Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4552 Views
  • 0 replies
  • 1 Likes

Video Traffic between cameras and server

Dears I have a huge campus of university with multiple building ( 20 to 30 small and big) we have cameras every where in the campus and also user traffic is on the same access switch , i m introducing a campus firewall so that the user traffic between the vlan will pass by firewall currently the CCTV server is not behiind the firewall and it ...

adamgibs by L0 Member
  • 1541 Views
  • 0 replies
  • 0 Likes

PA-3000 series and PA-5000 series Content updates consume 100 % Pan/cfg.

Before Content update. Wed Jan 10 07:06:05 SGT 2024Filesystem Size Used Avail Use% Mounted on/dev/md2 3.8G 3.4G 270M 93% //dev/md5 7.6G 6.0G 1.2G 84% /opt/pancfg/dev/md6 3.8G 1.7G 2.0G 47% /opt/panrepotmpfs 2.0G 210M 1.8G 11% /dev/shmcgroup_root 2.0G 0 2.0G 0% /cgroup/dev/md8 198G 153G 36G 82% /opt/panlogswhile upgrading. Wed Jan 10 07:06:26 SGT...

Resolved! PA-5250 Raid Integrity Check

Hi everyone, A good day to all! I encountered the following when upgrading the physical PA-5250 Firewalls from 10.0.10-h1 to 10.1.0 and from 10.1.0 to 10.1.5-h2.Such that the Log Quota is reflected 0MB and there were no logs there were displayed (E.g. System Logs). When we enter the command ‘show system raid status’ on CLI, we saw that the ...

RVizcarra by L4 Transporter
  • 27413 Views
  • 15 replies
  • 1 Likes

Lab initial procedure for PA VM 8.0

Hello Team, First of all am a noob on the paloalto and I'm diving into the Palo Alto Firewall world after spending a year on the Cisco L2 side. Just set up a lab mirroring the site design for a new organization, and it's my first go at Palo Alto. For the real deal, I'll be handling a PA-850. Feeling pretty good about Nexus and endpoints, but c...

SSL Decryption for Outbound Traffic and the Block Private Key Export option

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

rmeddane_0-1705176333008.png
rmeddane_1-1705176333011.jpeg
rmeddane_2-1705176333013.jpeg
rmeddane_3-1705176333018.jpeg
rmeddane by L2 Linker
  • 1771 Views
  • 0 replies
  • 0 Likes

Understand the "Block Private Key Export" option with three scenarios

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

Capture d'écran 2024-01-13 155814.png
rmeddane_0-1705158156795.jpeg
rmeddane_1-1705158156797.jpeg
rmeddane_2-1705158156803.jpeg
rmeddane by L2 Linker
  • 2552 Views
  • 0 replies
  • 1 Likes

"The Block Private Key Export" option - Strange Behavior

I read the following explanation about the "The Block Private Key Export" option : You can permanently block the export of private keys for certificates when you generate them in or import them into PAN-OS or Panorama. I tested this option for the certificate generated by an external CA as shown below: I submitted the CSR to the CA serve...

1.png
3.png
Capture d'écran 2024-01-12 230321.png
6.png
rmeddane by L2 Linker
  • 1713 Views
  • 0 replies
  • 0 Likes

Preempt behaviour in HA

Hi all, As per palo alto documentation if we enable preempt in HA then primary palo alto will reclaim its active position if it comes back. Does this reclaim works on complete device failure or for any monitoring link/path failure also.

BGP route is not present on the other region

This is the representation of the connectivity of my setup. Inside each region have Palo Alto firewall and Silverpeak appliance. On each region, between Palo Alto and Silverpeak there is ibgp that been configured. AS number is the same. On the firewall itself, each AS number is different. Currently from China, it only have the route to Sing...

KhairulNizam_0-1704683652019.png

DNS-Base traffic

Hello Fellow Members, Have been going through the ACC tab and noticed some rather abnormal traffic, have traffic that well beyond 800TB, and at times goes beyond 1000TB(1PB), is this normal given that fact I am looking at internal traffic (intrazone default) and looking at just the last 1 hour. Application causing all the traffic appears to ...

mshale by L0 Member
  • 2433 Views
  • 2 replies
  • 0 Likes

30 day trial license activation

Hello, i started my trial license yesterday and wondering if i can register it? When i go under software update, it says "The device is not found or not registered, please try after some time". When i try to create a support account it wants from me a serial number. I insert the number from dashboard and error appear "Invalid Azure Serial Num...

ivans89 by L0 Member
  • 1269 Views
  • 1 replies
  • 0 Likes

Resolved! DNS not resolving for a website

Hi All, I have been experiencing DNS resolution issue for one particular website on all the systems under our Palo Alto firewall network. However, it is working well on the systems under our Sophos network. At first, I checked the website category and found it falls under malware and gave an exception to it to be accessed on our network in th...

Jerome.j by L1 Bithead
  • 18794 Views
  • 9 replies
  • 0 Likes
  • 1589 Posts
  • 60 Subscriptions