Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4679 Views
  • 0 replies
  • 1 Likes

"The Block Private Key Export" option - Strange Behavior

I read the following explanation about the "The Block Private Key Export" option : You can permanently block the export of private keys for certificates when you generate them in or import them into PAN-OS or Panorama. I tested this option for the certificate generated by an external CA as shown below: I submitted the CSR to the CA serve...

1.png
3.png
Capture d'écran 2024-01-12 230321.png
6.png
rmeddane by L2 Linker
  • 1764 Views
  • 0 replies
  • 0 Likes

Preempt behaviour in HA

Hi all, As per palo alto documentation if we enable preempt in HA then primary palo alto will reclaim its active position if it comes back. Does this reclaim works on complete device failure or for any monitoring link/path failure also.

BGP route is not present on the other region

This is the representation of the connectivity of my setup. Inside each region have Palo Alto firewall and Silverpeak appliance. On each region, between Palo Alto and Silverpeak there is ibgp that been configured. AS number is the same. On the firewall itself, each AS number is different. Currently from China, it only have the route to Sing...

KhairulNizam_0-1704683652019.png

DNS-Base traffic

Hello Fellow Members, Have been going through the ACC tab and noticed some rather abnormal traffic, have traffic that well beyond 800TB, and at times goes beyond 1000TB(1PB), is this normal given that fact I am looking at internal traffic (intrazone default) and looking at just the last 1 hour. Application causing all the traffic appears to ...

mshale by L0 Member
  • 2533 Views
  • 2 replies
  • 0 Likes

30 day trial license activation

Hello, i started my trial license yesterday and wondering if i can register it? When i go under software update, it says "The device is not found or not registered, please try after some time". When i try to create a support account it wants from me a serial number. I insert the number from dashboard and error appear "Invalid Azure Serial Num...

ivans89 by L0 Member
  • 1332 Views
  • 1 replies
  • 0 Likes

Resolved! DNS not resolving for a website

Hi All, I have been experiencing DNS resolution issue for one particular website on all the systems under our Palo Alto firewall network. However, it is working well on the systems under our Sophos network. At first, I checked the website category and found it falls under malware and gave an exception to it to be accessed on our network in th...

Jerome.j by L1 Bithead
  • 20415 Views
  • 9 replies
  • 0 Likes

URL filtering database updates problem

I have a feeling that the URL filtering database updating doesn't work correctly. After a reboot of the firewall it update a few days and then stops. In the URL filtering logs I also see a lot of "not-resolved" even for url's like play.google.com. I've had this with at least PAN-OS 10.2.4-h2 and now also with 11.0.2-h2. When I run the command "s...

adminglu by L1 Bithead
  • 8884 Views
  • 4 replies
  • 0 Likes

Wildcard certificate-GPVPN certificates

Just imported new wildcard cert for firewall management GUI as the existing one is expiring soon. Certificate first imported to Panorama then pushed to Primary & Secondary firewalls (Active-Standby). Certificate is showing valid for Panorama but not for primary and secondary firewalls. Do we need to restart any services for the new certifica...

High Disk Space Usage on /opt/pancfg partition

Hi Mates, I am getting alerts on /opt/pancfg utilizing 90%. How ever I deleted the old, downloaded software and dynamic updates (around 1.5Gb file) but still space utilization is same as 90% using below KB. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLSJCA4 Filesystem Size Used Avail Use% Mounted on/dev/md2 3.8G...

GP-Agent, Allow with Ticket to disconnect the GP-Agent

Hi everyone, I have a use case to disconnect the GP agent through the ticket. By following up on the admin guide I configured it. But it's not working. I have attached screenshots of the error message. Configuration part: In Portal, Agent >App settings >allow users to disconnect GlobalProtect App(Always-on-mode)----Allow with Ticket. Th...

AkashThangavel_0-1676191600728.png
error3.png
error2.png
error1.png

Palo Alto - Security rules best practice for web filtering delegation

Hi, We deploy multiple PA-220 and configure them through a unified Panorama. The need is to provide local administrators with the ability to manage a part of the web filtering to do things like add/remove a website from the allow/blocklist URL category that has been defined locally. The biggest challenge to us, is in the way Palo Alto han...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors