Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4709 Views
  • 0 replies
  • 1 Likes

Intermittent IPsec connection

We recently setup IPsec tunnel between PA-1410 and 3rd party device. We can see the tunnel is up, but when testing ping between endpoint on our side to endpoint on the peer's side there are frequents request timed out.Our configuration for IKE crypto using sha256, aes-256-cbc, DH group 19, lifetime 24 hours. For IPsec crypto we use sha256, aes-2...

i.rifai by L1 Bithead
  • 84 Views
  • 4 replies
  • 0 Likes

Time-Based Access Restriction and Password Expiration for Local Users

Hello Palo Alto Community Team, I need your assistance with configuring local user accounts on a Palo Alto Networks firewall. My requirements are: Configure time-based access restrictions for specific local users. For example, allow a user to log in only during a specified time period (such as Monday–Friday, 8:00 AM to 5:00 PM). Configure passw...

LACP Port Channel Link Flap between Cisco PA-445 and IR9320

Hello,We have a Palo Alto PA-445 firewall connected to a pair of Cisco IE9320 core switches configured as a stack, with one link connected to each switch. The links are configured in a Port-Channel on the Cisco side and as an AE (Aggregate Ethernet) interface on the Palo Alto firewall. Additionally, the MAC persistency timer is configured to 0 o...

Him143u by L0 Member
  • 69 Views
  • 1 replies
  • 0 Likes

VPN Performance over Prisma Access : slow downloads

Hi, Can somebody tell met what you can expect from downloading a file over prisma access backbone. Our datacenter is connected to service connection and when I try to download a 200 Mbps file from the datacenter to a remote network located in the same region, I am getting a download speed of 500Kbps per second.(smb transfer) Within the remote ...

zGomez by L3 Networker
  • 8961 Views
  • 9 replies
  • 0 Likes

PA-220 Login issue

Hi Everyone We have a load of PA-220's in HA at variuos different sites, after a set period of time the devices stop allowing use to login. Does not matter what method of Auth we try, it just does not work. To compond the problem, if we do not resolve this issue eariler enough both devices at the site go offline taking the whole site down. ...

R.Moth by L1 Bithead
  • 232 Views
  • 6 replies
  • 0 Likes

3 node cluster or HA

Hi community. I am setting up a palo alto firewalls for a customer and they need it as 3 nodes. they are going to be placed in three different buidling inside the same campus. I have gone through the documents and seeing that clustering is the only option as it is 3 in number. I want to know is there any way that i can make this into HA of ...

License expired

hello guru, what will happen if my either the support and CDSS license expired? I assumed the CDSS function will not work because no signature updates. how about Firewall, NAT and VPN? thanks,

Commit failed and firewall now down after reboot

Hi, I have a weird issue on a cluster of two firewalls on active/active mode. Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck. On the secondary I tried to commit localy and I had this error : Unable to generate IKE VPN transform(Mod...

PA-460 VERSION 11.1.13-H7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 95 Views
  • 0 replies
  • 0 Likes

pa-460 version 11.1.13-h7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 105 Views
  • 0 replies
  • 0 Likes

HTTP partial response - Security protection bypass

The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting. Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates. When HTTP parti...

DaMonk by L1 Bithead
  • 144 Views
  • 0 replies
  • 2 Likes

Alternate of Expedition Tool

Hello Palo Alto Networks Community, I would like to introduce PAN-Tool, a web-based platform designed to simplify multi-vendor firewall migration and Palo Alto Networks configuration conversion. Many engineers currently use tools like Expedition for configuration migration and optimization. PAN-Tool is built with a similar objective — providing ...

Resolved! Policy Optimizer not available in PAN-OS 12.1

Hello there, with the brand-new PA-520 and PAN-OS 12.1.4-h3 is the Policy Optimizer missing (see my screenshots). I have found this info "(PAN-OS 12.1.2 and later versions) To ensure the best performance, customize your view to display the Policy Optimizer, only when you need it. The system fetches data for this component on-demand, which prev...

J.Dhling by L2 Linker
  • 702 Views
  • 5 replies
  • 0 Likes
  • 1618 Posts
  • 61 Subscriptions
Top Solution Authors
Top Liked Authors