Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4679 Views
  • 0 replies
  • 1 Likes

Resolved! How to check not detected open or allowed ports in service rule policy

NGFW Hi, Any idea if there is a tool to trace in PA5220 to check the un-detected open or allowed ports in rule policy. For example from a source IP 192.168.x.x.x. to a destination public IP (web server) . In the service I only specify port 443 but upon checking there are a lot of open ports that were allowed. This poses a security vulnerability...

giozapa by L0 Member
  • 3974 Views
  • 2 replies
  • 0 Likes

Resolved! Configuring DHCP Server for Hostname-Based IP Assignment with Three IP Range

My goal is to set up a DHCP server capable of allocating IP addresses according to the hostnames of client machines. Here are the specific requirements: We require the DHCP server to oversee three separate IP ranges. For hostname-based IP assignment: Client machines with hostnames starting with "win*" should be assigned IP addresses from Range ...

hamza_d by L1 Bithead
  • 6072 Views
  • 4 replies
  • 0 Likes

HA traffic failover not wotking.

This is my HA configuration, PC 1 is 10.0.0.10 and PC2 is 30.0.0.15, I have configured HA active-passive.HA is formed between Both Palo Alto but Failover is not working.When I do failover the Passive becomes active however it is not responding for the ping from PC1 or From Pc2, I am doing continous ping from Pc1 to pc2. What I noticed is Palo is...

ArunKumar7_0-1708965333841.png

Resolved! OpenSSH verification and upgrade

Aside from checking in the OSS listing, how can i verify the current OpenSSH version installed on the Palo Alto device. Also how can we upgrade it to a recommended version? Current firmware version: 10.2.6 Based on OSS listing, OpenSSH version is: 8.0p1

Resolved! URL filtering not working

My issue is that the url filtering isn't working. I for example, I can browse to urlfiltering.paloaltonetworks.com/test-adult and it isn't blocked. This is on a PA-220. It is currently running 10.1.3-h3. Earlier today, I noticed that the URL filtering license was expired, but I just did "retrieve license keys from license server" and now it sh...

nwnetadmin_0-1708648821131.png

Resolved! Bandwidth

Hello team, This is my first time here. I have two palo alto to replace and i need to find out the current bandwidth get used on the site, Is there a specific command on the cli or GUI i can find out what bandwidth get used on the site please?

Newly-Registered-Domains

Hi Everyone We recently implemented Advanced URL filtering at our University, one of the categories we have blocked is Newly-Registered-Domains, we created a custom URL group and implemented dynamic lists for the infosec team to add exceptions and put a good process in place. The issue we seem to have is that we now face a challenge with our...

GinAmRSA by L0 Member
  • 3765 Views
  • 1 replies
  • 0 Likes

Action is Reset Both in traffic monitoring

The user was trying to access the Proofpoint links it is not accessible in the firewall. We could see the action is reset both in monitoring and a session end reason is policy-deny and checked the threat logs but we couldn't see any logs in the threat. could someone please help me to understand the issue

The panorama encountered a commit failure: "failed to create sdwan cluster meta file: object of type 'NoneType' has no len()"

Hi team, While configuring PanOS SD-WAN, I successfully added the firewalls as managed devices to Panorama and installed the SD-WAN plugin version 3.1.2. Subsequently, I included the devices in the SD-WAN configuration, activated BGP policy for automatic creation. However, an error has surfaced in the process. ---------failed to create sdwan clu...

AkashThangavel_0-1708435135979.png

How to check if a specific port/servic is getting passed throgh the firewall to a specific Public IP address

An IT Auditor stated that SNMP is listening through the firewall for a specific Public IP Address. I have been filtering the network traffic on the PaloAlto 3020 for that specific IP address and also filtering with port 161. BUt Id not see any results except that the 'Deny-Deny' catch all group was being used. That is suggesting to me that t...

My PA-450 is not showing Network activity in the ACC tab

Good Morning! I am not seeing any network activity in the ACC tab for my 450. I've cleared all filters just in case, restarted the management plane, I even failed over to see if it was isolated to the one unit. Both are showing this. When I set the date spans, I see that the 9th is the last time datapoints were added to the display. The ONLY c...

RMaillet by L0 Member
  • 1918 Views
  • 1 replies
  • 0 Likes
  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors