Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4738 Views
  • 0 replies
  • 1 Likes

Looking for a genuine factory-default PA-Series running-config.xml for audit-tool development

Hi everyone,I'm developing a firewall configuration-audit/parser tool and I'm looking for a genuine factory-default Palo Alto Networks firewall configuration for testing.I'm interested in any PA-Series firewall. A PA-5220 would be preferred, but configurations from other PA-Series models are also useful.PAN-OS 11.x would be preferred, but config...

PAN-294687 - HIP Report synchronization and GlobalProtect Gateway behavior in NGFW Clusters

Hi Team, We are investigating PAN-294687 and would like clarification on the following points. 1. In an NGFW Cluster, how are HIP Reports shared between Panorama, the Leader Node, and Non-Leader Nodes? Specifically, is HIP Report synchronization between the Leader Node and Non-Leader Nodes performed directly, or through Panorama? 2. Publi...

f.yanai by L0 Member
  • 75 Views
  • 0 replies
  • 0 Likes

PA-5200 Series Enviroment

Hi I have a question regarding the output of the 'show system environmentals' command on the PA-5200 Series. Could someone explain the difference between 'NP / NP Core' and 'CP / CP Core' in the output results? In my opinion, NP and CP are likely hardware accelerators, such as a Network Processor and a Content Processor, respectively. However,...

Error: Domain's DNS name is missing in Active Directory Authentication

Hi guys, while working on setting up user-id, I got this 'Error: Domain's DNS name is missing in Active Directory Authentication' while trying to commit. I found this instruction: Using the Web GUI:1. Navigate to Device ➔ User Identification ➔ User Mapping.2. Click the Gear Icon next to Palo Alto Networks User-ID Agent Setup.3. Click on the Ser...

tinhnho by L3 Networker
  • 21 Views
  • 0 replies
  • 0 Likes

Specifications for Device Telemetry

Please let me know if you have any information. Regarding device telemetry, there was a report last year that it would be automated starting with releases from 10.2.17 onward. My understanding is that it will be enabled automatically and cannot be turned on or off.https://docs.paloaltonetworks.com/ngfw/administration/device-telemetry/device-te...

n-tomo by L2 Linker
  • 135 Views
  • 1 replies
  • 0 Likes

PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

Looking to see if anyone has done the above configuration. Essentially 2 sets of firewalls, 2 locations, managed in Panorama. I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate). Created 1 gateway on the local VM, then planned to issue the remote VM a c...

DJ_1924 by L2 Linker
  • 176 Views
  • 2 replies
  • 0 Likes

CVE-2026-0261 PAN-OS_ Authenticated Admin Command Injection Vulnerability

Attention: Global TPM team, In the Security Advisory referenced in the subject, is it correct to understand that the behavior of the vulnerability exploitation by an authenticated administrator does not differ depending on the assigned role?Or does the behavior vary depending on the role of the authenticated administrator?

Is 10.2.17 affected by CVE-2026-0287?

Hi, I'm looking into the new CVE-2026-0287, and I can't figure out if PAN-OS version 10.2.17 is affected.In the “Product Status” table, the following versions are listed as affected: "<10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8“ and these others as unaffected ” >= 10.2.7-h36, >= 10.2.10-h39, >= 1...

G.Valfre by L0 Member
  • 195 Views
  • 1 replies
  • 0 Likes

Palo Alto 3410 Firewall 100% DP CPU spike

Hello all,We are seeing sudden spikes in Data Plane CPU on our Palo Alto Networks PA-3410 firewalls running PAN-OS 11.1.13. The CPU usage jumps to 100% for a few seconds and then returns to normal automatically. This happens randomly, with no fixed timing. We have observed this at two different locations where we have PA-3410.Initially, we suspe...

Firewall SSH, the login succeeds with TACACS Account, but there is an issue that closes the session immediately.

Hello, everyone. Firewall has OS of 10.2.4-H2. When TACACS account to connect to Firewall SSH, the login succeeds, but there is an issue that closes the session immediately. In Firewall System-log, authentication and authorization were successful and it was confirmed that the Superuser role was granted.. However, a "create-admin-acct-err...

hbshin by L2 Linker
  • 2914 Views
  • 5 replies
  • 0 Likes

'release-date' shows wrong timezone after Panorama push (PAN-OS 12.1.6)

Hi community, I'm seeing a minor display issue on a PA-460 (PAN-OS 12.1.6). Both the firewall and Panorama are correctly set to the JST timezone. When installing a content update pushed from Panorama, the installed versions are correct, but the release-date in the show system info CLI output goes backwards by 16 hours. However, it still displays...

I.Awano by L0 Member
  • 121 Views
  • 0 replies
  • 0 Likes

Resolved! PA-460 VERSION 11.1.13-H7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 249 Views
  • 1 replies
  • 0 Likes

Time-Based Access Restriction and Password Expiration for Local Users

Hello Palo Alto Community Team, I need your assistance with configuring local user accounts on a Palo Alto Networks firewall. My requirements are: Configure time-based access restrictions for specific local users. For example, allow a user to log in only during a specified time period (such as Monday–Friday, 8:00 AM to 5:00 PM). Configure passw...

  • 1624 Posts
  • 61 Subscriptions
Top Solution Authors
Top Liked Authors