Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4696 Views
  • 0 replies
  • 1 Likes

License expired

hello guru, what will happen if my either the support and CDSS license expired? I assumed the CDSS function will not work because no signature updates. how about Firewall, NAT and VPN? thanks,

Commit failed and firewall now down after reboot

Hi, I have a weird issue on a cluster of two firewalls on active/active mode. Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck. On the secondary I tried to commit localy and I had this error : Unable to generate IKE VPN transform(Mod...

PA-220 Login issue

Hi Everyone We have a load of PA-220's in HA at variuos different sites, after a set period of time the devices stop allowing use to login. Does not matter what method of Auth we try, it just does not work. To compond the problem, if we do not resolve this issue eariler enough both devices at the site go offline taking the whole site down. ...

R.Moth by L0 Member
  • 40 Views
  • 0 replies
  • 0 Likes

PA-460 VERSION 11.1.13-H7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 50 Views
  • 0 replies
  • 0 Likes

HTTP partial response - Security protection bypass

The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting. Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates. When HTTP parti...

DaMonk by L1 Bithead
  • 88 Views
  • 0 replies
  • 2 Likes

Resolved! Policy Optimizer not available in PAN-OS 12.1

Hello there, with the brand-new PA-520 and PAN-OS 12.1.4-h3 is the Policy Optimizer missing (see my screenshots). I have found this info "(PAN-OS 12.1.2 and later versions) To ensure the best performance, customize your view to display the Policy Optimizer, only when you need it. The system fetches data for this component on-demand, which prev...

J.Dhling by L1 Bithead
  • 528 Views
  • 5 replies
  • 0 Likes

PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

Looking to see if anyone has done the above configuration. Essentially 2 sets of firewalls, 2 locations, managed in Panorama. I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate). Created 1 gateway on the local VM, then planned to issue the remote VM a c...

DJ_1924 by L2 Linker
  • 93 Views
  • 0 replies
  • 0 Likes

Sizing help — university internet edge, 3 Gbps today, 4,000–5,000 students, 7-year lifespan. PA-3430 / PA-3440 / PA-5410?

Looking for sizing advice from anyone running PAN at a university/campus internet edge. Environment: University with 4,000–5,000 students plus staff/faculty Current internet bandwidth: 3 Gbps — expect this to grow substantially over the appliance's life (bandwidth per student keeps climbing; wouldn't be surprised to hit 8–10 Gbps by end of life...

simsim by L4 Transporter
  • 107 Views
  • 0 replies
  • 0 Likes

Best free Syslog server 2026

Hi everyone, we are currently trying to set up a syslog server as we would want to retain older logs in case we need it for auditing purposes. We are looking for a free one that's good in 2026. I'm currently choosing between an ELK stack and Wazuh, which would be easier? I have experience in setting up Docker containers. Was looking at Graylogs ...

Sizing PA-Series for internet edge — 3 Gbps today, growing to 8–9 Gbps, with SSL decryption. Which model?

Sizing an edge firewall for a university campus and would appreciate real-world input from people running decryption at scale. Requirements: Internet edge only — no east-west/inter-VLAN (core switches handle that) Current internet traffic: ~3 Gbps, growing to 8–9 Gbps over the appliance's 5–7 year lifecycle Security profile: Threat Prevention (...

simsim by L4 Transporter
  • 67 Views
  • 0 replies
  • 0 Likes

Resolved! IPSec Dynamic Peer VPN, failure to send traffic over attached tunnel interface

Is anyone aware of a known issue with sending traffic over an IPSec tunnel interface when using multiple dynamic peers with FQDN (host) peer identification? I have multiple existing branch locations connected to the PA with IKEv2 IPSec tunnels using dynamic FQDN (host) peer identification from Cisco branch routers. Up to now it has worked fine...

Commit Protection – Automatic Restore Point Before Every Commit

The ProblemAs network technicians, we all know that committing a configuration is the most critical action on a firewall.Most commits complete successfully.Sometimes they don't.A wrong static route, a Virtual Router change, an interface modification or an incorrect NAT rule can immediately affect the firewall after the commit.The firewall is sti...

Is there a way to configure Pan-OS to integrate with an ACME server for certificate enrollment?

Hello, I am working with an IPsec VPN setup on my Palo Alto Networks firewall and am currently using certificate-based authentication. My organization utilizes an internal Certificate Authority (CA) that supports ACME (Automatic Certificate Management Environment) for certificate enrollment. However, I haven't been able to find any resources or ...

  • 1611 Posts
  • 61 Subscriptions
Top Solution Authors