Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4725 Views
  • 0 replies
  • 1 Likes

Upgrade 10.1.10-hx to 10.2.4-hx

Is there any good reason for me not to upgrade some 5220 series Firewalls from 10.1 to 10.2? One of the reasons I would sort of like to do this is to eventually get waste deep in some ML stuff. Will I break anything at this point? We are running GP 6.0.5 at the moment (about to jump to 6.0.7) as well.

birkhojk by L2 Linker
  • 1908 Views
  • 3 replies
  • 0 Likes

Resolved! In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?

We have over 200 users on a network, and IP addresses are assigned using DHCP. However, we have a customer request to allow internet access on ports 80 and 443 for specific individuals(may be 50 or more) via the Paloalto firewall. Please review and confirm the various configuration options.

shivunrp by L1 Bithead
  • 3398 Views
  • 5 replies
  • 0 Likes

Using AUX port as management port

Hello everybody, I'm configuring a pair of PA5250 in active/standby high availability mode. Since we have no RJ-45 ports on our switches, I would like to use one of the AUX ports as the management port in place of the default MGT RJ-45 port. We are using 10 Gbps SFP+ transceiver (long range, single mode fiber), and the AUX-1 configured as th...

grenzi by L3 Networker
  • 3882 Views
  • 3 replies
  • 0 Likes

Lost NGFW PA CLI superuser password

Hello. I have a question and I don't know if someone could help me with it. I have 2 users on the Palo Alto firewall is a PA220 One of them that CLI superuser and I don't remember the password The other one I have access to is admindevice but it won't let me create users via the GUI I have tried to take a copy of the firewall configuration,...

ccortijo by L2 Linker
  • 2998 Views
  • 4 replies
  • 0 Likes

PA-3430 Oracle Session Drop

We have multiple application servers that need to go through the firewall to access different oracle database servers, but after the recent replacement of the PA-3430, one of the application servers accessing the Oracle database session is unstable, and the other application server accesses other Oracle database servers through the firewall. Suc...

Global Protect Satellite over 2 ISP's

Hi, We have multiple branches connecting to a data center via Global Protect satellite connections. This works perfectly fine. We've now started installing redundant Internet links but I'm experiening issues with the GP Satellite config. Obviously, when you configure the Satellite IPSec tunnel, you need to specify the interface from which you...

rudiGQ by L0 Member
  • 1963 Views
  • 1 replies
  • 0 Likes

Resolved! Can't define Forward Trust certificate

Hello, We have a new firewall, PA-460 model. The panos version is 10.2.4-h2. I have a problem for define the Forward Trust certificate for the decryption. The certificate i want to declare for Forward trust is a root certificate of our domain. I import the certificate with is private key in pkcs12. When i check the case "Forward Trust Certifi...

CHARRIER by L2 Linker
  • 3882 Views
  • 5 replies
  • 0 Likes

Allowing only low-risk of a url category

Hello everyone, I have a requirement to adjust security policies in a way that only "white list" logic is enabled, and for one specific rule I have to allow only the low-risk category of given url category, for example training-and-tools, and not high-risk and medium-risk. However, the rule should not block the medium and high risk of trainin...

Shams.G by L0 Member
  • 3776 Views
  • 3 replies
  • 0 Likes

BGP peeering

Trying to setup a Two BGP session with 2 separate routers that provide internet access.The 3 devices (PA, router1 and router2) share the same network 10.9.9.0/25.BGP session 1 : PA <--> Router1BGP Session 2: PA <--> Router2the two sessions seems working fine when activating them individually, however when trying to establish the 2 se...

Resolved! UserID to be used in security policy - FW not offering user/group list

Hi, I have problem with User-ID not being selectable when creating/editing security policy rule. Setup is as followed: branch firewalls connected to Panorama Firewall 3400 with 10.2.4 software LDAP server configured Authentication profile configured Included groups in "user identification" configured User-ID configured (i am seeing domain\u...

szi7443 by L1 Bithead
  • 3617 Views
  • 5 replies
  • 0 Likes
  • 1621 Posts
  • 61 Subscriptions
Top Solution Authors