Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4728 Views
  • 0 replies
  • 1 Likes

Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade

Hey all,Recently step-upgraded Panorama from 9.1.14-h4 to 10.2.4-h4. No issues upgrading Panorama. This panorama manages 180+ remote site firewalls. Ever since the upgrade we have *a few* remote site firewalls that are failing to commit properly in 2 ways: 1. commit failures related to particular configuration items, mostly specific interfaces a...

chantilly-error.PNG
MicrosoftTeams-image (2).png

Customer Firewall Transfer

Hello Guys, I am new on the Palo Alto Environment, i work a lot with Fortinet. So in the Fortinet "world" i can register an account like a customer and require for try some of their products, like FortiEMS, FortiOS VM, FortiAnalyzer Etc, all of this for free, without any comercial relationship. So what i want to know is that if there is somethin...

How to limit youtube with QoS max bandwidth?

Hi experts, Palo alto qos is my first time. So i have a task to limit maximum bw for youtube in my company is just 10 MB. Can i assume to config : guarantee bw : 0 max bw : 10 I assume with that config, i didn't reserved any bw for youtube but if youtube reach more than 10 MB, palo will drop the traffict, is that right? I do this becaus...

Source and Destination NAT for Site to site VPN

Hello, I'm trying to configure a site-to-site vpn with between two organizations. Our internal IP range is conflicting with the other organization network, so we are trying implement Source and Destination NAT The VPN tunnel is up, but I'm struggling to NAT Source and Destination. Route : 172.25.255.0/29 via Tunnel.50 The NAT...

Capture.JPG
Capture1.JPG
Tunnel.JPG
FLOW.JPG

Resolved! Link Group with Subinterfaces

Dear all,I'm trying to set up our link monitor configuration in our 440, and I ran into a problem. Each of our physical interfaces has many subinterfaces and I only want to monitor a few of those, but when I want to form a new Link Group it doesn't allow for subinterfaces to be chosen, just physical interfaces. Is there a way in which I can form...

mR00t_s5 by L2 Linker
  • 2944 Views
  • 3 replies
  • 0 Likes

Resolved! PA5220 to Version 10.25

Good Day to All, I have a Firewall PA 5220 running on A/A setup. Initially it is running on 8.1.4 version and just recently we have upgraded to 9.1.16 version. Since 9.1.16 version will be EOS by Dec 13, 2023 we plan to upgrade it to 10.2 version. Questions: 1. Is PA5220 capable of being upgraded to 10.2.5* preferred version? 2. What wo...

DNS routing issue - OpenVPN inside GlobalProtect VPN

Hi, We are running on a setup today where the client connects through L2TP to a Mikrotik-router and then connects with OpenVPN to the next environment. Just now we are switchning to PA440 and GlobalProtect VPN IPSec instead of L2TP, and we have a problem now that the DNS lookup is not working when on the OpenVPN-tunnel inside the GlobalProte...

Resolved! PA-5430 HA1 interface 10G SFP+ support?

hi I would like to know if the PA-5430 HA1 Interface supports 10G. The datasheet says 1G."1G SFP high availability (2), 40G QSFP+ high availability (1)," It is listed as 1G/10G on the PA-5400 Series Front Panel page.Two SFP+ 1Gbps/10Gbps ports for high availability (HA) control. Thank you.

sungbok by L1 Bithead
  • 5029 Views
  • 3 replies
  • 0 Likes

Migration assistance PA-5050 to PA-3420

Hi, I need assistance replacing a firewall cluster PA-5050 and standalone panorama by a firewall cluster PA-3420 and a cluster panorama. Actually the firewall cluster PA-5050 and standalone panorama are in production. The templates network is manage in locally PA-5050 and the devices group is manage by panorama. The new cluster PA-3420 is UP b...

Active/Passive FW with Primary/Backup ISP

Hi My ISP will provide an Internet access with primary access and backup access. We have an HA Active/Stand-by firewall. The primary Internet access will be directly connected on active FW and the backup Internet access will be connected on interface on stand-by FW as showing in the following diagram. My questions are : - How I must configure ...

jeromecarrier_0-1696920457143.png

Mitigation for DHCP Starvation attack in shared network zone (e.g.Eduroam)

Hi everyone, Is there anyway for us to utilize Palo NGFW to prevent or mitigate DHCP starvation attack. For example, a user's BYOD device is infected with malware, after authenticated with eduroam network, the device start performing DHCP starvation attack without the user even realize. I have tried looking online for solutions, there's re...

LuckyLau by L1 Bithead
  • 2362 Views
  • 1 replies
  • 0 Likes
  • 1620 Posts
  • 61 Subscriptions
Top Solution Authors