Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4558 Views
  • 0 replies
  • 1 Likes

Resolved! Add Cold DR to a existing environment

Hello, I have a Panorama that manages several clusters with a dedicated device-group and template For one of them my customer bought a single firewall as a Cold DR to put in a different DC. Considering the following scenario:- Cluster-Intranet (active/standby) with member (Intranet01 and Intranet02) - new DR name will be IntranetDR Before the a...

Resolved! PAN-PA-445

Hello all, Could you please give me correct ECCN for firewall PA-445 or some look up tool list with all products where could I find ECCN? Thank you. Best regards,

smacura by L1 Bithead
  • 2264 Views
  • 3 replies
  • 0 Likes

Resolved! Multi Virtual System Capability option is missing

Hey community, I'm setting up a new PA-450 FW, which we will use in the future with Multi Virtual Systems Capability. So I wanted to enable it ahead to eliminate problems in the future, but it seems like I'm missing the option to enable it ( Device> Setup> management> edit General Settings). I attached a screenshot for reference. In t...

EDL and FQDN ID Tools

Community, I wanted to provide an announcement of a couple of open source tools that I have written and published for External Dynamic Lists (EDL) manager as well as a method for identifying domains in use for SaaS applications that can be used independently or in conjunction with each other. The primary project name for the EDL manager is K...

HA1 Interfaces PA-1410 + interfaces dell

Hi PA-1410 comes with it's own rj45 ports for HA1-A and HA1-B. For HA2 it has a dedicated port that needs a SFP. My question is the following: Can we add 1 Gbps SFP fiber modules to the firewall and configure them as HA1/HA2 or is it mandatory to use the dedicated one's with rj45? Besides this I wanted to check with you if Dell Twinax 10 Gbps ca...

Threat detections of "Canonical ksmbd-tools ksmbd.mountd ndrwritebytes Heap Buffer Overflow Vulnerability(94951)" in Windows server traffic

Anyone else seeing the following alerts:tcp,alert,"gpt.ini",Canonical ksmbd-tools ksmbd.mountd ndrwritebytes Heap Buffer Overflow Vulnerability(94951) But this is being detected in traffic between 2 Windows server, so it doesn't make sense. Seems to be a false positive.

Megawatt by L1 Bithead
  • 4700 Views
  • 5 replies
  • 0 Likes

Resolved! Connection to Panorama for new deployment failing

Hi, I have the following issue I am running panorama 10.2.7h3 my new device P440 is also running 10.2.7h3. When I want to onboard the device into panorama it is not working. I am onboarding the device with Authenticatio keys. Following the below procedure. Add a Firewall as a Managed Device (paloaltonetworks.com) I have also reset the secure c...

zGomez_0-1707923254038.png
zGomez by L3 Networker
  • 7725 Views
  • 4 replies
  • 0 Likes

PA-850 Static NAT between 2 Switches

Hello all. Looking for help here. I am trying to create a static NAT between two switches using a vwire, but it doesn't seem to be working. Can someone please provide steps on how to make this happen? I do not wish to insert routers between the switches, and wasn't sure if this was possible. I'm new to networking and firewalls, and have bee...

zbSA24 by L1 Bithead
  • 2848 Views
  • 7 replies
  • 0 Likes

SMB share - Right clicking shared folder and selecting folder properties

Hi all, We have observed an issue with an SMB share which traverses our PA FW. The initial rule was setup simply such that the client was allowed to access the remote SMB share in the firewall rule base by use of the inbuilt ms-ds-smb application container. Client was able to browse to the folder fine and upload/download files fine with no...

dmellors by L0 Member
  • 3620 Views
  • 2 replies
  • 0 Likes

Monitoring Subinterfaces with zabbix

I would like to ask if you have experience with integrating Zabbix and Palo Alto FW. I have an issue with graphs traffic on subinterfaces as it is not accurate compared to the port connected on the other end. For example, on the switch port, I see 20Mbps traffic in, but on the Palo Alto interface connected to that same switch, I see 1.2Mbps traf...

inglpa by L0 Member
  • 1605 Views
  • 0 replies
  • 0 Likes

USER_ID mapping constantly changing with Zscaler App

Hi Team, We are facing an issue where PA user authenticated access from ZScaler app connect servers is failing intermittently. Access through PA FW to a server network using user authentication is failing intermittently when connections are made from a pair of ZScaler app connector servers. CLI command "show user ip-user-mapping ip-address-o...

PaloAlto to Watchguard Site to Site connects but passes no traffic to parts of the Watchguard site.

Looking to see if anyone has come across this issue. We have setup a site-to-site tunnel to another location. We have a PA460 running 10.7.h3 and the other location uses a watchguard firewall with NetMotion for their Vpn clients. When we connected, the clients running NetMotion can't reach applications or the local network can't, this depends on...

how to monitor encryption domains in VPN Palo Alto

Best regard Equipment We are currently experiencing an issue with one of our VPNS that we have configured against Azure on a 5200 series FW The problem that arises is that of 10 configured domains, 5 are going down for no reason, since the traffic to these encryption domains is constant and this has generated different types of incidents. Do you...

aalfaro by L2 Linker
  • 2438 Views
  • 1 replies
  • 0 Likes
  • 1589 Posts
  • 60 Subscriptions