Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4725 Views
  • 0 replies
  • 1 Likes

What is the Certificate Chain of Trust?

The Chain of Trust refers to your SSL certificate and how it is linked back to a trusted Certificate Authority. In order for an SSL certificate to be trusted it has to be traceable back to the trust root it was signed off of, meaning all certificates in the chain – server, intermediate, and root, need to be properly trusted. There are 3 parts ...

ca-1.png
rmeddane by L2 Linker
  • 3954 Views
  • 0 replies
  • 0 Likes

Aggregate interace behaviour

Hi All, Facing an issue where doing an failover with aggregate interface not working. Example if I unshut any one link from aggregation link of passive firewall and shut both interfaces of aggregation link of primary firewall, still firewall don't switch it state from passive to active or vice versa. Is it firewall consider aggregate inter...

Migration from PA-3060 to PA-3260

I'm seeking advice regarding a migration from a PA-3060 HA pair with PAN-OS v9.1.X to PA-3260 HA pair v10.2.X. I understand that to have minimal issues for the migration, it is recommended to have the same OS version. From the Compatibility Matrix shown here, I can see that I am able to downgrade PA-3260 to version 9.1.X for the migration. ht...

Packets retransmission captured in packet capture on firewall but still seems dropping

Recently trying to debug a possible packet dropping issue at firewall (screenshot attached for reference). The issue is appearing when I try to make request to my server from my iOS device, some API calls works Ok but often few of those fails with 503 error code and this happens randomly against different APIs. When I looked at the firewall the ...

Does the Post-NAT Zone for security policy is for Source zone and Destination Zone?

I read the following from the palo alto study guide: A Security policy rule requires a source IP, destination IP, source zone, and destination zone. If you use an IP address in a Security policy rule, you must add the IP address value that existed before NAT was implemented, which is called the pre-NAT IP. After the IP address is translated (p...

Post NAT Zone.png
rmeddane by L2 Linker
  • 10780 Views
  • 2 replies
  • 0 Likes

User ID - Igonere User list

Hi, I have added a few users to the "Ignore USer list" for user-id configuration. But when I checked the User-IP mappings I still see the user-id is mapping the username with IPs even though the usernames are in ignore list. Any suggestions on what to check here?

srikarpuligandla_0-1703226223762.png

Resolved! HA pair not synchronizing

Hi all, I have a PA-220 HA pair without licenses running on PANOS 9.1.13-h3. Recently I had an issue with a HA passive Firewall, so it had to be replaced. I extracted the active firewall's running-config and uploaded it into the new passive one. I was able to synchronize App&Threat version by re-installing the active's FW current version. ...

JuanFelipeAyala_1-1703613361357.png
JuanFelipeAyala_2-1703613751019.png
JuanFelipeAyala_4-1703613921986.png

IPSec VPN Tunnel Interface with IP Addresses

I read the following example of Site to Site VPN IPsec with static routing : https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/site-to-site-vpn-quick-configs/site-to-site-vpn-with-static-routing In the figure the example shown that both Tunnel Interfaces on the peers VPN are 10.10.10.10 and 10.10.10.11 in the same s...

Topo VPN.png
Tunnel.png
rmeddane by L2 Linker
  • 5100 Views
  • 5 replies
  • 0 Likes

Incidents contain many alert types... but why?

Hello, everyone. Our product suite now includes receiving alerts from the NGFW, in addition to XDR. It seems, though, that a single incident may include several different alerts. This seems like a strange behavior, because the list of alerts come from many hosts, or threat type, or threat vector. If the Incidents are grouping unrelated alert...

  • 1621 Posts
  • 61 Subscriptions
Top Solution Authors