Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP"

Hi, I've been receiving many system alerts with the message: opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile '', vsys 'vsys1', From" "Public IP" eventid: auth-fail It looks like these public IP's are trying to access our internal network by coming through Global Protect App. Coming from many differ...

roma by L2 Linker
  • 5026 Views
  • 1 replies
  • 0 Likes

Many system event about "ha2-link-change" that made HA2 status was down from 23:02:35 (19/Nov/2022) until 17:29:11 (20/Nov/2022) ,HA2 status is Up

Hi Guys, During weekend I found many system event about 'ha2-link-change' on Firewall event that was generated more 1400++ events/periods and send more email notification.This events was occurred for 2 periods that made HA2 status was down from 23:02:35 (19/Nov/2022) until 17:29:11 (20/Nov/2022) ,HA2 status is show Up .First time at 23:0...

Jirapan by L1 Bithead
  • 3014 Views
  • 2 replies
  • 0 Likes

Resolved! Palo Alto GlocalProtect VPN

Hi All, Currently, we have Palo Alto global protect VPN client ver 5.x. Can we upgrade to VPN client 6.2 directly from version 5.x? Also, does VPN client 6.2 supports PAN-OS 9.1.16? (This is the machine we are running GlobalProtect Portal and GlobalProtect Gateway)

Does VM Series-Trial Support VMware Workstation ?

HI Guys I have registered and got a VM-Series Trial for 30 days from this link. https://www.paloaltonetworks.com/vm-series-trial I clearly understand that the guide says the Hypervisor Supported are VMware ESXI. But I want to use it in my VMware workstation. I have downloaded ovf template and installed it on the Workstation. the installation w...

AriqAziz_0-1688287839598.png

Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ?

Hi all, Can I check with you the following Fortinet Pre-authentication Heap-based Buffer Overflow Vulnerability (CVE-2023-27997) is covered in Palo Alto NIPS Signature ? If yes, May I know which released signature version and threat id is covered for this vulnerability? Vulnerability Details: Title Fortinet Pre-authentication Heap-base...

http-req-user-agent-header

Hello, SSO is requesting to me to add a rule on policy to alert http request without user-agent (empty) on header. i know I can use vulnerability by adding a condition when « http-req-user-agent-header » is equal to a regex. i tried to use the regex .*$ and negate but it don’t work. Can you help me on the good regex to add ? BR

Resolved! Device Gropus: How to see previously devices

Hi,We got an RMA, but for the new fw there has not been selected any devices. It was a lot back and forth when trying to set up and add the new fw to Panorama, so in the process the old fw has been deleted from Panorama.Does anyone know if there is possible to see or find out which devices that have previously been selected in the different devi...

Using XFF for Logs Only

Hello, I have an application behind a WAF, without XFF the source IPs are always my WAF and for auditing reasons I need to get and log the real client IP addresses. Traffic flow is like this: Client -> WAN -> NAT -> DMZ - App Server My security policy only allows the communication from internal IP addresses, in this case the priva...

Security rule with URL category mixed up

Hello, We have a weird rule in our Security Rules list. Basically it's allowing any to any with some specific applications, but also a custom URL Category in "Service/URL Category" tab. So normally it should allow only the traffic hitting the URLS in this category. But it's allowing all the traffic actually that is hitting the specific a...

CTramier by L0 Member
  • 1321 Views
  • 1 replies
  • 0 Likes
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors