Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4519 Views
  • 0 replies
  • 1 Likes

US Government / DoD Conttract

Is there a mechanism to add purchased devices to a pre-existing government contract? I would assume PA runs a DoD contract similar to Cisco, wherein devices used by the DoD can be added to a contract vehicle of some sort to receive software/hardware support? Thanks, appreciate any insight.

PaloAlto Firewall Vsys

Dears i have an 2 no's of physical PAN in HA and in multiple vsys that are splited as an internet firewall and DC Firewall, can i know the disadvantages for the same. can i know the firewall resources are shared example CPU, RAM, if an CPU or RAM consumption based attack happens on the internet fw vsys it will not be having enough resources to...

adamgibs by L0 Member
  • 1570 Views
  • 2 replies
  • 0 Likes

How to create Custom Application Signature to identify WebRTC Application with Cisco Meeting Server

A Custom App-ID allows you to do two things: Create pattern-based signatures for traffic that doesn't match any of the pre-defined application signatures. Create a Custom Application for use in an Application Override Policy to override a pre-defined application signature. The Traffic Logs shown that a WebRTC connection using Cisco Meet...

rmeddane_0-1705919196406.png
rmeddane_1-1705919196415.jpeg
rmeddane_2-1705919196427.jpeg
rmeddane_3-1705919196434.jpeg
rmeddane by L2 Linker
  • 3400 Views
  • 0 replies
  • 1 Likes

PBF Rule Monitoring - Forced egress i/f?

I have a dual ISP configuration. ethernet1/1 is primary Internet. ethernet1/2 is backup wireless Internet (phone or dedicated hot spot as needed). ethernet1/2 is connected to an old Linksys router running DD-WRT and it automatically connects to my hotspot when I turn it on. Otherwise, there is no Internet access via ethernet1/2. I have a P...

Traffic Log - What's the difference between the "Type" field and the "action" field

While investigating and navigating in the Traffic Log, I noticed for some traffic the Type is Drop and the Action is Deny, While in some traffic, the Type is Deny and the Action is Reset Both. The Security Policy Rule is configured with the Deny Action without Security Profiles. How to explain this behavior in the Traffic Logs?

1.png
Traffic Log.png
2.png
rmeddane by L2 Linker
  • 8216 Views
  • 3 replies
  • 0 Likes

Internet is not reachable

Hi We have a pa-850 in our site and the issue is when i try to ping isp side ip , i am able to get ping response. But when i use command ping source <eth1/1 ip configured with isp range usable ip> host google.com i am not able to get any response. What could be the reason that pa-850 is able to get response from isp side interface...

How to Disable Auto Commit in Firewall

Is there any way to stop Auto-Commit? I am facing issues with one of my Palo Alto Firewall where Auto Commit keeps failing and starting again & again. Due to BUG, it's happening, and solution is to upgrade or downgrade to another release. Whenever I am trying to upgrade/downgrade it gives error that Auto-commit is in queue and cannot insta...

Resolved! Internet -> PA-440 -> ASUS RT-AX53U AX1800. Error = Router does not get Internet access

I have just purchased my first PaloAlto firewall. I am a sysadmin at a small office (about 20 people) and I am in the progress of setting up a new WiFi for my office. This is my equipment: Firewall: PA-440 Router: Asus RT-AX53U AX1800 This is my current setting: I have managed to connect to the PA-440 firewall by setting my network ca...

01 PA-440 Drawing.png
02 PA-440 Dashboard.png
03 PA-440 Interfaces.png
10 Asus Dashboard.png

Resolved! EDL Category Explanation - Teams

Hi Can someone explain the difference between the EDL categories published as part of the EDL Hosting Service I.e. looking at the Teams worldwide IPv4 EDLs, there are 4 categories (Base, Allow, Optimise & Required). The EDL Hosting page doesn't state the difference between each. EDL Hosting Service (paloaltonetworks.com) Once all duplica...

NGJ1 by L1 Bithead
  • 3516 Views
  • 2 replies
  • 0 Likes

restoring an NGFW from factory default

Good day to Palo Alto LIVE Community, What are the steps / procedures for "resurrecting" a dead Palo Alto firewall? We have a previously-working Palo Alto firewall that eventually needed to be set to factory default settings. (since its console port was still working) I'm guessing that, after factory default settings, I will need to try do...

Resolved! ms-rdp and cotp

Hello there, I have googled and searched the community but I am still at a loss: why is the "rdp" communication identified as "cotp" sometimes? Does anyone have an answer or a a link? Have a great no-unplanned-downtime-day everyone! Jan

janhoppe by L0 Member
  • 14403 Views
  • 2 replies
  • 0 Likes

Video Traffic between cameras and server

Dears I have a huge campus of university with multiple building ( 20 to 30 small and big) we have cameras every where in the campus and also user traffic is on the same access switch , i m introducing a campus firewall so that the user traffic between the vlan will pass by firewall currently the CCTV server is not behiind the firewall and it ...

adamgibs by L0 Member
  • 1485 Views
  • 0 replies
  • 0 Likes
  • 1795 Posts
  • 60 Subscriptions