Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4679 Views
  • 0 replies
  • 1 Likes

Internet is not reachable

Hi We have a pa-850 in our site and the issue is when i try to ping isp side ip , i am able to get ping response. But when i use command ping source <eth1/1 ip configured with isp range usable ip> host google.com i am not able to get any response. What could be the reason that pa-850 is able to get response from isp side interface...

How to Disable Auto Commit in Firewall

Is there any way to stop Auto-Commit? I am facing issues with one of my Palo Alto Firewall where Auto Commit keeps failing and starting again & again. Due to BUG, it's happening, and solution is to upgrade or downgrade to another release. Whenever I am trying to upgrade/downgrade it gives error that Auto-commit is in queue and cannot insta...

Resolved! Internet -> PA-440 -> ASUS RT-AX53U AX1800. Error = Router does not get Internet access

I have just purchased my first PaloAlto firewall. I am a sysadmin at a small office (about 20 people) and I am in the progress of setting up a new WiFi for my office. This is my equipment: Firewall: PA-440 Router: Asus RT-AX53U AX1800 This is my current setting: I have managed to connect to the PA-440 firewall by setting my network ca...

01 PA-440 Drawing.png
02 PA-440 Dashboard.png
03 PA-440 Interfaces.png
10 Asus Dashboard.png

Resolved! EDL Category Explanation - Teams

Hi Can someone explain the difference between the EDL categories published as part of the EDL Hosting Service I.e. looking at the Teams worldwide IPv4 EDLs, there are 4 categories (Base, Allow, Optimise & Required). The EDL Hosting page doesn't state the difference between each. EDL Hosting Service (paloaltonetworks.com) Once all duplica...

NGJ1 by L1 Bithead
  • 3789 Views
  • 2 replies
  • 0 Likes

restoring an NGFW from factory default

Good day to Palo Alto LIVE Community, What are the steps / procedures for "resurrecting" a dead Palo Alto firewall? We have a previously-working Palo Alto firewall that eventually needed to be set to factory default settings. (since its console port was still working) I'm guessing that, after factory default settings, I will need to try do...

Resolved! ms-rdp and cotp

Hello there, I have googled and searched the community but I am still at a loss: why is the "rdp" communication identified as "cotp" sometimes? Does anyone have an answer or a a link? Have a great no-unplanned-downtime-day everyone! Jan

janhoppe by L0 Member
  • 15562 Views
  • 2 replies
  • 0 Likes

Video Traffic between cameras and server

Dears I have a huge campus of university with multiple building ( 20 to 30 small and big) we have cameras every where in the campus and also user traffic is on the same access switch , i m introducing a campus firewall so that the user traffic between the vlan will pass by firewall currently the CCTV server is not behiind the firewall and it ...

adamgibs by L0 Member
  • 1636 Views
  • 0 replies
  • 0 Likes

PA-3000 series and PA-5000 series Content updates consume 100 % Pan/cfg.

Before Content update. Wed Jan 10 07:06:05 SGT 2024Filesystem Size Used Avail Use% Mounted on/dev/md2 3.8G 3.4G 270M 93% //dev/md5 7.6G 6.0G 1.2G 84% /opt/pancfg/dev/md6 3.8G 1.7G 2.0G 47% /opt/panrepotmpfs 2.0G 210M 1.8G 11% /dev/shmcgroup_root 2.0G 0 2.0G 0% /cgroup/dev/md8 198G 153G 36G 82% /opt/panlogswhile upgrading. Wed Jan 10 07:06:26 SGT...

Resolved! PA-5250 Raid Integrity Check

Hi everyone, A good day to all! I encountered the following when upgrading the physical PA-5250 Firewalls from 10.0.10-h1 to 10.1.0 and from 10.1.0 to 10.1.5-h2.Such that the Log Quota is reflected 0MB and there were no logs there were displayed (E.g. System Logs). When we enter the command ‘show system raid status’ on CLI, we saw that the ...

RVizcarra by L4 Transporter
  • 28169 Views
  • 15 replies
  • 1 Likes

Lab initial procedure for PA VM 8.0

Hello Team, First of all am a noob on the paloalto and I'm diving into the Palo Alto Firewall world after spending a year on the Cisco L2 side. Just set up a lab mirroring the site design for a new organization, and it's my first go at Palo Alto. For the real deal, I'll be handling a PA-850. Feeling pretty good about Nexus and endpoints, but c...

SSL Decryption for Outbound Traffic and the Block Private Key Export option

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

rmeddane_0-1705176333008.png
rmeddane_1-1705176333011.jpeg
rmeddane_2-1705176333013.jpeg
rmeddane_3-1705176333018.jpeg
rmeddane by L2 Linker
  • 1868 Views
  • 0 replies
  • 0 Likes

Understand the "Block Private Key Export" option with three scenarios

The firewall uses a certificate with the role of CA Certificate of Authority to perform SSL Decryption for outbound traffic. There are three methods to generate this certificate. Method 1 : You can use a self-signed certificate. The firewall will generate a Certificate with the Public / Private keys automatically without involving an extern...

Capture d'écran 2024-01-13 155814.png
rmeddane_0-1705158156795.jpeg
rmeddane_1-1705158156797.jpeg
rmeddane_2-1705158156803.jpeg
rmeddane by L2 Linker
  • 2825 Views
  • 0 replies
  • 1 Likes
  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors