Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

SSH\SFTP Proxy

Hello, I'm currently managing an SFTP (SSH) server. I'm attempting to implement file blocking using the NGFW. I've configured a decryption profile that includes "SSH Proxy". According to the traffic logs, the "decrypt" option appears to be activated. However, I'm not observing any files in the data filtering logs, even though logs for other file...

chens by L3 Networker
  • 2657 Views
  • 1 replies
  • 0 Likes

get-ldap-data-failure - LDAP Failover doesn't work

-I had two LDAP servers configured with a firewall, the primary LDAP server had an issue with high CPU and memory due to which the firewall lost the group membership though the firewall has L3 reachability. During the log analysis found that get-ldap-data-failure from Primary LDAP. We manually failed over the LDAP to a secondary one and this r...

Resolved! PAN-OS Version Release History

Hello Community, How to get the release history (actual date) for the various versions on the PAN-OS? For e.g. I want to know the release date for PAN-OS 10.1.4-h4. Thank you, MKPlease note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or comp...

mkgsgi by L1 Bithead
  • 12864 Views
  • 6 replies
  • 0 Likes

Site-to-Site VPN with Static and Dynamic Routing

I read the following article about Site to Site VPN With Static and Dynamic Routing. https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/site-to-site-vpn-quick-configs/site-to-site-vpn-with-static-and-dynamic-routing The article says that the Satellite Site uses static Routing so the VPN Peer A has a static routes to...

VPN Redi Profile 2.png
VPN Redi Profile 1.png
rmeddane by L2 Linker
  • 2378 Views
  • 2 replies
  • 0 Likes

Wrong Geo location

Hello, couple times we had issue with wrong geolocation. It is very interesting how PaloAlto create ip<->location database. example: from FW: show location ip 46.8.61.78 46.8.61.78Czech Republic regarding https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPtECAW and any other geolocation service it is russian add...

Resolved! Upgraded pa820 to 10.2.7, no acc info showing

Hi all, I upgraded our PA820 to 10.2.7, and somehow now the acc tabs don't show any information, in network, threats, blocked, only in globalprotect it shows data, I searched and found some information on the release notes, as well as searched around the web, found some talk about issues with PAN-OS 10.2.7. So there's bugs in 10.2.7 mainly in...

cdcirexx by L3 Networker
  • 5878 Views
  • 5 replies
  • 1 Likes

Resolved! Security Policy

Hello, I have created a security policy with the below details. I am the hitting following URL https://10.x.x.x:15671 and I see the 'connection is reset' in the browser. I see traffic is hitting the policy (Hit count) but it's not logging. When I set the action to Deny/Drop/reset-client\reset-server the traffic is logging when hits the rule. W...

srikarpuligandla_0-1701627610318.png
srikarpuligandla_1-1701627668060.png
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors