Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4784 Views
  • 0 replies
  • 1 Likes

Resolved! Management Interface and In Band Network Overlap

Hello, I have the management interface of some PAs in the 10.10.10.0/24 management network. This is the a corporate management network for network devices etc. I also want to inspect traffic on this network and have assigned a interface/security zone with the default gateway for the management network on the PAs. I am having trouble getting the ...

NSutfin_0-1699885772086.png
NSutfin by • L2 Linker
  • 3324 Views
  • 2 replies
  • 0 Likes

Massive alets from PAN NGFW Source

Hello community, I need your help, At my last 30 days im getting alot of alerts to my XSIEM from PAN NGFW source about Prevented action from bad URLthe category is (Spyware Detected via Anti-Spyware profile) After block Url's and Domain and added them to Black List, i still get the same Url and domain trigger agine. Someone have idea what to do?

Y.Zalsov by • L1 Bithead
  • 1435 Views
  • 2 replies
  • 0 Likes

NFS 4.0 vs 4.1

Looking for guidance around configuring a firewall for NFS 4.1 traffic. NFS traffic using NFS 4.0 works fine but when switching over to NFS 4.1 there is a huge amount of latency. To my understanding NFS 4.1 uses parallel nfs which is structured differently than previous nfs. Instead of the NFS Filer head (Server) being the gateway between the st...

Making PA-820 quieter??

Hi, I have an opportunity to grab one of company's Palo Alto PA-820 firewalls for free. It would be shame to dispose of perfectly operational hardware just because topology has changed and we have no use for it anymore. But - had one at home when I was learning PAN-OS and found it to be quite loud, and because my home lab setup in in living ...

R.Tryba by • L1 Bithead
  • 1625 Views
  • 2 replies
  • 0 Likes

Migrating to multi-vsys environment

We recently decided to migrate to a multi-vsys environment for two of our data centers. The main reason for this is the shared gateway feature. We are starting to do a lot of disaster recovery planning, and need a segmented environment (with overlapping IPs), that can also share the internet connectivity. We were just using virtual routers to...

buck1 by • L1 Bithead
  • 1768 Views
  • 1 replies
  • 0 Likes

Standby firewall restarting on 11.0.4-h1

Upgraded my 5250 firewall pair last week to 11.0.4-h1 for CVE-2024-3400. Since then, have seen my secondary/standby firewall reboot twice over the course of a week after a error of "HA Group 52: Dataplane is down: too many children exited". This never happened prior to this release. I am currently working with support, just waiting on a resp...

Smithm by • L1 Bithead
  • 5240 Views
  • 6 replies
  • 1 Likes

Issue Nat Outbond Palo Alto

i got an issue, while sometimes my fortimail is unable connect to internet, and for my fortimail to able connect to internet again i disable and enable my nat policy, is there any bug related to that because i got this every day here is my nat policy

niam77_0-1720093967736.png
f.niam by • L1 Bithead
  • 3153 Views
  • 5 replies
  • 0 Likes

Resolved! Block PDF sites

Hello there, I need to every pdf converter sites. Examples like pdf.io, tools.pdf24.org, lightpdf.com. I need to block that site url that contains "pdf" How to configure it ? Any help please ?

Tuguldur by • L1 Bithead
  • 4396 Views
  • 4 replies
  • 0 Likes
  • 1633 Posts
  • 62 Subscriptions
Top Solution Authors