Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4554 Views
  • 0 replies
  • 1 Likes

Resolved! PA-415 Multiple interfaces into one VLAN

Hello ALl, I am hoping somebody can help with my configuration as I seem to be stumbling and hitting a brick wall the whole week. The firewall is a PA-415 running SW 11.0.0 Ethernet 1/1 is set as a WAN interface. Ethernet 1/2 = no configuration Ethernet 1/3 = no configuration Ethernet 1/4 = 192.168.4.1 / 24 [Set as default LAN, layer 3] Ethern...

Custom URL filtering policy

we created two custom policies where some listed URLs or domains will allow on specific workstations and others will be denied. After implementing these policies we found that listed allow list URLs or websites can be accessible but end users only can see the website content without Images. We had a support call with PA team but didn't resolve t...

a_Islam by L0 Member
  • 1816 Views
  • 3 replies
  • 0 Likes

PA-820 Interface configured but down

As the title states. I have an interface on PA-820 that shows "configured but down". This is really silly but I know the interface was "switched off" by another network admin. Under Advance --> LinkState is set to Auto already. There is some other setting that put the interface in a non-workable state which I just cannot find it.

ITBrute by L0 Member
  • 5118 Views
  • 3 replies
  • 0 Likes

System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP"

Hi, I've been receiving many system alerts with the message: opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile '', vsys 'vsys1', From" "Public IP" eventid: auth-fail It looks like these public IP's are trying to access our internal network by coming through Global Protect App. Coming from many differ...

roma by L2 Linker
  • 4818 Views
  • 1 replies
  • 0 Likes

Many system event about "ha2-link-change" that made HA2 status was down from 23:02:35 (19/Nov/2022) until 17:29:11 (20/Nov/2022) ,HA2 status is Up

Hi Guys, During weekend I found many system event about 'ha2-link-change' on Firewall event that was generated more 1400++ events/periods and send more email notification.This events was occurred for 2 periods that made HA2 status was down from 23:02:35 (19/Nov/2022) until 17:29:11 (20/Nov/2022) ,HA2 status is show Up .First time at 23:0...

Jirapan by L1 Bithead
  • 2907 Views
  • 2 replies
  • 0 Likes

Resolved! Palo Alto GlocalProtect VPN

Hi All, Currently, we have Palo Alto global protect VPN client ver 5.x. Can we upgrade to VPN client 6.2 directly from version 5.x? Also, does VPN client 6.2 supports PAN-OS 9.1.16? (This is the machine we are running GlobalProtect Portal and GlobalProtect Gateway)

Does VM Series-Trial Support VMware Workstation ?

HI Guys I have registered and got a VM-Series Trial for 30 days from this link. https://www.paloaltonetworks.com/vm-series-trial I clearly understand that the guide says the Hypervisor Supported are VMware ESXI. But I want to use it in my VMware workstation. I have downloaded ovf template and installed it on the Workstation. the installation w...

AriqAziz_0-1688287839598.png

Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ?

Hi all, Can I check with you the following Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ? If yes, May I know which released signature version and threat id is covered for this vulnerability? Vulnerability Details: Title Fortinet Pre-authentication Heap-base...

http-req-user-agent-header

Hello, SSO is requesting to me to add a rule on policy to alert http request without user-agent (empty) on header. i know I can use vulnerability by adding a condition when « http-req-user-agent-header » is equal to a regex. i tried to use the regex .*$ and negate but it don’t work. Can you help me on the good regex to add ? BR

Resolved! Device Gropus: How to see previously devices

Hi,We got an RMA, but for the new fw there has not been selected any devices. It was a lot back and forth when trying to set up and add the new fw to Panorama, so in the process the old fw has been deleted from Panorama.Does anyone know if there is possible to see or find out which devices that have previously been selected in the different devi...

  • 1589 Posts
  • 60 Subscriptions