Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4685 Views
  • 0 replies
  • 1 Likes

Resolved! PA-5400 Series Port HA1 Down every time there is an upgrade

Hi everyone, I found a problem every time we upgrade the PA-5420 firmware. After the device reboots, port HA1 is always down. I tried to find the relevant logs. It could not find any reason for this happening. Has anyone encountered this kind of problem? I want to know what is the root cause of this problem. We directly connect Active and Pass...

Resolved! BGP peering over virtual-wire interface

Hello, I have existing eBGP connection between 2 routers, layer3 connectivity is done with vlan going customer side and with /30 IP address they are peering. My question is that if i pass this BGP peering on Palo-Alto firewall with Virtual-Wire interfaces. Will I be able to see the prefix customer side of peer announcing or will I only see t...

Memmed by L0 Member
  • 2826 Views
  • 2 replies
  • 0 Likes

Resolved! Response status error code 403 while using api

Hello all. I'm trying to get started with some API work on my PAN OS. I walked through the Getting Started guide and I created a user, assigned an admin role to it that had API access, and then generated a key.While I am using curl -k -X GET "https://a.b.c.d/api/?type=op&cmd=<show><system><info></info></system>&...

ssovee by L2 Linker
  • 20083 Views
  • 4 replies
  • 1 Likes

ChatGPT and Chromium Browser issues

Hey all,Specific scenario here wondering if anyone else has seen so far. In our organization we have SSL Decrypt/Break and Inspect enabled using a self signed cert and SSL Forward Proxy. We have also implemented a custom Continue Response page just to acknowledge some risk of using ChatGPT. In FireFox and Safari, if a user navigates to cha...

Is there tool available to sync the config from physical Paloalto on-premise the disaster recovery site in Azure?

We have onpremise network and paloalto firewalls and zone base zero trust config and we want to have the DR in Azure on virtual firewalls and looking for the way to convert and sync the config from on-premise physical firewalls to Azure virtual firewalls. I know there are some magic need to be done to convert vlans to subnets/vnets and update al...

Facing packet dropping issue after imported configuration.

The issue is currently planning to migrate PA220 to PA440. We have imported the configuration file from PA220 to PA440, The network is down and facing packet drops Then we disabled the HA and disabled the ECMP configuration, but the same issue persists. We took a backup from PA220 and then imported it to PA440 after 6 hours we faced a packet d...

PAN-OS NGFW - LDAP Authentication via Group Membership - Admin UI

Hello, I'm trying to set up NGFW in a lab environment where all users have an account defined in a centralized authentication store. We're using FreeIPA, which provides authentication services via LDAP and Kerberos. I've gotten authentication working with LDAP, but it requires specifying a unique Administrator account and then pointing it to...

PBF based on URL Filtering/Application

hi everyone, We have a PBF Rule allow all internal users to internet via our ISP1. And I want to create another PBF rule on top of the above PBF rule to allow Instagram application traffic towards ISP2? I look through the below KB but it is not doable: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clq1CAC So i wan...

LeoLion by L0 Member
  • 3511 Views
  • 5 replies
  • 0 Likes

URL Category behavior with rule match condition question

I came across behavior that confused and concerned me recently. I had a test rule with the following conditions set: Source Zone (LAN) Source user Destination Zone (WAN) Application (ANY) URL Category (not in Profile/Action section, but in Service/URL section) I was under the understanding that the URL Category is part of the match condition ...

Traffic: Logs and Indexes and Current Retention

Found our that our FW1 only able to keep 4 days of traffic logs but took more space than FW02 which able to log up to 15 days ( previously FW2 in active for around 2 weeks+) FW01 FW02 Disk usage: traffic: Logs and Indexes: 34G Current Retention: 4 days threat: Logs and Indexes: 18G Current Retention: 6 days system: Logs and Indexes...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors