Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4516 Views
  • 0 replies
  • 1 Likes

Does the Post-NAT Zone for security policy is for Source zone and Destination Zone?

I read the following from the palo alto study guide: A Security policy rule requires a source IP, destination IP, source zone, and destination zone. If you use an IP address in a Security policy rule, you must add the IP address value that existed before NAT was implemented, which is called the pre-NAT IP. After the IP address is translated (p...

Post NAT Zone.png
rmeddane by L2 Linker
  • 9158 Views
  • 2 replies
  • 0 Likes

Demystifying NAT Traversal with VPN IPsec

One of the biggest concepts in VPN Technologies is NAT Traversal, like NAT Traversal in VOIP deployment with SIP Protocol, the story is always inside the payload to solve the Incompatibility between NAT and IPSEC similar to the Incompatibility between SIP protocol and NAT. IPsec uses ESP to encrypt all packet, encapsulating the L3/L4 headers w...

rmeddane_0-1703952217760.png
rmeddane_1-1703952217761.png
rmeddane_2-1703952217767.png
rmeddane_10-1703952217864.png
rmeddane by L2 Linker
  • 19730 Views
  • 0 replies
  • 6 Likes

Full Cone NAT, Restricted Cone NAT and Symmetric RFC NAT Terminologies versus Vendor NAT Terminologies.

When we talk about Stun Protocol used for NAT traversal in voip environment or SDWAN, the common term used when talking about the Type of NAT that is compatible with Stun is “Full Cone NAT”, then when we explain why Turn Protocol is developped to replace Stun Protocol, the most common reason is “Symmetric NAT is not compatible with Stun”. These ...

rmeddane by L2 Linker
  • 5112 Views
  • 0 replies
  • 1 Likes

User ID - Igonere User list

Hi, I have added a few users to the "Ignore USer list" for user-id configuration. But when I checked the User-IP mappings I still see the user-id is mapping the username with IPs even though the usernames are in ignore list. Any suggestions on what to check here?

srikarpuligandla_0-1703226223762.png

Resolved! HA pair not synchronizing

Hi all, I have a PA-220 HA pair without licenses running on PANOS 9.1.13-h3. Recently I had an issue with a HA passive Firewall, so it had to be replaced. I extracted the active firewall's running-config and uploaded it into the new passive one. I was able to synchronize App&Threat version by re-installing the active's FW current version. ...

JuanFelipeAyala_1-1703613361357.png
JuanFelipeAyala_2-1703613751019.png
JuanFelipeAyala_4-1703613921986.png

Can we configure Server monitoring using OpenLDAP

Hi All, Here i have an requirement to configure Server monitoring on Palo Alto firewall with an OpenLDAP server. Iam a bit confused on choosing the type & transport protocol under server monitoring tab. Is it possible to integrate the OpenLDAP with Palo Alto server monitoring..? Please help me to get a clarity on this. Thanks in adv...

Arun_R_0-1703763705633.png
Arun_R by L1 Bithead
  • 809 Views
  • 0 replies
  • 0 Likes

How to decrypt ESP IPSEC packet using wireshark

Sometimes you want to see how the tunnel mode encapsulation occurs, especially when using GRE over IPsec and VTI IPsec and you would like to decrypt the ESP or IPSEC packet to see how packet is encaspulated on both scenarios (GRE over IPsec and VTI IPsec, especially for studying or may be for troubleshooting. Below how to do it: Configue the...

6.png
9.png
2.png
8.png
rmeddane by L2 Linker
  • 9336 Views
  • 0 replies
  • 1 Likes

IPSec VPN Tunnel Interface with IP Addresses

I read the following example of Site to Site VPN IPsec with static routing : https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/site-to-site-vpn-quick-configs/site-to-site-vpn-with-static-routing In the figure the example shown that both Tunnel Interfaces on the peers VPN are 10.10.10.10 and 10.10.10.11 in the same s...

Topo VPN.png
Tunnel.png
rmeddane by L2 Linker
  • 4537 Views
  • 5 replies
  • 0 Likes

Incidents contain many alert types... but why?

Hello, everyone. Our product suite now includes receiving alerts from the NGFW, in addition to XDR. It seems, though, that a single incident may include several different alerts. This seems like a strange behavior, because the list of alerts come from many hosts, or threat type, or threat vector. If the Incidents are grouping unrelated alert...

Shared IP in the WAN Side with HA Active/Active and ARP Load Sharing

Can we confgure the Shared IP in the WAN side in HA Active/Active? Because I read in the PAN OS Admin guide two things: Page 410: As illustrated in the floating IP address scenario, the firewall supports a shared IP addressfor ARP load-sharing only on the LAN side of the firewall; the shared IP address cannot beon the WAN side. In the sam...

PA Shared IP.png
PA Shared IP WAN1.png
rmeddane by L2 Linker
  • 1553 Views
  • 0 replies
  • 0 Likes
  • 1795 Posts
  • 60 Subscriptions