Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4750 Views
  • 0 replies
  • 1 Likes

Can't ping a PaloAlto interface

I am new to Palo Alto firewall. I have loaded Pan-OS 9 on eve-ng and connected one of it's port to router. It is layer three connectivity and have assigned ip to both ends. However I can't ping the firewall interface. OSPF neighborship is also not forming. Can someone help please.

jasamit by L0 Member
  • 4725 Views
  • 1 replies
  • 0 Likes

Routing question

I might be overlooking something fundamental. We are trying to slow-step out of another firewall into a PA. I have created an interface on the PA in the old subnet. I can ping across to the server and old firewall. Clients behind the PA cannot get a DHCP address. I am wondering if trying to maintain the same subnet on a Legacy VLAN will even...

We are not able to receive the password resetting link

We are not able to login the support.paloaltonetworks.com site. When we try to resetting the password using mail id, we did not receive the password reset link on mail. Kindly help us to resolve this issuePlease note you are posting a public message where community members and experts can provide assistance. Sharing private information such as ...

ISP ping going out via different interface

I am facing a very strange issue. Thee are four ISP connected to PA. All are VLAN interfaces. While doing a ping to 8.8.8.8 or any public IP from the vlan interface IP it works fine except for one ISP. For one ISP if a ping a initiated from vlan.7 the traffic goes out via vlan.3. attached a screenshot. Ping is initiated from PA cli - ping sour...

pingPA.jpg
ceapen01 by L2 Linker
  • 5339 Views
  • 5 replies
  • 0 Likes

Static Source nat, two /24 subnets one to one

I want to know if this is possible, make a Static Source NAT so thatsource network last octet lets say 192.168.1.10 is translated to 10.1.1.10 then next host 192.168.1.11 is translated to 10.1.1.11 and this should happen always only natting last octet, so it does not get mixed and source nat to a different Ip that does not match the last octet. ...

Carlos_N by L1 Bithead
  • 9384 Views
  • 9 replies
  • 0 Likes

Resolved! Decryption exception issue - no SNI - SCN: chat.signal.org

Hi,how to add following decryption error (ssl-forward-proxy) to exceptions? - logs->decryption: dest address: ac88393aca5853df7.awsglobalaccelerator.com (shodan solves this ip /13.248.212.111/ also to service.signal.org; SNI - no value; SCN: chat.signal.org; error: General TLS protocol error - logs->traffic: destination like above; decrypt...

JarerkZajac_0-1655994017023.png
JarerkZajac_3-1655994196320.png
JarerkZajac_1-1655994083091.png
JarerkZajac_2-1655994143220.png

Regarding REST API feasibility

There is a requirement to check the REST API feasibility for the below parameters. Logs will be sent to Monitoring tool through REST API. Could anyone please help on this? Can we achieve below parameters through REST API? CPS CPU Utilization Dataplane CPU Utilization mgmt. plane Global server health Operational mode Packet buffer status Ses...

Routing client vpn over site to site tunnel

Hello everyone, I’m new to palo alto and I have the following problematic that I couldn’t solve. I have PA Firewall in my local site and it’s configured to allow site to site connection to a remote branch which works perfectly. In addition, I’ve set up client to site (to local site) connection and it works perfectly, I can reach all the resource...

John19 by L0 Member
  • 2185 Views
  • 1 replies
  • 0 Likes

Log Collector status", it gives me "Error"

Hello All, From the device-Setup-Management tab, there is "Logging and Reporting Settings". And when I click "Log Collector status", it gives me an "Error" The FW is connected to Panorama and it gets shared policies and objects and it seems like forwarding logs. What is the error indicated in firewall. Kindly suggest on this.

SunilduttJ_0-1672310556548.png

VPN Phase 2 Tunnel stuck

Hi, We have multiple S2S VPN with many vendors but facing issue with Fortinet. On our side we observe Phase 2 tunnel is up and packets are going out through Tunnel interface but no reply. Other party saying no issue on their end but once we restart that Phase 2 Proxy id, it starts working. Just to inform you that we have multiple Proxy ids. a...

ISG-JHAH by L0 Member
  • 3718 Views
  • 3 replies
  • 0 Likes

VM not working in Vmware 6.7

Hello, I am getting desperate :(. I am totally new in PA, this was supposed to be my first VM to lab and play with it. Anyway I have credits and I have OVA file. When I try to deploy it in Workstation on my local PC, it works. When I use the same OVA in our lab environment With VXLANs a Vmware 6.7 (NSX). Its not working at all. I am not able t...

JLoukota by L1 Bithead
  • 3154 Views
  • 3 replies
  • 0 Likes
  • 1625 Posts
  • 61 Subscriptions
Top Solution Authors