Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.
About Next-Generation Firewall Discussions
Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

Discussions

Welcome to the Next-Generation Firewall Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4558 Views
  • 0 replies
  • 1 Likes

[FIREWALL] - Commit Issue

Hi everyone, I'd like to request support for a recent problem I'm having. I have one cluster with two Palo Alto firewalls, one of which was recently updated to version 11.1.13-h5 and is currently active, while the other is on version 11.1.13 and is passive. The environment is currently in this state because we are still validating version 11.1.1...

jobs.png
ErrorQueue.png

CVE-2026-0261 PAN-OS_ Authenticated Admin Command Injection Vulnerability

Attention: Global TPM team, In the Security Advisory referenced in the subject, is it correct to understand that the behavior of the vulnerability exploitation by an authenticated administrator does not differ depending on the assigned role?Or does the behavior vary depending on the role of the authenticated administrator?

EDL Performance and Refresh Handling in Panorama

Hello, We are reviewing an EDL-based IOC blocking architecture using Palo Alto Networks firewalls with Panorama and Cortex XDR. Currently, IOC blocking is managed mainly with address objects/groups, but we are considering migrating to EDL-only management for operational simplicity and external emergency response through Cortex XDR. I would appre...

.522643 by L1 Bithead
  • 186 Views
  • 3 replies
  • 0 Likes

Multi-VSYS 11.2.8 - How to assign a dedicated Forward Trust Certificate per VSYS for SSL Decryption

Hi everyone,I’m running PAN-OS 11.2.8 with Multi-VSYS enabled (3 VSYS). I need a different Forward Trust Certificate per VSYS for SSL decryption, but since my certificates are imported in the Shared store, I can only select one Forward Trust Certificate globally.Should I import the certificates directly at the VSYS level instead of Shared to fix...

Palo Windows ARP Issue - Windows Hosts Not Installing ARP info

Hello, We have random issue with Windows 11 Enterprise ( 10.0.26200) hosts not installing ARP reply from a stack of PAs running 10.2.7-h8. I have captured the traffic with the (non ip) filter and I can see the ARP requests and the replys. The hosts are sourcing DHCP from a PA interface with standard options for mask, default gateway and dom...

NSutfin by L2 Linker
  • 289 Views
  • 2 replies
  • 0 Likes

Palo Alto Site to Site VPN ipsec tunnel up but unable to ping Source to destination

Dear Team, When I am doing implement Site to Site VPN ipsec tunnel then tunnel status is down & Ike gateways is down after test commands manually trigger negotiation, then all up. But still source to destination unable to ping. Already on virtual router point to tunnel interface for all traffic on both firewall. On security policies allow ...

OSPF process crashes after manual HA Failover

Hi All,I seem to have a very odd issue that when a manual HA failover is triggered, via changing the priority of the active firewall to be worse than the passive, The devices will gracefully exchange control and sessions. However upon becoming the active device the OSFP (osfpd) process will exhaust it's restarts causing a reboot to be trigge...

NetFox by L0 Member
  • 139 Views
  • 0 replies
  • 1 Likes

Resolved! TS-Agent 11.1.1 Compatibility

The Compatibility Matrix shows that TS-Agent 11.1.0 is compatible with (only) Citrix XenApp 7.x According to the matrix, the TS-Agent 11.1.1 is not compatible with ANY version of Citrix XenApp Is this correct? Has TS-Agent 11.1.1 deprecated all support for Citrix? There is nothing in the release notes to suggest this which would seemto be a...

djr_0-1776240529102.png
djr by L4 Transporter
  • 401 Views
  • 2 replies
  • 0 Likes

traffic disruption on routing change

hi folks, I deleted a vlan subinterface from the VR config and from the ospf redist options. after comitting the change we had a partial service disruption where sessions where dropped. I can see a visible drop in thoughput but not in number of sessions. according to monitoring traffic I can says that it lasted roughly 15 seconds which is quite ...

False positive High-Risk classification for legitimate healthcare SaaS (gmedic.co)

Hello, https://gmedic.co is a legitimate healthcare SaaS platform used by healthcare professionals in Colombia. The domain is correctly categorized as Health-and-Medicine, however it is currently flagged as High-Risk. We already verified:- no malicious content- no phishing- no malware- clean reverse IP- dedicated legitimate hosting The issue see...

Regarding the migration from HDD to SSD for PA-VM running in the Azure environment

Hello everyone,We are deploying and building a PA VM on Azure.During deployment, there was no option to select between HDD and SSD, so we built it on an HDD.Therefore, as a test, we stopped the virtual machine (Palo Alto) and migrated it from HDD to SSD in Azure.Afterward, we started Palo Alto and performed a differential check, and there were n...

Otsuka by L1 Bithead
  • 277 Views
  • 2 replies
  • 1 Likes

PA 445 setup

So i''m setting up a new site on our JAPAN site. I setup 2 PA 445 A/P. Both FW are setup and HA's are connected as well. The problem is the HA are not synch yet, the primary PA 445 is accessible remotely via both public ISP 1 and ISP2 HTTPS. The reason is i'm not moving yet the private MGMT IP under permitted list on interface MGMT for...

weezy_0-1776845884511.png
weezy by L3 Networker
  • 901 Views
  • 5 replies
  • 0 Likes
  • 1589 Posts
  • 60 Subscriptions