Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

HA error when configuring

  • High-availability ha1 encryption requires an import of the high-availability-key(Module: ha_agent)
  • client ha_agent phase 1 failure

Any ideas why this is happening? I have configured 3 other HA pairs with no issue.

 

PA1

 

PA2

 

 

MAllen_1-1755178114085.png
MAllen_0-1755178085803.png
MAllen_2-1755178169452.png
MAllen_3-1755178206678.png
M.Allen by L1 Bithead
  • 413 Views
  • 1 replies
  • 0 Likes

Security Profile Evaluation

Hey Community!

 

In Palo Alto NGFW, when multiple Security Profiles (like Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, DLP, etc.) are applied to a Security Policy

 

How does the inspection happen?

 

  • Is it sequential (one
...

Edsnow by L3 Networker
  • 310 Views
  • 1 replies
  • 0 Likes

HA Links Over DWDM

Currently have a couple pairs of Palos (internal and external), with an HA pair over at a remote location. These 2 sites at connected via redundant DWDM devices (SmartOptics to be precise). Currently the HA links are just connected to a core switch,

...

Header Insertion doesn't work

Hi,

 

I try to enable HTTP Header Insertion to allow only my company's domain. I see the header insertion in the logs, but I got an error:

 

This account is not allowed to sign in within this network.

Please talk to  your network administrator for mo

...

K.Balas by L0 Member
  • 274 Views
  • 0 replies
  • 0 Likes

Dos Policy Value Finetune

Hello,

 

We are currently using PA-3420 appliance & we have configured DOS Policy with default values, which is as below:

 

Action

Current Value

Alarm Rate

10000

Activate Rate

10000

Max Rate

40000

Block Duration (Sec)

300

 

We have feteche

...

Failover whilst HA2 link is down?

Hi!


We have two PA440 in A/P HA. We have HA1, HA1 Backup, HA2 and HA2 Backup configured.

We are planning on eliminating HA2 Backup to gain one extra interface and we were wondering which would be the downtime if (for some very unlikely reason) our mai

...

mR00t_s5 by L2 Linker
  • 252 Views
  • 0 replies
  • 0 Likes
  • 1640 Posts
  • 53 Subscriptions