Discover LIVEcommunity — Watch Now

  • 491,306 Members
  • 2,818 Online
  • 170,876 Posts
  • 18,034 Solutions
  • 50,503 Likes
🔥 We are nominated in 4 CMX Community Industry Award categories! 🔥
Cast your vote now and be part of our journey to victory!

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Conditional Advertisement / BGP Failover with Dual ISP — How to Remove ISP1 Routes on Internet Loss?

Hi all, I’m running a dual-ISP setup on a PA with BGP to ISP1 and ISP2. My goal is: Monitor ISP1 default route / Internet reachability. If ISP1 becomes unusable, I want all traffic to fail over to ISP2. I am advertising an IP pool to both ISP1 and ISP2 for incoming traffic, with AS-path prepending applied to ISP2 so that incoming traffic ...

app override and out-of-order packets

Does app override have any implications on the tcp counterout-of-order queueWondering if it just for turning off layer 7 inspection of the given application, OR if it also changes the way ingestion occurs and disregards the TCP out-of-order queue size limitation on firewalls?

Sec101 by L4 Transporter
  • 13 Views
  • 0 replies
  • 0 Likes

Palo Alto Unable to Download Software Updates

Hi All, Any advice on a possible solution or workaround? All traffic passes through the proxy server. We have already checked the KB below; however, we cannot change the DNS settings because the proxy server is being used as the DNS server. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEpCAK Model: PA - 3410 Sof...

GUEST WIFI for new client

Hi All, I just have a question. We have a new client on office and they will be using their own domain and laptop. They will connect to our GUEST internet and will use it to access their internal network. The thing is client wants to have a dedicated guest vlan for them. We have an existing GUEST VLAN for our clients and this new client do...

weezy by L3 Networker
  • 161 Views
  • 3 replies
  • 0 Likes

Palo Alto Networks PA- 450 Next‑Generation Firewall to maintain uninterrupted BSNL SIP trunk services in the event of a primary internet link failure.

Please provide comprehensive and step‑by‑step instructions for configuring a Palo Alto Networks PA- 450 Next‑Generation Firewall to maintain uninterrupted BSNL SIP trunk services in the event of a primary internet link failure. The BSNL SIP Trunk Server which is on cloud having a static IP of 117.198.215.109 & BSNL SIP trunk is presently bou...

XDR Allow-Listing signed processes

We have internally developed scripts that we would like to create XDR exclusions or alert level reduction for based on if they contain code signing certificates. I don't know how to go about doing this or if it's even possible. The idea here is to not need to update exclusions based on hashes any time the scripts are changed and to be more se...

M.Crow by L0 Member
  • 213 Views
  • 2 replies
  • 0 Likes

How to find the assets that do not have XDR agent installed in new Cortex 4.x version ?

Hi, earlier in the old Cortex 3.x version, it was easier to list out the assets that do not have Cortex XDR agent installed, from Asset Inventory (from the boolean value : Has_XDR_Agent as shown in the attachment). Is this feature removed from the new Cortex version as it is not listed in the 4.x documentation and as 'Asset inventory' has been r...

XDR Legacy Agent Exception's behavior

Hi, We have confirmed through the official manual that XDR does not perform evaluation on files or paths allowed under XDR Legacy Agent Exception.What I would like to know is whether files covered by a Legacy Agent Exception policy also do not generate alerts.I would also like to confirm if this behavior is explicitly stated in the official docu...

Block Execution of Specific Applications Regard of version

Hi, We want to enforce the use of only the approved version of AnyDesk (9.6.5.0 and above) on all Windows endpoints and completely prevent execution of any older versions of anydesk.exe. Is there a clean and maintainable way to achieve this using Cortex XDR Prevention/Restriction Profiles? From what I’ve seen, the straightforward way is:- Block ...

DanielBr by L0 Member
  • 199 Views
  • 1 replies
  • 0 Likes

resources-unavailable for DNS-base traffic

Model: Palo Alto PA-3420Software version: 11.2.4-h1 Most of our dns-base traffic has the "session end reason" resources-unavailable suddenly. We're also having trouble loading webpages. The resources-unavailable reason is only on DNS-base traffic and it is for DNS traffic to our 2 internal DNS servers, but also from our DNS-server to the forwa...

adminglu by L1 Bithead
  • 3922 Views
  • 9 replies
  • 1 Likes

Stale SIP Sessions

Hello all, We seem to have an issue with sip sessions being stuck in the session monitor for weeks and sometimes months. There have been instances, albeit extremely rare, where it prevented new sessions from being formed on a sip trunk we were testing (it's being moved off of the firewall for production). Once I cleared the stuck session we we...

stalesessions.png
stalesessionssip.png
ClintL by L2 Linker
  • 14214 Views
  • 11 replies
  • 0 Likes

False Positive - MecaNet.exe

FileHash: d80aa6abc728eb367d55509003a9c1c521934a83eb04de0de7f1f3dd3c40c3c3Link to VirusTotal report:https://www.virustotal.com/gui/file/d80aa6abc728eb367d55509003a9c1c521934a83eb04de0de7f1f3dd3c40c3c3VirusTotal Detection: Generic.ml

carlos by L0 Member
  • 30 Views
  • 0 replies
  • 0 Likes

Resolved! Request for VPN Capability Enhancement on Palo Alto Networks Firewalls

We respectfully request the addition and native support of Layer 2 and Layer 3 VPN technologies, specifically OpenVPN, SoftEther VPN, and WireGuard VPN, including both server and client functionalities, across all Palo Alto Networks Next-Generation Firewall platforms.The availability of these VPN solutions would significantly improve secure conn...

Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook

Hello everyone, I am building a simple playbook in Cortex XSIAM to check whether an endpoint is CONNECTED or DISCONNECTED using an XQL query on the endpoints dataset. The XQL query works correctly and returns the expected output: {"results": [{"endpoint_name": "ENDPOINT_089","endpoint_status": "DISCONNECTED"}],"status": "SUCCESS"} However, in ...

AAliyev094633_0-1763915838126.png
AAliyev094633_1-1763915877982.png
AAliyev094633_2-1763915894257.png
AAliyev094633_3-1763915924145.png

Upcoming Fuel Events

Top Solution Authors
Top Contributors

Latest from our Blog

Fuel Workshop - SASE Easy Onboarding

Please note - this event is scheduled with relation to Singapore time (GMT+8), 11:30 AM to 2:00 PM. Please plan your day and attendance accordingly. Hi there, As a valued Palo Alto Networks customer, ...

0 Comments