Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4554 Views
  • 0 replies
  • 1 Likes

Using XFF for Logs Only

Hello, I have an application behind a WAF, without XFF the source IPs are always my WAF and for auditing reasons I need to get and log the real client IP addresses. Traffic flow is like this: Client -> WAN -> NAT -> DMZ - App Server My security policy only allows the communication from internal IP addresses, in this case the priva...

Security rule with URL category mixed up

Hello, We have a weird rule in our Security Rules list. Basically it's allowing any to any with some specific applications, but also a custom URL Category in "Service/URL Category" tab. So normally it should allow only the traffic hitting the URLS in this category. But it's allowing all the traffic actually that is hitting the specific a...

CTramier by L0 Member
  • 1257 Views
  • 1 replies
  • 0 Likes

Tenant ID change on NGFW

Hi all, We have a set of NGFWs that somehow are pointed to an old tenant ID and therefor not dropping the logs into the CDL. We have put in a TAC case but haven't gotten any resolution as of yet. Is there a way in the CLI to change the tenant ID? Or is this a log forwarding profile issue? Any assistance would be helpful.

2 PA-850s and 1 PA-440

Hi,I received a quote from a supplier for 2 PA-850s with Wildfire , Partner enabled premium support and GlobalProtect subscription.Then for the PA - 440 - Wildfire , GlobalProtect , advanced Url filtering , advanced threat protection and premium support.As far as i can tell they want to run 2 separate networks with the same level of protection o...

Calc66 by L1 Bithead
  • 4678 Views
  • 5 replies
  • 0 Likes

Resolved! Palo Alto NGFW: LDAP authentication with DUO/OKTA MFA

Hi, We have a got a new Palo Alto NGFW in our Premises and configured with LDAP for authentication. Things were good with LDAP for authentication until we started looking for MFA. I couldn't find any document to have LDAP and DUO/OKTA for MFA. As this is my first firewall configuration, it hits me so hard. Can someone help me with this? Thanks...

jeromej by L1 Bithead
  • 4611 Views
  • 2 replies
  • 0 Likes

User-ID with Azure AD

Hey all, I've set up User-ID with on-prem AD servers a few times - quite straightforward. My question is, how do I set up User-ID when my customer uses Azure AD (with no on-prem servers)? I need to someone get the user-to-IP mappings on the firewall but pulled from Azure AD but not sure how its done. I did see/hear about the "Cloud Identity En...

Palo Alto New User ID Agent Adding to Firewall

Hi All, We want to add new User ID Agent to our Palo Alto Firewalls and remove the existing user ID Agent from Firewalls. The reason is the current User-ID Agent is hosted on Window 2012 and we are going to decom that Window server. We will install new user ID Agent on new Window Server 2022. We already successfully added new User-ID Agent on Fi...

EvanRaci by L1 Bithead
  • 1542 Views
  • 1 replies
  • 0 Likes

Palo Alto Site to Site IPsec VPN went down

Hi , We've setup Site to Site IPsec VPN between Palo Alto Firewalls. The tunnel was up and working but it went down after some time. Look like the tunnel went down because there is no traffic passing through the tunnel. Everytime we need to trigger IPsec tunnel by using >test vpn ike-sa gateway to bring up. How can we configure the tunnel t...

EvanRaci by L1 Bithead
  • 2555 Views
  • 2 replies
  • 0 Likes

VPN internet access

I have set my VPN access with no split tunnel so the users gets their internet access through the access through the VPN. Even though I cloned the security rule to the internet from the one used when you are onsite, it does not give the same access to those on the VPN and I need access via vpn to be exactly the same as onsite. Let me know if any...

Resolved! Palo PA-450 High Availability ports

Hello everyone, wanted to deploy a pair of PA-450s in HA and I understand there are no dedicated HA ports on this model so we need use data ports - I could not find a deployment guide for the PA-450 to address HA specifically and I assume you could use any data port but does anyone have any experiences when selecting ports for HA? does it matter...

bormanb by L0 Member
  • 6524 Views
  • 3 replies
  • 0 Likes

TCP-RST-from-CLIENT

Hi Friends, We have a requirement we have cloud server Oracle cloud When ever user from LAN tries to access the resources over the cloud user is able to login but unable to access any resources. While checking in logs it is showing tcp-rst-from-client. I am attaching the screenshot and session flow for reference. I am also attaching the wire s...

Screenshot (207).png
Screenshot (209).png
Satyak by L3 Networker
  • 6070 Views
  • 2 replies
  • 0 Likes
  • 1589 Posts
  • 60 Subscriptions