Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4593 Views
  • 0 replies
  • 1 Likes

What problems or vulnerabilities does this present?

IMPORTANT NOTE: Never set both checkboxes "Forward Trust Certificate" and "Forward Untrust Certificate" in the same certificate, and do not have the "Forward Untrust Certificate" deployed under a trusted certificate chain. If you do this, it will cause the firewall to present client devices with a CA certificate they trust, even when they connec...

Vulnerability Protection Profile action drop, but still forwards packets

Hello, A customer has a Palo Alto perimeter firewall and a Fortigate DCFW which sits behind the PA in the line of traffic when incoming from the internet . It has been observed that in a scenario when the Palo Alto firewall which has SSL Inbound inspection enabled for all internet facing applications and the vulnerability protection signatur...

Aamirjan by L1 Bithead
  • 4882 Views
  • 4 replies
  • 0 Likes

Adding an External Dynamic List Object and importing the Intermediate CA certificate from the external web server that the EDL is hosted on

I am trying to add an External Dynamic List to our PA-440. The External Dynamic List is hosted on an external web server by one of our security partners. This web server is https enabled and authentication is via username/password. This is the screenshot when you go to the EDL's Source URL: According to this documentation, in order for...

thivye_1-1676501196399.png
thivye_2-1676501218691.png
thivye_3-1676501263508.png
thivye_8-1676501297085.png
user9891 by L0 Member
  • 3082 Views
  • 1 replies
  • 0 Likes

Palo Alto PA-3400 Series degraded specs vs 3200 Seires

Dear Palo Alto CommunityIs it just me, or did Palo Alto drop the ball on the new PA-3400 Series, while almost all specs gained an improvement over the old 3200 series. There is the value of Security-Zones that has me deeply confused/puzzled. For the sticker price (whether it is list price or street price). Having a PA3410 with a max of 40 Securi...

PA-comparison.png
PA-3400-performance.png
AlexNC by L3 Networker
  • 10168 Views
  • 4 replies
  • 1 Likes

Resolved! Suspicious Code in GIF File Detection - Logic of Detection

Good Day Team! I hope You are all doing well! We have a detection re: a remote ip attempting to connect to a certain server which hit the rule Suspicious Code in GIF File Detection. We have blocked the ip, however, the detection has: Threat Category: downloader PA Subtype (custom): spyware wherein we are currently in a dilemma if the former reme...

Palo Alto and Forescout

Hi, I have both Paloalto firewall and Forescout in our organization. This is my current setup. 1.) Forescout handling the grouping for our wireless devices (BYOD). 2.) Paloalto policy is incorporated through user mapping (Active Directory) 4.) I already setup the connection between the paloalto and forescout. Is it possible that the wireless d...

bundle gre tunnels and distribute internet traffic across them

Has anyone had a location with more than 1Gbps internet link and also have Zscaler? The limitation to Zscaler is 1Gbps gre tunnel. We have a 10Gbps link and this doesn't work. We have to create 5 nats across 2 routers behind a firewall to build 10 GRE tunnels. I wanted to do something similar at the edge with palo alto but i am not seeing what i...

Resolved! Palo Alto in Virtual wire vs TAP mode.

Hello,Just wanted to confirm my understanding on the different modes of deployment in PA. Virtual Wire is an INLINE mode ( similar like IPS) and TAP mode is a passive monitoring mode. So does that mean if I find an unlocked rack somewhere and I were to remove the ethernet from the switch/firewall in that rack and instead attach it to lets say et...

Outlook web excessive bandwidth usage

Hello, We recently noticed starting last few weeks that application (outlook-web-online) had a massive data being sent and saturating our internet link. This looks to be across the network as we can identify multiple users with same application traffic being the top bandwidth consumers when we generated the custom report. Does anyone exper...

Marconi by L0 Member
  • 2480 Views
  • 2 replies
  • 0 Likes
  • 1586 Posts
  • 61 Subscriptions