Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4685 Views
  • 0 replies
  • 1 Likes

Resolved! In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?

We have over 200 users on a network, and IP addresses are assigned using DHCP. However, we have a customer request to allow internet access on ports 80 and 443 for specific individuals(may be 50 or more) via the Paloalto firewall. Please review and confirm the various configuration options.

shivunrp by L1 Bithead
  • 3359 Views
  • 5 replies
  • 0 Likes

Using AUX port as management port

Hello everybody, I'm configuring a pair of PA5250 in active/standby high availability mode. Since we have no RJ-45 ports on our switches, I would like to use one of the AUX ports as the management port in place of the default MGT RJ-45 port. We are using 10 Gbps SFP+ transceiver (long range, single mode fiber), and the AUX-1 configured as th...

grenzi by L3 Networker
  • 3841 Views
  • 3 replies
  • 0 Likes

Lost NGFW PA CLI superuser password

Hello. I have a question and I don't know if someone could help me with it. I have 2 users on the Palo Alto firewall is a PA220 One of them that CLI superuser and I don't remember the password The other one I have access to is admindevice but it won't let me create users via the GUI I have tried to take a copy of the firewall configuration,...

ccortijo by L2 Linker
  • 2939 Views
  • 4 replies
  • 0 Likes

PA-3430 Oracle Session Drop

We have multiple application servers that need to go through the firewall to access different oracle database servers, but after the recent replacement of the PA-3430, one of the application servers accessing the Oracle database session is unstable, and the other application server accesses other Oracle database servers through the firewall. Suc...

Global Protect Satellite over 2 ISP's

Hi, We have multiple branches connecting to a data center via Global Protect satellite connections. This works perfectly fine. We've now started installing redundant Internet links but I'm experiening issues with the GP Satellite config. Obviously, when you configure the Satellite IPSec tunnel, you need to specify the interface from which you...

rudiGQ by L0 Member
  • 1948 Views
  • 1 replies
  • 0 Likes

Resolved! Can't define Forward Trust certificate

Hello, We have a new firewall, PA-460 model. The panos version is 10.2.4-h2. I have a problem for define the Forward Trust certificate for the decryption. The certificate i want to declare for Forward trust is a root certificate of our domain. I import the certificate with is private key in pkcs12. When i check the case "Forward Trust Certifi...

CHARRIER by L2 Linker
  • 3827 Views
  • 5 replies
  • 0 Likes

Allowing only low-risk of a url category

Hello everyone, I have a requirement to adjust security policies in a way that only "white list" logic is enabled, and for one specific rule I have to allow only the low-risk category of given url category, for example training-and-tools, and not high-risk and medium-risk. However, the rule should not block the medium and high risk of trainin...

Shams.G by L0 Member
  • 3730 Views
  • 3 replies
  • 0 Likes

BGP peeering

Trying to setup a Two BGP session with 2 separate routers that provide internet access.The 3 devices (PA, router1 and router2) share the same network 10.9.9.0/25.BGP session 1 : PA <--> Router1BGP Session 2: PA <--> Router2the two sessions seems working fine when activating them individually, however when trying to establish the 2 se...

Resolved! UserID to be used in security policy - FW not offering user/group list

Hi, I have problem with User-ID not being selectable when creating/editing security policy rule. Setup is as followed: branch firewalls connected to Panorama Firewall 3400 with 10.2.4 software LDAP server configured Authentication profile configured Included groups in "user identification" configured User-ID configured (i am seeing domain\u...

szi7443 by L1 Bithead
  • 3558 Views
  • 5 replies
  • 0 Likes

Can we create a rule to match only the selected application without selecting WEb-Browsing dependency

Dear All, I need a community advice, we are migrating all our Firewalls from Checkpoint to Palo Alto. First Palo Alto was implemented 2 weeks ago, a PA 3420 version 10.2.4-h2 We are trying to transform the imported rules into Palo alto style. For example I want to create a rule to allow only access to "TeamViewer" application for some comput...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors