Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4688 Views
  • 0 replies
  • 1 Likes

We are not able to receive the password resetting link

We are not able to login the support.paloaltonetworks.com site. When we try to resetting the password using mail id, we did not receive the password reset link on mail. Kindly help us to resolve this issuePlease note you are posting a public message where community members and experts can provide assistance. Sharing private information such as ...

ISP ping going out via different interface

I am facing a very strange issue. Thee are four ISP connected to PA. All are VLAN interfaces. While doing a ping to 8.8.8.8 or any public IP from the vlan interface IP it works fine except for one ISP. For one ISP if a ping a initiated from vlan.7 the traffic goes out via vlan.3. attached a screenshot. Ping is initiated from PA cli - ping sour...

pingPA.jpg
ceapen01 by L2 Linker
  • 5221 Views
  • 5 replies
  • 0 Likes

Static Source nat, two /24 subnets one to one

I want to know if this is possible, make a Static Source NAT so thatsource network last octet lets say 192.168.1.10 is translated to 10.1.1.10 then next host 192.168.1.11 is translated to 10.1.1.11 and this should happen always only natting last octet, so it does not get mixed and source nat to a different Ip that does not match the last octet. ...

Carlos_N by L1 Bithead
  • 9239 Views
  • 9 replies
  • 0 Likes

Resolved! Decryption exception issue - no SNI - SCN: chat.signal.org

Hi,how to add following decryption error (ssl-forward-proxy) to exceptions? - logs->decryption: dest address: ac88393aca5853df7.awsglobalaccelerator.com (shodan solves this ip /13.248.212.111/ also to service.signal.org; SNI - no value; SCN: chat.signal.org; error: General TLS protocol error - logs->traffic: destination like above; decrypt...

JarerkZajac_0-1655994017023.png
JarerkZajac_3-1655994196320.png
JarerkZajac_1-1655994083091.png
JarerkZajac_2-1655994143220.png

Regarding REST API feasibility

There is a requirement to check the REST API feasibility for the below parameters. Logs will be sent to Monitoring tool through REST API. Could anyone please help on this? Can we achieve below parameters through REST API? CPS CPU Utilization Dataplane CPU Utilization mgmt. plane Global server health Operational mode Packet buffer status Ses...

Routing client vpn over site to site tunnel

Hello everyone, I’m new to palo alto and I have the following problematic that I couldn’t solve. I have PA Firewall in my local site and it’s configured to allow site to site connection to a remote branch which works perfectly. In addition, I’ve set up client to site (to local site) connection and it works perfectly, I can reach all the resource...

John19 by L0 Member
  • 2151 Views
  • 1 replies
  • 0 Likes

Log Collector status", it gives me "Error"

Hello All, From the device-Setup-Management tab, there is "Logging and Reporting Settings". And when I click "Log Collector status", it gives me an "Error" The FW is connected to Panorama and it gets shared policies and objects and it seems like forwarding logs. What is the error indicated in firewall. Kindly suggest on this.

SunilduttJ_0-1672310556548.png

VPN Phase 2 Tunnel stuck

Hi, We have multiple S2S VPN with many vendors but facing issue with Fortinet. On our side we observe Phase 2 tunnel is up and packets are going out through Tunnel interface but no reply. Other party saying no issue on their end but once we restart that Phase 2 Proxy id, it starts working. Just to inform you that we have multiple Proxy ids. a...

ISG-JHAH by L0 Member
  • 3666 Views
  • 3 replies
  • 0 Likes

VM not working in Vmware 6.7

Hello, I am getting desperate :(. I am totally new in PA, this was supposed to be my first VM to lab and play with it. Anyway I have credits and I have OVA file. When I try to deploy it in Workstation on my local PC, it works. When I use the same OVA in our lab environment With VXLANs a Vmware 6.7 (NSX). Its not working at all. I am not able t...

JLoukota by L1 Bithead
  • 3102 Views
  • 3 replies
  • 0 Likes

Resolved! NGFW Telemetry Uploads Failing

We have been receiving critical alerts saying telemetry uploads on all of our NGFWs from all locations are failing since just past midnight EDT last night. The most relevant parts of the alert are: type: SYSTEMsubtype: device-telemetryeventid: send-failedobject:fmt: 0id: 0module: generalseverity: criticalopaque: Failed to send: file 'PA_&l...

KMcKenna by L2 Linker
  • 40505 Views
  • 12 replies
  • 1 Likes

PaloAlto does not pass through itself a request for AD

Hi !I have problem with connection PC to AD between which stands PaloAltoPC 192.168.10.10AD 192.168.30.40 (loc.lab)pings go from PC to AD 192.168.30.40 (loc.lab) and return successfullypings go from PC to loc.lab (192.168.30.40) and return successfullyBut when I try to connect a PC with a local account enter into the domain i get   when i t...

1PC.jpeg
1PC.jpeg
2PC.jpeg
PA_Metwork_InterfaceMgmt.jpeg
  • 1606 Posts
  • 61 Subscriptions
Top Solution Authors