Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4722 Views
  • 0 replies
  • 1 Likes

Resolved! Including CVE in Threat Logs

For as long as the Palo Threat feature has been around, I can't believe this feature doesn't already exist. Would it be possible for Palo to include the associated CVE as a field next to the ThreatID? These mapps occur outside of the Firewall as part of the ThreatDB or Content Update emails, but not locally on the Firewall itself. It would ...

Azure SAML authentication: validate identity provider certificate. (best pratices)

Hi, We have configured SAML on our portal and gateway. By default Microsoft generates a self signed certificate that is valid for 3 years for every Enterprise application you create. Is this secure enough to use the default self signed one and not validate it on my gateway/portal leave the check unmarked. According to this article it should be ...

zGomez by L3 Networker
  • 6772 Views
  • 3 replies
  • 0 Likes

Resolved! QoS configuration based on destination (sub)interface on 3400 series

I am migrating a configuration from PA-3200 series device on PAN-OS 10.1 to PA-3410 where minimum version is 10.2. On migration I noticed error messages about destination interface in QoS configuration: network -> qos -> interface -> ae3 -> regular-traffic -> groups -> regular-traffic-group -> members -> aaaa -> matc...

santonic by L6 Presenter
  • 2811 Views
  • 2 replies
  • 0 Likes

How Palo Alto NGFW Prevent Unknow CVEs?

Dear Team, I hope all of you are doing well. I have one question. How can PA prevent an unknown CVE on NGFW? Why I brought up this question is because I saw that from one vendor to another, they have different CVE numbers and IDs. I was wondering if you could advise me. Thanks!

Advanced Wildfire Allowing High Severity Verdicts but blocking Informational

Hi I have Advanced Wildfire in our Lab env and have noticed something very odd, when the firewall is submitting any files to Wildfire if they are returning "informational" they are blocked, if they are returning Malicious and "High" the action is allow, this has also been confirmed by the fact that the samples of Malware are being blocked by t...

i can‘t commit after upgrading to 11.0.2 version

hi, i can't commit after upgrading 11.0.2 version from 10.2.X, For testing purposes, I changed any of the small options and did not make any other changes, but I cannot commit them。 tip: Details Partial changes to commit: changes to configuration by administrators: admin Changes to policy and objocts confguration DHcP Client Interface has no...

david.ge by L1 Bithead
  • 2006 Views
  • 1 replies
  • 0 Likes

Can Palo notice and react to a flapping Internet link?

Hi All, We have simple setup, when firewall is connected over physical interface to a L2 switch, while L2 switch is connected to 2 CPEs of different ISPs. Obviously, next hop for our firewall going out is an interface of the CPE. We are tracking default routes for both ISP using route monitoring feature. Unfortunately, that does not seem to...

File Blocking block/continue issue

Hi everyone, I'm trying to setup fileblocking on PanOS 11.0.2-h1 and I'm facing strange behaviors. With some sites I get block or continue page, and DataFiltering logs. With others, I get an empty file download for both continue or block actions and a traffic log with threat as end of session reason : I prefer to get a block or continue page ...

masdidier_0-1706806542509.png

Policy commit failures due to profiles exceeding platform capacity using version 10.1.8-h2

We have not updated the number of profiles and have been successfully committing policy for probably a year with this same number of policies, but all of a sudden we are not able to commit policy pushes either from gui or cli. We have gone through and deleted alot of shared profiles and are still getting the following error: Error: Total num...

Interface migration to fiber over SFP 10G

Hello team, I have a Palo Alto 3220 cluster that is connected to a CORE switch over ethernet and I need to migrate that connection to fiber over SFP 10G converter. I am trying to define a procedure to migrate with no downtime and I had thought to start with the standby node, suspending this node for HA, dehabilitating the link monitoring inter...

ALDIAZEG by L0 Member
  • 1617 Views
  • 1 replies
  • 0 Likes
  • 1620 Posts
  • 61 Subscriptions
Top Solution Authors