# Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

### [Welcome to the Next-Generation Firewall Discussions!](https://live.paloaltonetworks.com/t5/next-generation-firewall/welcome-to-the-next-generation-firewall-discussions/td-p/1086236 "Welcome to the Next-Generation Firewall Discussions!")
To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

#### Rules and Best Practices
- **Be Respectful:** Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not.
- **Stay On-Topic:** This board is dedicated to discussions regarding Next-Generation Firewalls.

### Discussed Topics

- ### [NAT policy conversion](https://live.paloaltonetworks.com/t5/next-generation-firewall/nat-policy-conversion/td-p/1255866 "NAT policy conversion")
  Hello, I'm currently converting the Cisco ASA's configuration to Palo Alto. So in Cisco ASA, the NAT policy is configured as follows: object network VMAnat (ADM,inside) static 10.15.65.3.

- ### [SOLVED: User-ID Domain Mismatch](https://live.paloaltonetworks.com/t5/next-generation-firewall/solved-user-id-domain-mismatch-resolving-domain-s-conflicts/td-p/1256243 "[SOLVED User-ID Domain Mismatch]: Resolving Domain's Conflicts Between Prisma Access GlobalProtect (CIE) and On-Premises Server Monitoring")
  Hello LiveCommunity Team! I created this post to share my experience regarding an issue involving the User-ID domain mapping issue between the Prisma Access Mobile Users GlobalProtect and the NGFW On-Premises.

- ### [Using ethernet 1/1 - 1/12 for 10Gbps connections on a PA-3400 series firewall](https://live.paloaltonetworks.com/t5/next-generation-firewall/using-ethernet-1-1-1-12-fo-10gbps-connections-on-a-pa-3400/td-p/1255640 "Using ethernet 1/1 - 1/12 for 10Gbps connections on a PA-3400 series firewall")
  The spec on PA-3410 front panel states that Ethernet ports 1 through 12 can handle various speeds for network traffic. Is the speed determined by auto-negotiation? Also, can these ports be used for HA?

- ### [To force NGFW login using SAML/SSO](https://live.paloaltonetworks.com/t5/next-generation-firewall/to-force-ngfw-login-using-saml-sso/td-p/1229870 "To force NGFW login using SAML/SSO")
  Is it possible to use SAML/SSO login instead of manual credential username/password?

## Other Topics Covered

- **CVE-2026-0261 PAN-OS Authenticated Admin Command Injection Vulnerability**: Querying vulnerability behaviors based on roles of authenticated administrators.
- **EDL Performance and Refresh Handling in Panorama**: Migration considerations for IOC blocking architecture.
- **High CPU Issues After Upgrading PAN-OS**: Experiences regarding performance after update.

### Conclusion
Join the discussions and contribute your insights!
