Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4732 Views
  • 0 replies
  • 1 Likes

PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

Looking to see if anyone has done the above configuration. Essentially 2 sets of firewalls, 2 locations, managed in Panorama. I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate). Created 1 gateway on the local VM, then planned to issue the remote VM a c...

DJ_1924 by L2 Linker
  • 152 Views
  • 2 replies
  • 0 Likes

PA-5200 Series Enviroment

Hi I have a question regarding the output of the 'show system environmentals' command on the PA-5200 Series. Could someone explain the difference between 'NP / NP Core' and 'CP / CP Core' in the output results? In my opinion, NP and CP are likely hardware accelerators, such as a Network Processor and a Content Processor, respectively. However,...

CVE-2026-0261 PAN-OS_ Authenticated Admin Command Injection Vulnerability

Attention: Global TPM team, In the Security Advisory referenced in the subject, is it correct to understand that the behavior of the vulnerability exploitation by an authenticated administrator does not differ depending on the assigned role?Or does the behavior vary depending on the role of the authenticated administrator?

Is 10.2.17 affected by CVE-2026-0287?

Hi, I'm looking into the new CVE-2026-0287, and I can't figure out if PAN-OS version 10.2.17 is affected.In the “Product Status” table, the following versions are listed as affected: "<10.2.7-h36, < 10.2.10-h39, < 10.2.13-h23, < 10.2.16-h9, < 10.2.18-h8“ and these others as unaffected ” >= 10.2.7-h36, >= 10.2.10-h39, >= 1...

G.Valfre by L0 Member
  • 184 Views
  • 1 replies
  • 0 Likes

Palo Alto 3410 Firewall 100% DP CPU spike

Hello all,We are seeing sudden spikes in Data Plane CPU on our Palo Alto Networks PA-3410 firewalls running PAN-OS 11.1.13. The CPU usage jumps to 100% for a few seconds and then returns to normal automatically. This happens randomly, with no fixed timing. We have observed this at two different locations where we have PA-3410.Initially, we suspe...

Firewall SSH, the login succeeds with TACACS Account, but there is an issue that closes the session immediately.

Hello, everyone. Firewall has OS of 10.2.4-H2. When TACACS account to connect to Firewall SSH, the login succeeds, but there is an issue that closes the session immediately. In Firewall System-log, authentication and authorization were successful and it was confirmed that the Superuser role was granted.. However, a "create-admin-acct-err...

hbshin by L2 Linker
  • 2878 Views
  • 5 replies
  • 0 Likes

Specifications for Device Telemetry

Please let me know if you have any information. Regarding device telemetry, there was a report last year that it would be automated starting with releases from 10.2.17 onward. My understanding is that it will be enabled automatically and cannot be turned on or off.https://docs.paloaltonetworks.com/ngfw/administration/device-telemetry/device-te...

n-tomo by L2 Linker
  • 77 Views
  • 0 replies
  • 0 Likes

'release-date' shows wrong timezone after Panorama push (PAN-OS 12.1.6)

Hi community, I'm seeing a minor display issue on a PA-460 (PAN-OS 12.1.6). Both the firewall and Panorama are correctly set to the JST timezone. When installing a content update pushed from Panorama, the installed versions are correct, but the release-date in the show system info CLI output goes backwards by 16 hours. However, it still displays...

I.Awano by L0 Member
  • 108 Views
  • 0 replies
  • 0 Likes

Resolved! PA-460 VERSION 11.1.13-H7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 184 Views
  • 1 replies
  • 0 Likes

Time-Based Access Restriction and Password Expiration for Local Users

Hello Palo Alto Community Team, I need your assistance with configuring local user accounts on a Palo Alto Networks firewall. My requirements are: Configure time-based access restrictions for specific local users. For example, allow a user to log in only during a specified time period (such as Monday–Friday, 8:00 AM to 5:00 PM). Configure passw...

Software NGFW Credit Pool Activation Lag (Ramp Status Showing INACTIVE)

Hello Community, I am looking for some clarification regarding the renewal and activation timeline of our Software NGFW Credits. Our renewal order for 350 credits has been successfully deposited into our Customer Support Portal under Ramp 2. However, looking at our portal dashboard, the status for Ramp 2 (Start Date: 08/07/2026, End Date: 08/0...

スクリーンショット 2026-08-07 095552.png

Resolved! Intermittent IPsec connection

We recently setup IPsec tunnel between PA-1410 and 3rd party device. We can see the tunnel is up, but when testing ping between endpoint on our side to endpoint on the peer's side there are frequents request timed out.Our configuration for IKE crypto using sha256, aes-256-cbc, DH group 19, lifetime 24 hours. For IPsec crypto we use sha256, aes-2...

i.rifai by L1 Bithead
  • 612 Views
  • 4 replies
  • 0 Likes
  • 1621 Posts
  • 61 Subscriptions
Top Solution Authors