Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4593 Views
  • 0 replies
  • 1 Likes

restoring an NGFW from factory default

Good day to Palo Alto LIVE Community, What are the steps / procedures for "resurrecting" a dead Palo Alto firewall? We have a previously-working Palo Alto firewall that eventually needed to be set to factory default settings. (since its console port was still working) I'm guessing that, after factory default settings, I will need to try do...

Resolved! ms-rdp and cotp

Hello there, I have googled and searched the community but I am still at a loss: why is the "rdp" communication identified as "cotp" sometimes? Does anyone have an answer or a a link? Have a great no-unplanned-downtime-day everyone! Jan

janhoppe by L0 Member
  • 15122 Views
  • 2 replies
  • 0 Likes

Video Traffic between cameras and server

Dears I have a huge campus of university with multiple building ( 20 to 30 small and big) we have cameras every where in the campus and also user traffic is on the same access switch , i m introducing a campus firewall so that the user traffic between the vlan will pass by firewall currently the CCTV server is not behiind the firewall and it ...

adamgibs by L0 Member
  • 1593 Views
  • 0 replies
  • 0 Likes

PA-3000 series and PA-5000 series Content updates consume 100 % Pan/cfg.

Before Content update. Wed Jan 10 07:06:05 SGT 2024Filesystem Size Used Avail Use% Mounted on/dev/md2 3.8G 3.4G 270M 93% //dev/md5 7.6G 6.0G 1.2G 84% /opt/pancfg/dev/md6 3.8G 1.7G 2.0G 47% /opt/panrepotmpfs 2.0G 210M 1.8G 11% /dev/shmcgroup_root 2.0G 0 2.0G 0% /cgroup/dev/md8 198G 153G 36G 82% /opt/panlogswhile upgrading. Wed Jan 10 07:06:26 SGT...

Resolved! PA-5250 Raid Integrity Check

Hi everyone, A good day to all! I encountered the following when upgrading the physical PA-5250 Firewalls from 10.0.10-h1 to 10.1.0 and from 10.1.0 to 10.1.5-h2.Such that the Log Quota is reflected 0MB and there were no logs there were displayed (E.g. System Logs). When we enter the command ‘show system raid status’ on CLI, we saw that the ...

RVizcarra by L4 Transporter
  • 27726 Views
  • 15 replies
  • 1 Likes

Lab initial procedure for PA VM 8.0

Hello Team, First of all am a noob on the paloalto and I'm diving into the Palo Alto Firewall world after spending a year on the Cisco L2 side. Just set up a lab mirroring the site design for a new organization, and it's my first go at Palo Alto. For the real deal, I'll be handling a PA-850. Feeling pretty good about Nexus and endpoints, but c...

SSL Decryption for Outbound Traffic and the Block Private Key Export option

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

rmeddane_0-1705176333008.png
rmeddane_1-1705176333011.jpeg
rmeddane_2-1705176333013.jpeg
rmeddane_3-1705176333018.jpeg
rmeddane by L2 Linker
  • 1818 Views
  • 0 replies
  • 0 Likes

Understand the "Block Private Key Export" option with three scenarios

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

Capture d'écran 2024-01-13 155814.png
rmeddane_0-1705158156795.jpeg
rmeddane_1-1705158156797.jpeg
rmeddane_2-1705158156803.jpeg
rmeddane by L2 Linker
  • 2666 Views
  • 0 replies
  • 1 Likes

"The Block Private Key Export" option - Strange Behavior

I read the following explanation about the "The Block Private Key Export" option : You can permanently block the export of private keys for certificates when you generate them in or import them into PAN-OS or Panorama. I tested this option for the certificate generated by an external CA as shown below: I submitted the CSR to the CA serve...

1.png
3.png
Capture d'écran 2024-01-12 230321.png
6.png
rmeddane by L2 Linker
  • 1738 Views
  • 0 replies
  • 0 Likes

Preempt behaviour in HA

Hi all, As per palo alto documentation if we enable preempt in HA then primary palo alto will reclaim its active position if it comes back. Does this reclaim works on complete device failure or for any monitoring link/path failure also.

BGP route is not present on the other region

This is the representation of the connectivity of my setup. Inside each region have Palo Alto firewall and Silverpeak appliance. On each region, between Palo Alto and Silverpeak there is ibgp that been configured. AS number is the same. On the firewall itself, each AS number is different. Currently from China, it only have the route to Sing...

KhairulNizam_0-1704683652019.png
  • 1586 Posts
  • 61 Subscriptions