Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

Resolved! Palo Alto in Virtual wire vs TAP mode.

Hello,Just wanted to confirm my understanding on the different modes of deployment in PA. Virtual Wire is an INLINE mode ( similar like IPS) and TAP mode is a passive monitoring mode. So does that mean if I find an unlocked rack somewhere and I were to remove the ethernet from the switch/firewall in that rack and instead attach it to lets say et...

Outlook web excessive bandwidth usage

Hello, We recently noticed starting last few weeks that application (outlook-web-online) had a massive data being sent and saturating our internet link. This looks to be across the network as we can identify multiple users with same application traffic being the top bandwidth consumers when we generated the custom report. Does anyone exper...

Marconi by L0 Member
  • 2545 Views
  • 2 replies
  • 0 Likes

Policy Based VPN

All,We are migrating Policy based VPN's from Juniper Netscreen to Palo-Alto firewall. Please let us is Policy based VPN will be supported in palo-Alto , if not how we need migrate the Policies of Policy based VPN.

Sujanya by L3 Networker
  • 14146 Views
  • 3 replies
  • 0 Likes

Whatsapp File transfer Block

i work as a security specialist engineer at a moderate enterprise.recently my superiors have asked me to block whatsapp file transfer only(meaning chat would still work).however i've tried anything using our Fw's but to no avail. from what i have read on some forums and various sources, i need to url block mmi.whatsappmms and mmv..i tried doing ...

High Bandwidth Utilization & Data Plane Restart

We have a 5220 running 9.1.12-h3, and it has a 10 Gb vwire with multiple VLANs configured with managed switches on both sides. There was a 13 Terrabyte copy across this vwire, and then as that was finishing, there was a 3 Terrabyte data copy. Both were sources from the same side of the vwire, and both towards (destination side of vwire) servers ...

Resolved! Advanced threat protection_Deep Learning

Hi, PAN OS Version 10.2 support Advanced threat protection and its seems like , for any unknowns the metadata will be forwarded to cloud for deep learning mechanism (Correct me if i am wrong). My coroners are how can we check what details has been uploaded to cloud for deep learning? what action that firewall will take until the verdict is ret...

Resolved! Path monitor setup using tunnel interface

Setting up a path monitor on a static route where source is a tunnel interface. I am able to ping from CLI with tunnel interface IP as source. But the route does not get installed. ping source 10.0.0.1 host 4.2.2.2PING 4.2.2.2 (4.2.2.2) from 10.0.0.1 : 56(84) bytes of data.64 bytes from 4.2.2.2: icmp_seq=280 ttl=57 time=21.4 ms64 bytes from 4...

image.png
raji_toor by L4 Transporter
  • 4687 Views
  • 2 replies
  • 0 Likes

Can't ping a PaloAlto interface

I am new to Palo Alto firewall. I have loaded Pan-OS 9 on eve-ng and connected one of it's port to router. It is layer three connectivity and have assigned ip to both ends. However I can't ping the firewall interface. OSPF neighborship is also not forming. Can someone help please.

jasamit by L0 Member
  • 4684 Views
  • 1 replies
  • 0 Likes

Routing question

I might be overlooking something fundamental. We are trying to slow-step out of another firewall into a PA. I have created an interface on the PA in the old subnet. I can ping across to the server and old firewall. Clients behind the PA cannot get a DHCP address. I am wondering if trying to maintain the same subnet on a Legacy VLAN will even...

  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors