Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4599 Views
  • 0 replies
  • 1 Likes

BI-DIRECTIONAL STATIC NAT NOT WORKING

Hi, I have the following situation I want to do a bi-directional NAT for a complete subnet range. I want to translate 192.168.96.0/24 --> 10.196.96.0/24 : 192.196.96.1 --> 10.196.96.1 192.168.96.2 --> 10.196.96.2 ... And this in both directions. When i select bi-directional nat on the NAT policy it is not working for the...

zGomez_0-1698767701056.png
zGomez_1-1698767778179.png
zGomez by L3 Networker
  • 2698 Views
  • 1 replies
  • 0 Likes

Resolved! DDOS / DOS Protection

Is there any benefit of placing an additional firewall on the OUTSIDE of the customer's internet/external router? There is already a perimeter firewall on the inside of this router. (Proposed additional firewall running virtual wire) <---> External Router (BGP and internet links) <----> Perimeter Firewall <----> Internal Router...

Antivirus Download and Install Hanging

Pa11.0.1 onPa820 in High Avaliability mode. The antivirus download and install update job has been at the "download in progress" status for several hours. The last antivirus valid is:4406 -4923 of 31/03/2023. The following resolution answer does not work Resolution [Not work] Run the following commands to clear the stuck download job...

Resolved! Decommission IPSec site to site VPN

Hi All, I have been looking at the best way to decommission VPN tunnels on Palo Alto firewall, and I could only find disabling the IKE phase1 and the IPSec tunnels. is there a recommended way to decom IPSec VPN tunnels on Palo Alto firewalls? Thank you in advance.

Resolved! How to use a PA-220R in a small office environment without DC power?

I recently purchased an additional PA-220 firewall for a new small office our company is connecting to other offices running PA-820 and PA-220 firewalls. I was surprised to find that the product I received is a PA-220R which requires DC power, and that the legacy PA-220 firewall I thought I was buying is End-Of-Sale. I requested an RMA from my r...

Cramer by L1 Bithead
  • 3913 Views
  • 3 replies
  • 0 Likes

Wildfire Analysis Report returns 500 internal server error

Hi team I’m new to PA firewalls and facing some WebUI related problem. When I try to open Wildfire Analysis Report under DEVICE>NETWORK>Wildfire Submissions, “500 internal server error” is shown and I cannot check the report. I searched through LIVEcommunity, tech docs, knowledgebase and even Reddit but it seems no one is confronting...

OWET2501 by L0 Member
  • 2201 Views
  • 1 replies
  • 0 Likes

XFF

Hi I am hosting a website behind ngfw. The traffic comes from google load balancer, and i would like to LOG ONLY the x-forward IP (the original). I have used this kb: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs But my URL filtering logs a...

chens by L3 Networker
  • 1317 Views
  • 1 replies
  • 0 Likes

Global protect "certificate is not singed by CA" not allow to connect time to time

We have global protect version 6.1.1-5 When we connect to the GP it's working fine. Once we connect to another firewall's GP and disconnected from it and try to connect again to same firewall then we get the error "certificate is not singed by CA" For example : Let's assume Site A is having a firewall cluster and Site B is having a firewall cl...

polycom会议电话流量经过palo alto防火墙,发现会议到达16分钟左右会断开连接

如上面所说,当流量跳过防火墙是连接同一台交换机,状态正常,专线网络,没有做nat,会话保持时间也是默认的3600,尝试过override 策略,流量也匹配正常,但是情况还在,抓包分析,流量建立了三次握手以后,后续会出现超时的流量,网络层是正常的,不明白会有超时的数据,有人碰到过吗,有什么解决建议。

zhangfw_0-1697776779864.png
zhangfw_1-1697776863671.png
zhangfw by L1 Bithead
  • 1289 Views
  • 1 replies
  • 0 Likes

Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade

Hey all,Recently step-upgraded Panorama from 9.1.14-h4 to 10.2.4-h4. No issues upgrading Panorama. This panorama manages 180+ remote site firewalls. Ever since the upgrade we have *a few* remote site firewalls that are failing to commit properly in 2 ways: 1. commit failures related to particular configuration items, mostly specific interfaces a...

chantilly-error.PNG
MicrosoftTeams-image (2).png

Customer Firewall Transfer

Hello Guys, I am new on the Palo Alto Environment, i work a lot with Fortinet. So in the Fortinet "world" i can register an account like a customer and require for try some of their products, like FortiEMS, FortiOS VM, FortiAnalyzer Etc, all of this for free, without any comercial relationship. So what i want to know is that if there is somethin...

  • 1586 Posts
  • 61 Subscriptions