Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4680 Views
  • 0 replies
  • 1 Likes

Integrating 3rd Party feeds in Palo Alto firewall for blocking IOC's

We would like to know if we can integrate 3rd Party feeds in Palo Alto firewall for blocking IOC's automatically. Generally we seen people integrate Open Source threat intel with SIEM etc with Virus total and IBM Xforce xchange https://www.dshield.org/block.txthttps://blocklist.greensnow.co/greensnow.txtOpen source threat intel to block IOC's au...

Resolved! 802.3bz multi-gig 2.5

march2023 and 802.3bz devices are arriving from ISPs, (eg comcast CGA4332COM) where is the compatibility/forecast/roadmap from PAN? After searching high and low i found zero content from PAN on this topic... if you have info post here and share with other members. https://en.wikipedia.org/wiki/2.5GBASE-T_and_5GBASE-T

Resolved! User ID (with Windows Agent) not working

Hi, we set up User ID based on these docs: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent Konfiguration and installation is working: - the agent installed on serve...

Resolved! Can we use 10GbE SFP+ on PA-3220 to connect directly to NetApp SAN over optical connection

Hey all. We're kind of in a bind. We procured a NetApp AFF A220 SAN that only have 10GbE optical transceivers for data access. We have no network hardware (no fabric or network switch) that support 10 gigabit except potentially our PA-3220 that have 4 x SFP+ ports capable of 10GbE. Is it possible to connect the SAN directly to the SFP+ ports o...

Resolved! App ID base load balancing dual isp

Hi, I have 2 ISP links failover mode. I wants Lan users Apps base traffic forwarding . For example all users whatsapp and instragam traffic forwarding backup isp path, and others content will passing primary path. Is it possible to forwarding if possible what is the procedure.

Resolved! Problems with URL-DB (it's missing!)

Hi! We've been having on going issues after an upgrade (since downgraded) with our standby firewall - when made live it only functioned at about 10% (i.e. most legitimate traffic was blocked for one reason or another). We fixed an issue with DNS resolution - apparently the domain string being present broke DNS resolution(!), but there remains ...

Block File upload on facebook Messager and instagram

I get a request to allow users to access facebook and allow users to use text chat and comment only. If users want to upload or send files, the firewall has to block them. Instagram as well, does not allow users to upload anything, but they can log in view, and comment. I have configured SSL Description, created a policy to allow facebook-chat...

PAN-OS XML API filtering question

Does the PAN-OS XML API for Global Protect previous users have a time filter option? I didn't see one documented. This query returns all previous users in the firewalls logs, but really I just want the last hour: https://<firewall _address>/api/?type=op&cmd=<show><global-protect-gateway><previous-user/></global-pr...

mgreer by L1 Bithead
  • 1827 Views
  • 1 replies
  • 0 Likes

URL Filtering Categorisation Justification

Hi! We're running URL filtering on our PanOS campus firewalls and I very often get asked to add domains to our 'allow list' - almost always because they're newly registered domains. On occasions we've had sites requested that fit into more serious categories - the latest being 'grayware'. These are very often personal web sites used for teachi...

Resolved! HA Port on PA-5220

Dear All, Is there any way to see the physical status of the HA1 Port through CLI or GUI ? HA1-A and HA1-B —Ethernet 10Mbps/100Mbps/1000Mbps ports used for HA1 traffic in both HA Modes. For HA1 traffic —Connect the HA1-A port on the first firewall directly to the HA1-A port on the second firewall in the pair or connect them to...

  • 1605 Posts
  • 61 Subscriptions
Top Solution Authors