Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4518 Views
  • 0 replies
  • 1 Likes

SCP import file without accept host key

Is it possible that we import file using "scp import" without accept the host key? In ubuntu(UNIX), we can add "-o UserKnownHostsFile=/dev/null" in connection string to avoid storing host key in local machine. I understand that PA's NGFW CLI is not a fully functional shell(bash) as we have in ubuntu. Could we do something similiar to avoid st...

AndyLiao by L0 Member
  • 834 Views
  • 0 replies
  • 0 Likes

SSH\SFTP Proxy

Hello, I'm currently managing an SFTP (SSH) server. I'm attempting to implement file blocking using the NGFW. I've configured a decryption profile that includes "SSH Proxy". According to the traffic logs, the "decrypt" option appears to be activated. However, I'm not observing any files in the data filtering logs, even though logs for other file...

chens by L3 Networker
  • 2372 Views
  • 1 replies
  • 0 Likes

get-ldap-data-failure - LDAP Failover doesn't work

-I had two LDAP servers configured with a firewall, the primary LDAP server had an issue with high CPU and memory due to which the firewall lost the group membership though the firewall has L3 reachability. During the log analysis found that get-ldap-data-failure from Primary LDAP. We manually failed over the LDAP to a secondary one and this r...

How to show the auditing process of objects during policy auditing

Hi Everyone, I'm a new member FW Palo Alto,Currently, I have done a dump of the rule checking process, but I cannot show the process of checking each object against the rules in the firewall, so that I can clearly see the rule checking and the matching of objects before and determines which rule will be selected to handle traffic.For checkpoint ...

ChungNX3 by L0 Member
  • 1238 Views
  • 0 replies
  • 0 Likes

Resolved! PAN-OS Version Release History

Hello Community, How to get the release history (actual date) for the various versions on the PAN-OS? For e.g. I want to know the release date for PAN-OS 10.1.4-h4. Thank you, MKPlease note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or comp...

mkgsgi by L1 Bithead
  • 12153 Views
  • 6 replies
  • 0 Likes

Unable to connect GlobalProtect

GlobalProtect Unable to connect and the web portal showing err_empty_response. Certificate is already installed in the client. PANGPS log: (P2832-T9964)Debug( 929): 12/15/23 09:43:34:892 SSL connecting to x.x.x.x(P2832-T9964)Debug( 487): 12/15/23 09:43:34:892 socket send buffer old size is 65536(P2832-T9964)Debug( 511): 12/15/23 09:43:34:892 soc...

Gourab_H by L1 Bithead
  • 1928 Views
  • 0 replies
  • 0 Likes

Policy match either XFF or layer 3 IPs?

We have load balancers proxying traffic back through a pair of PA5250s and recently started extracting X-forwarded-for data to match in our traffic policies. Is it possible to have rules that match EITHER the XFF IP or the load balancers' proxied IPs at the same time? That is to say, if the load balancer's source is 10.10.10.1 but the XFF sour...

Destination Static NAT vs Source Static NAT with Bidirectional

Static Destination NAT: This NAT Rule allows users on Internet to initiate traffic to access internal or dmz server with a public IP of the server let's say 13.1.1.10. The inbound request has a Layer 3 destination IP 13.1.1.10, the firewal then applies a Destination NAT to translate the this destination IP 13.1.1.10 to the private IP of the serv...

DNAT.png
Capture d'écran 2023-12-14 073550.png
rmeddane by L2 Linker
  • 8087 Views
  • 0 replies
  • 2 Likes

Site-to-Site VPN with Static and Dynamic Routing

I read the following article about Site to Site VPN With Static and Dynamic Routing. https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/site-to-site-vpn-quick-configs/site-to-site-vpn-with-static-and-dynamic-routing The article says that the Satellite Site uses static Routing so the VPN Peer A has a static routes to...

VPN Redi Profile 2.png
VPN Redi Profile 1.png
rmeddane by L2 Linker
  • 2190 Views
  • 2 replies
  • 0 Likes
  • 1795 Posts
  • 60 Subscriptions