Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Resolved! DNS-Sinkhole Injection

The DNS sinkhole option works perfectly well with a Microsoft DNS environment. Unfortunately, it fails if you try to perform DNS-sinkhole injection in front of a BIND DNS server running on Red Hat Linux. Requests to malicious domains simply time out:

...

HeinzP by L1 Bithead
  • 1088 Views
  • 3 replies
  • 0 Likes

Outbound SSL Decryption Quirk

Hello,

 

I have established an outbound SSL decrypt policy that I have enabled for only myself as I test functionality. Over the past few months, I've noticed a quirk that I'm unsure of the reasoning behind. With the policy enabled, sometimes connect

...

RH747 by L2 Linker
  • 987 Views
  • 2 replies
  • 0 Likes

Azure "az" command and decryption

Hello, All.

 

Working on Windows. A few days ago, tried to understand why the Microsoft Azure CLI "az" command line program was not working with decryption behind our PAN OS 10.2.10.

  • Azure CLI is a python tool. I am currently running v2.77 (latest)
  • I
...

Rievax by L2 Linker
  • 2003 Views
  • 3 replies
  • 0 Likes

LSVPN Portal connection Failed

Hi

 

We have around 500 sites and most of them are connected via LSVPN and a Site-2-Site VPN for backup.  At somepoint the username for the portal connection has been changed which means all off the sites that are connected via LSVPN report that they

...

R.Moth by L0 Member
  • 430 Views
  • 1 replies
  • 0 Likes

Resolved! Public Website IPs that is not a part of the address object group specified in destination is being blocked by Deny security policy

Hi Team,

I’m experiencing an unusual issue with my Palo Alto firewall. This problem started about a week ago. Prior to that, the website in question was functioning properly and being handled by the appropriate security policy.

 

Currently, a public

...

  • 1714 Posts
  • 56 Subscriptions