 Likes

When Pushing SDWAN config to fw got this error: pan_routed_cfg_altcfg_add_if(tunnel.902) failed

I am trying to do a SDWAN push for a newly imported fw. The interfaces is not existing on fw.It comes from another PN also configured with SDWAN, moved to new one and all except SDWAN config copied and working. Then added fw into SDWAN device and existing cluster (with 15'ish fws already). Commit to PN (other) is ok. when push to fw we got the e...

  • 1633 Posts
  • 62 Subscriptions
Top Solution Authors