Discover LIVEcommunity — Watch Now

  • 486,311 Members
  • 1,720 Online
  • 170,375 Posts
  • 17,865 Solutions
  • 50,177 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Resolved! Telemetry - Hostname/url is in illegal/bad format

Hello - Any idea on how to troubleshoot this? Device Telemetry Statistics:device-health-performance: last-attempt: Fri Oct 6 13:29:13 UTC 2023last-success: Fri Oct 6 12:19:14 UTC 2023num-of-failed-attempts: 2reason: Hostname/url is in illegal/bad formatstatus: failedproduct-usage: last-attempt: Fri Oct 6 13:29:13 UTC 2023last-success: Fri Oct ...

Windows Event Collector vs XDR collector

Hello guru, it seems both served the same purpose to me. all i would like to ingest the event logs for analystic purpose. except the configuration nature, like WEC required AD config and XDR collector need an agent installed. what is the pros and cons for for WEC and XDR collector? any use case for each? thanks SdG

Applying QOS bandwidth restriction

Hi, I would like to understand if my FW is capable of the below using QOS: - I am using PA-1410 in HA pair - I have 1 ISP internet link with 50Mbps bandwidth connected to eth1/1 - I have a requirement to create a guest network using the same ISP link and assign 10Mbps out of 50Mbps. So. using the same outside interface (eth1/1) I want to res...

Ahmed_94 by L1 Bithead
  • 210 Views
  • 5 replies
  • 0 Likes

Is it possible to configure a custom report into graph or chart format, similar to the options available for predefined reports?

We have configured a custom report for Interface Bandwidth and scheduled it for daily email delivery. However, we are not receiving the reports via email or seeing them triggered. The SMTP configuration test is successful, and we are not able view the reports under Monitor > Reports. Whenever we try to pull the report manually from the cus...

About FIN/RST Packets

Hi Experts, I was unable to find detailed information in the manufacturer's documentation or knowledge base, so please advise. ・If a communication is permitted by the firewall's security policy, is it possible for the firewall to send FIN or RST packets to that communication (client or server)?・Does the firewall ever send FIN or RST packets ...

Y.Kida by L0 Member
  • 50 Views
  • 0 replies
  • 0 Likes

RADIUS flows for Authenticating GP with username, password and OTP

Hello, I have a working GP configuration that uses client certificate, username and password for authentication, with the username and password validated using PEAP-MSCHAPv2 against a RADIUS server. I want to add an OTP challenge as described at https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS, for the on demand ...

Issue with PA-445 Failover - Interface Reset

We just replaced our active-passive PA-850s with PA-445s and have run into an issue when we failover the firewalls. On failover, all the data-plane interfaces on the new active node go down for 20 seconds before coming back up. This is dropping every active connection through the firewall. We did not see this behavior on the PA-850s (failover...

XSOAR IP Forwarding requirement

For Cortex XSOAR 6.X On-premises deployment, in server deployment / system requirements describes that IPv4 IP forwarding is required (System Requirements • Cortex XSOAR Administrator Guide • Palo Alto Networks documentation portal ). Security team is questioning if there is other possibility to deploy XSOAR by not enabling IPv4 IP Forwarding or...

M.Sylos by L0 Member
  • 39 Views
  • 0 replies
  • 1 Likes

Prisma cloud API access key permissions

Hi I have aquestion for Prisma cloud's API access key. Quoted from docs, when generating access key, it's tied to current login user's Role. https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/create-access-keys I tried some test to see if it works. I made a role that do not have access to view, update, delete a...

ssublue by L0 Member
  • 86 Views
  • 2 replies
  • 0 Likes

Please update MITRE Techniques in BIOC module

Please update MITRE Techniques available in BIOC creation menu for Cortex XDR V3.16 Missing MITRE techniques in BIOC module: T1204.004 - User Execution: Malicious Copy and Paste - https://attack.mitre.org/techniques/T1204/004/ T1204.005 - User Execution: Malicious Library - https://attack.mitre.org/techniques/T1204/005/ I am sure these aren'...

D.Ogle by L0 Member
  • 43 Views
  • 0 replies
  • 0 Likes

Seeing DNS Tunnel traffic to/from our Public Ranges?

Hello, This past week I've started seeing traffic that's classified as Tunneling:isavscan.[tld] (threat type: dns-c2, ThreatID: 109001001) hitting our Outside intrazone rule where the source and destination are our public ARIN IPs (the rule is currently set to allow while I make sure I have all the traffic we need like BGP and IPSec allowed in o...

public to public DNS tunnel.PNG

False Positive - Generic.ml

FileHash: b1ef3582cd461327d9a93d210c7d503ece186ce6a86d3105355da45c5a208b62 Link to VirusTotal report for the file:https://www.virustotal.com/gui/file/7c0feaf9231ced1629c167e08a9bc997f01452ceab72e38fb180c3fbfd9d3bd6 Current VirusTotal Verdict: Generic.ml

[Let me know reason & workaround] Global Protect Agent ver6.3.3 “PanPUAC_xxx.dat” does not work (auto create or renew, failed to open).

- Let me know reason why “PanPUAC_xxx.dat” does not work (auto create or renew, failed to open), after Windows Update, BIOS Update. - Let me know workaround. -pan_gp_event.log Ex) -Failed to open file C:\xxx\Palo Alto Networks\GlobalProtect\PanPUAC_xxx.dat -Portal status is User authentication failed -Retry connect failed first time Best reg...

Upcoming Fuel Events

Top Solution Authors
Top Liked Authors
Top Contributors

Latest from our Blog

HashiCorp Incident Management

This blog was written by Sabitha Muppuri (Sr Staff Site Reliability Engineer) The Critical Need for Vendor Tool Health Monitoring in Orchestration Environments In today's highly orchestrated and autos...

0 Comments