Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4680 Views
  • 0 replies
  • 1 Likes

Resolved! Threat Intelligence External Dynamic Lists vs URL Filtering Security Profile

Hi All, I have security profiles on my main egress firewall rules, and the URL filtering is blocking anything malware, high-risk etc. I have some custom reports setup that report on any blocks that take place as a result of this profile. I am reading you can also setup firewall rules to block inbound/outbound traffic using sources and destinat...

Panorama fragmentation

Hi,If the checkbox for Fragmented traffic is uncheck, does that mean that the fw will not discard fragmented traffic? I have a case where someone says "10.154.74.0/23: We can not send from, or send to, packages bigger than 1472. All ports are defined to 9216 bits. 10.154.74.17 and 10.154.74.34 can be pinged with big packages."I checked the ...

Richard_M_3-1684146287887.png
Richard_M_2-1684146274804.png

Interface Monitoring

We have total 3 Interface , two ISP interface ( In router we have made them to act as Primary and Secondary) and one trust interface , now the confusion is I am trying to make if both ISP interface goes down , I need to make my trust interface also to goes down automatically by some monitoring feature. Is it possible to do that in Palo-Alto

Sujanya by L3 Networker
  • 3547 Views
  • 4 replies
  • 0 Likes

Proxy based IPSec tunnel is up but data traffic is not passing thorugh

Hi all, I have some issue regarding ipsec tunnel at Palo alto, IPSec tunnel is up and running well before. Suddenly, data traffic is not working without any changes. When i reinitiate tunnel at PA side, it is working fine. it happens frequently, i'm not sure about the cause, what would it be?. Hope i got some helps. Thanks much. BRs,

Resolved! DUO MFA popup twice for approval login GloablProtect

We configured PA 850 firewall to use DUO for GloablProtect MFA. It works. However, we have an issue. In GloablProtect Gateway Configuration>Agent>Client Settings, if I add a user, for example blin. it works fine. If I add a AD OU, for example Employees, the login user will get two DUO aoorval popup twice. From the DUO Authentication, I...

boblin_0-1683769185596.png
boblin_1-1683769394673.png
boblin by L2 Linker
  • 4561 Views
  • 4 replies
  • 0 Likes

Resolved! problem to download files from Dropbox

We have added dropbox.com to OBJECTS>Custom Objects>URL Category. We can login dropbox online. However, can't download files with these errors: .pdf files are supported but something went wrong or There was an error downloading your file. Any help?

boblin by L2 Linker
  • 5650 Views
  • 4 replies
  • 0 Likes

Resolved! Authentication Sequence problem

I configured DUO Proxy for GloablProtect MFA redundancy on our PA 850 firewall using Authentication Sequence. This post shows how I configured: Configure two duo proxy servers for Palo alto firewall MFA redundancy – Net/PC How to (howtonetworking.com) The problem I have is when the top Authentication profile or DUO Proxy server is down, then t...

boblin_1-1683767742215.png
boblin by L2 Linker
  • 4268 Views
  • 2 replies
  • 0 Likes

New VPN effects on existing VPNs

I am very new to Palo Alto administration, having been a Checkpoint guy at my previous job. At my new job I am tasked with creating a new IPsec site to site VPN with a vendor on our perimeter firewall. There are already several other VPNs running. My question is, when I set up the new VPN, will it have any effects on currently running processes,...

URL Encording issue

I am using URL Block Page.However, there is a part where the & part appears as %26 in a specific URL. ex. I entered abc.d/&uid=B5C61D407 in the browser, but it appears as URL:abc.d/%26uid=B5C61D407 in the block page. Why is this and what can be done to fix it?

WooBak by L0 Member
  • 1503 Views
  • 1 replies
  • 0 Likes

migrating ASA to Palo alto with inline deployment

We are planning to migrate firewall from ASA to Palo Alto . Instead of performing hot cutover , we will install the Palo Alto firewall in-line along with existing ASA firewall using virtual wire interface type. Since we have many security zones on ASA and there are policies to allow access between zones, where can i place the new firewall and ...

Bkrishnamoorthy_0-1683291233455.png

Attempt accessing the active and/or passive firewalls fails with the error "fork failed: No space left on device"

Dear and valuable Live Community Members, I'm wondering if anyone has an issue when trying to access the MGMT interface off the active and/or passive firewalls and getting the error "fork failed: No space left on device" We were never able to access the firewall and in the end, we rebooted both devices to be able to access the management int...

Post OS Upgrade for PA-5220 from 9.1.4 to 10.2.3-h4 Users Started Experiencing Issues with Accessing MS Office 365 Applications Internally

Hi There, Recently, we upgraded the OS on our PA-5220 from 9.1.4 to 10.2.3-h4. Immediately after we upgraded to 10.2.3-h4 our helpdesk began receiving calls from users reporting that they cannot get logged into MS Office365 Applications, it'll never bring them to the MS prompt to input their Office365 email/password it'll just say "Can't reach...

Krystin by L0 Member
  • 2045 Views
  • 1 replies
  • 0 Likes

DNS resolution for management interface not working after upgrade to 10.2.3

Since upgrading our firewalls from 10.2.2-h2 to either 10.2.3 or 10.2.3-h2, any DNS resolution from the management interface is failing. Attempting to ping an FQDN from the CLI results in "ping: cnn.com: System error". I confirmed that the DNS servers configured in Device -> Setup -> Services and the management interface settings in Device...

sskannan by L1 Bithead
  • 5078 Views
  • 2 replies
  • 0 Likes
  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors