Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4815 Views
  • 0 replies
  • 1 Likes

PDF not getting blocked by pre defined Data patterns

We do not see the pdf format getting listed under file type in predefined patterns. Below is the ref. screenshot, What are the expectation by selecting the file type "Any"? It seems that only HTML and Microsoft office documents are supported under this category. We have observed that the PDF files are not getting blocked having the same c...

AHaleem849724_0-1789644627442.png

Triggering of Packet based protection under Zone protection profile

In the PA documentation, it says Zone protection is applicable to new connections that does not have any existing session. To mitigate flood protection that will works definitely. However under Zone protection profile we have packet based attack protection which deals packet based attacks which uses certain option in layer3 and 4 of a packet. ...

Help with file blocking security profiles

Hello everyone, Let me say I am new to the live community, I am trying to figure out if possible to Block file downloads using the "File download" security profile. I enabled it added it to my in to out policy and it still downloaded the files. After doing some more research I found out that the "Allow HTTP partial response" is enable it w...

Website blocked automatically by the firewall

I am using PA-410. In our network, one specific website is blocked automatically by the firewall. I created a URL filtering, added URLs to the whitelist, and allow in the profile. Nevertheless, users cannot access the website. When I monitor the traffic, there is "undecided" in front of the application. End Reason is unknown. State is Active.Cou...

gdu_palo by • L1 Bithead
  • 484 Views
  • 6 replies
  • 0 Likes

Undecided application

In our environment, some webpages are not accessible. (This site can’t be reached) When I monitor the session browser, there is "undecided" in the Application column. I have attached the screenshot. Please help me to solve this issue.

gdu_palo by • L1 Bithead
  • 299 Views
  • 4 replies
  • 0 Likes

12.1 Base update not available

Hi all, I have a new PA-440, I've registered it and applied all the licensing. I've been updating the software on it but noticed there is no 12.1 base to go to so I'm not able to install 12.1.7-h3. Is there a reason for this, or something I'm missing? I'm currently on 11.2.10-h14. Base releases is checked on the bottom, and I've done a check now...

DopedWafer_0-1790785110606.png

Virtual patching iand PANOS Shield n PANOS 12.2

Hello , Joined the webinar and amazed by the Virtual patching concept, We are using PA-1410, except the ATP+ lic and PANOS upgrade to v12.2 other technical prerequisites, more technical information to share? cannot find in the official doc https://docs.paloaltonetworks.com/network-security/security-policy/administration/security-profiles/... Do ...

Addition of a DPC on a 5450 causing packet loss

Hello Everyone, Hope you all are doing well. I have a question regarding an issue we experienced after adding a new DPC to a firewall. After installing a new DPC in Slot 6 and changing the session distribution method to Session Load, the firewall started experiencing connectivity issues with the router and peer IP addresses. We observed a signif...

wally4 by • L2 Linker
  • 95 Views
  • 0 replies
  • 0 Likes

macOS27 Global Protect?

Hi, Has anyone tried Global Protect on macOS27? I have two users that get totally isolated intermittently when connected. Connection to gateway stays up, but the tunnel is seemingly blackholing all or some traffic (including dns requests). They have upgraded to the lates GP version. I have a support ticket open, but slow progress so far.

Resolved! Upgrade release

Hello everyone, For a customer, I need to upgrade the release from 10.2.7-h8 to 12.2.2. I would like to understand which steps are necessary to perform this upgrade. In short, do I need to install every required intermediate release until I reach the target version? For example, would the procedure be something like: Download the base image fo...

trojan/Win32.deceiver.d - False Positive?

I have noticed that PA NGFW sees this threat trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2). I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that. In the Threat log I see only a few of th...

  • 1641 Posts
  • 62 Subscriptions
Top Liked Authors