Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4551 Views
  • 0 replies
  • 1 Likes

Resolved! App ID base load balancing dual isp

Hi, I have 2 ISP links failover mode. I wants Lan users Apps base traffic forwarding . For example all users whatsapp and instragam traffic forwarding backup isp path, and others content will passing primary path. Is it possible to forwarding if possible what is the procedure.

Resolved! Problems with URL-DB (it's missing!)

Hi! We've been having on going issues after an upgrade (since downgraded) with our standby firewall - when made live it only functioned at about 10% (i.e. most legitimate traffic was blocked for one reason or another). We fixed an issue with DNS resolution - apparently the domain string being present broke DNS resolution(!), but there remains ...

Block File upload on facebook Messager and instagram

I get a request to allow users to access facebook and allow users to use text chat and comment only. If users want to upload or send files, the firewall has to block them. Instagram as well, does not allow users to upload anything, but they can log in view, and comment. I have configured SSL Description, created a policy to allow facebook-chat...

PAN-OS XML API filtering question

Does the PAN-OS XML API for Global Protect previous users have a time filter option? I didn't see one documented. This query returns all previous users in the firewalls logs, but really I just want the last hour: https://<firewall _address>/api/?type=op&cmd=<show><global-protect-gateway><previous-user/></global-pr...

mgreer by L1 Bithead
  • 1774 Views
  • 1 replies
  • 0 Likes

URL Filtering Categorisation Justification

Hi! We're running URL filtering on our PanOS campus firewalls and I very often get asked to add domains to our 'allow list' - almost always because they're newly registered domains. On occasions we've had sites requested that fit into more serious categories - the latest being 'grayware'. These are very often personal web sites used for teachi...

Resolved! HA Port on PA-5220

Dear All, Is there any way to see the physical status of the HA1 Port through CLI or GUI ? HA1-A and HA1-B —Ethernet 10Mbps/100Mbps/1000Mbps ports used for HA1 traffic in both HA Modes. For HA1 traffic —Connect the HA1-A port on the first firewall directly to the HA1-A port on the second firewall in the pair or connect them to...

Export Management Permitted IP Access List

I have been looking through posts but cannot seem to find what I am looking for. There are some Management Interface Permitted IPs on our Firewalls that do not match the Template that we have for them in Panorama. Is there a CLI command where I can export the Permitted IP list for a firewalls' Management access? From the GUI there doesn't seem...

NelsonE3 by L0 Member
  • 6209 Views
  • 1 replies
  • 0 Likes

any suggestion to replace current PA3020?

Hi. we are planning to replace/upgrade current PA3020 to a newer PA model. could you please suggest which model is the best suitable with my requirement below? thank you. Current PA3020 Setup Info - using 5 virtual routers - using aggregate interfaces - as Internet Gateway - as small Data Center Gateway (AD, some storages and a few apps) - aro...

zinkt101 by L1 Bithead
  • 5604 Views
  • 4 replies
  • 0 Likes

Resolved! PA-850 Management port

Hi. I'd like to configure a PA-850's management port to use DHCP via the CLI using 10.2. All of the information I can find only shows how to set the standard interfaces to either an ip or dhcp, but not the management interface. Does anyone know if that is even possible? Even ChatGPT wasn't helpful 🙂

Kevin407 by L1 Bithead
  • 5003 Views
  • 7 replies
  • 0 Likes

Why Management interface do query instead of DNS-Proxy Interface

Hi Team, I configured DNS proxy Interface e1/1 - 192.168.29.245 to clientless vpn. DNS-Proxy resolves as, General browsing resolves with DNS 8.8.8.8 and 1.1.1.1 Tutelartechlabs.com resolves with DNS 1.1.1.2 and 4.4.4.4 Amazon.forest.in (internal-application) resolves with DNS 172.30.30.31 Note: DNS-Proxy interface is the interface that act...

LC1.jpg
LC2.jpg
LC3.jpg
LC4.jpg

What problems or vulnerabilities does this present?

IMPORTANT NOTE: Never set both checkboxes "Forward Trust Certificate" and "Forward Untrust Certificate" in the same certificate, and do not have the "Forward Untrust Certificate" deployed under a trusted certificate chain. If you do this, it will cause the firewall to present client devices with a CA certificate they trust, even when they connec...

Vulnerability Protection Profile action drop, but still forwards packets

Hello, A customer has a Palo Alto perimeter firewall and a Fortigate DCFW which sits behind the PA in the line of traffic when incoming from the internet . It has been observed that in a scenario when the Palo Alto firewall which has SSL Inbound inspection enabled for all internet facing applications and the vulnerability protection signatur...

Aamirjan by L1 Bithead
  • 4740 Views
  • 4 replies
  • 0 Likes

Adding an External Dynamic List Object and importing the Intermediate CA certificate from the external web server that the EDL is hosted on

I am trying to add an External Dynamic List to our PA-440. The External Dynamic List is hosted on an external web server by one of our security partners. This web server is https enabled and authentication is via username/password. This is the screenshot when you go to the EDL's Source URL: According to this documentation, in order for...

thivye_1-1676501196399.png
thivye_2-1676501218691.png
thivye_3-1676501263508.png
thivye_8-1676501297085.png
user9891 by L0 Member
  • 3020 Views
  • 1 replies
  • 0 Likes
  • 1588 Posts
  • 60 Subscriptions