Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4765 Views
  • 0 replies
  • 1 Likes

trojan/Win32.deceiver.d - False Positive?

I have noticed that PA NGFW sees this threat trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2). I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that. In the Threat log I see only a few of th...

Resolved! [SOLVED] THE NGFW's DHCP SERVER AND DHCP RELAY SUDDENLY ARE NOT WORKING!!

Hello, LiveCommunity team! I created this post to share my experience with an issue on our branch PA-1420 NGFW, which is configured to act as both a DHCP server on the ethernet1/4 interface and a DHCP relay agent, but suddenly stopped working! About 20 days ago, our DHCP server and DHCP relay agent stopped functioning as expected. We use our PA ...

DanielSRomero_2-1789087056190.png

High availability failover: GARP doubts.

Hey guys!. First time poster here.To begin with, I am beginner to PA and learning my way through. I have just reached the HA part, and have a few questions.In an active/passive deployment, when the Active unit fails and the Passive unit starts taking over, it sends GARP and updates the downstream/ (upstream?) switches CAM tables with the new in...

Nadeem69 by L0 Member
  • 1532 Views
  • 2 replies
  • 0 Likes

Resolved! Fast Path vs Slow Path with Content ID

Hi, newish to Palo Alto so trying to understand the demarcation between Fast-Path and Slow path when using Content ID. My understanding is that when a new traffic flow starts App-ID is used to determine the application and once the flow is established traffic moves to Fast path. Am I right though that if Content-ID is used that the traffic m...

M.Gannon by L2 Linker
  • 311 Views
  • 3 replies
  • 0 Likes

Throughput from CLI vs Dashboard

hello experts, I have pa-3220, want to upgrade to new model, quite satisfied with our existing throughput, max session and new session... how to find out those figures from CLI or rhe Web-UI? what to spot out or how to cater the traffic spike? What is the CLI commands? any other need to concerns? thanks.

How to Update Specific Versions of Content via the CLI

Hello Palo Alto Networks Support Team, I would like to ask about the current method for updating content via the CLI. Previously, we used the following command to install a specific content version: request content upgrade download <content version> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/cli-commands-for-upgra...

Error: Domain's DNS name is missing in Active Directory Authentication

Hi guys, while working on setting up user-id, I got this 'Error: Domain's DNS name is missing in Active Directory Authentication' while trying to commit. I found this instruction: Using the Web GUI:1. Navigate to Device ➔ User Identification ➔ User Mapping.2. Click the Gear Icon next to Palo Alto Networks User-ID Agent Setup.3. Click on the Ser...

tinhnho by L3 Networker
  • 172 Views
  • 1 replies
  • 0 Likes

Looking for a genuine factory-default PA-Series running-config.xml for audit-tool development

Hi everyone,I'm developing a firewall configuration-audit/parser tool and I'm looking for a genuine factory-default Palo Alto Networks firewall configuration for testing.I'm interested in any PA-Series firewall. A PA-5220 would be preferred, but configurations from other PA-Series models are also useful.PAN-OS 11.x would be preferred, but config...

PAN-294687 - HIP Report synchronization and GlobalProtect Gateway behavior in NGFW Clusters

Hi Team, We are investigating PAN-294687 and would like clarification on the following points. 1. In an NGFW Cluster, how are HIP Reports shared between Panorama, the Leader Node, and Non-Leader Nodes? Specifically, is HIP Report synchronization between the Leader Node and Non-Leader Nodes performed directly, or through Panorama? 2. Publi...

f.yanai by L0 Member
  • 149 Views
  • 0 replies
  • 0 Likes

PA-5200 Series Enviroment

Hi I have a question regarding the output of the 'show system environmentals' command on the PA-5200 Series. Could someone explain the difference between 'NP / NP Core' and 'CP / CP Core' in the output results? In my opinion, NP and CP are likely hardware accelerators, such as a Network Processor and a Content Processor, respectively. However,...

Specifications for Device Telemetry

Please let me know if you have any information. Regarding device telemetry, there was a report last year that it would be automated starting with releases from 10.2.17 onward. My understanding is that it will be enabled automatically and cannot be turned on or off.https://docs.paloaltonetworks.com/ngfw/administration/device-telemetry/device-te...

n-tomo by L2 Linker
  • 211 Views
  • 1 replies
  • 0 Likes

PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

Looking to see if anyone has done the above configuration. Essentially 2 sets of firewalls, 2 locations, managed in Panorama. I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate). Created 1 gateway on the local VM, then planned to issue the remote VM a c...

DJ_1924 by L2 Linker
  • 231 Views
  • 2 replies
  • 0 Likes

CVE-2026-0261 PAN-OS_ Authenticated Admin Command Injection Vulnerability

Attention: Global TPM team, In the Security Advisory referenced in the subject, is it correct to understand that the behavior of the vulnerability exploitation by an authenticated administrator does not differ depending on the assigned role?Or does the behavior vary depending on the role of the authenticated administrator?

Is 10.2.17 affected by CVE-2026-0287?

Hi, I'm looking into the new CVE-2026-0287, and I can't figure out if PAN-OS version 10.2.17 is affected.In the “Product Status” table, the following versions are listed as affected: "<10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8“ and these others as unaffected ” >= 10.2.7-h36, >= 10.2.10-h39, >= 1...

G.Valfre by L0 Member
  • 274 Views
  • 1 replies
  • 0 Likes
  • 1629 Posts
  • 62 Subscriptions
Top Solution Authors