• 522,988 Members
  • 1,702 Online
  • 1,130,136 Posts
  • 19,551 Solutions
  • 53,279 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Device Security license

Hello everyone, I have an active Precision AI Network Security Subscription Renewal Bundle for a firewall. However, when I log in to the Customer Support Portal and navigate to Products > Assets, then select the firewall, I do not see a Device Security license listed. I found the following document, which mentions Device Security: https://d...

Global Protect 6.3.3 Issues

I am on Global Protect Version 6.3.3-1121. I can connect on my Windows Device just fine. On a Mac version 26.6.2 when i try to connect, the client says "you are redirected to an embedded browser to authenticate and connect". It just stays there and never connects

Resolved! Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

I’ve got an iPad that has the GlobalProtect client installed. I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert). I get this error “A valid client certificate is required for authentication. If the issue persists, contact your system administrator”. I’ve been troubleshooting ...

IMG_0623.jpeg
IMG_0620.png
IMG_0619.jpeg
IMG_0617.png

Unable to Connect to Global Protect 6.3.4 iPhone and iPads

Hello everyone, We're experiencing an issue with GlobalProtect on managed iPads and iPhones version 6.3.4-23. I'm trying to determine whether anyone else has run into this recently. Environment GlobalProtect VPN deployed via Microsoft Intune iPadOS devices Authentication through PingID (SAML) VPN type: Palo Alto Networks GlobalProtect Authent...

mtruong_0-1787151999535.png
mtruong_1-1787152104165.png
mtruong by L0 Member
  • 110 Views
  • 1 replies
  • 0 Likes

XDR Alert Dump – Finding the File That Triggered the Alert

I have a question. When we perform a Dump Alert and get the ZIP file, how can we analyze it in more detail? For example, if I want to see the .ps1 file that a particular user executed on the machine and that triggered the alert, would that file be included in the dump? I’ve already searched everywhere, but I can’t find it. I can see a folder cal...

tlmarques by L4 Transporter
  • 34 Views
  • 1 replies
  • 0 Likes

Using firewall's own loopbacks as dummy Panorama servers

Hello, was trying to find if anyone has ever dealt with something similar, but couldn't find anything (so, hopefully this isn't a duplicate post). Some info to put things into perspective: I was tasked to migrate 6 HA (active-passive) clusters from soon-to-be-decommissioned Panorama (hosted in Azure) to our on-prem Panorama (hosted in DC) ...

Error: Domain's DNS name is missing in Active Directory Authentication

Hi guys, while working on setting up user-id, I got this 'Error: Domain's DNS name is missing in Active Directory Authentication' while trying to commit. I found this instruction: Using the Web GUI:1. Navigate to Device ➔ User Identification ➔ User Mapping.2. Click the Gear Icon next to Palo Alto Networks User-ID Agent Setup.3. Click on the Ser...

tinhnho by L3 Networker
  • 49 Views
  • 1 replies
  • 0 Likes

Low Incident

We have integrated Cortex XDR with Elastic SIEM. Our SOC process currently creates a ticket for every Cortex XDR incident/case, including Low, Medium, and High severity incidents. Is Palo Alto's recommended best practice to create tickets for all Low severity incidents, or should Low severity alerts/incidents be monitored and correlated before t...

Resolved! XSIAM HTTP Log Collector Testing

Hello everyone, We are currently considering to us a HTTP Log Collector. However, before this can be started, I wanted to test the collection. Now, in theory, this should not be hard, due to the examples provided after setting up the integration. Nonetheless, either the Python Example is faulty in some way, or I am being exceedingly stupi...

XDR 4 - Integrations AD Query

Hi everyone, on Cortex XDR 4 ,we can build small playbooks, and one of the available actions is AD Query.My question is: what is required to configure this integration? I see that the integration asks for the IP address, domain user, and other parameters, but if the Active Directory is on-premises, how does Cortex XDR establish the connection?Wh...

tlmarques by L4 Transporter
  • 1894 Views
  • 4 replies
  • 0 Likes

PANCast™ Episode 59: How to Create and Manage a Support Case from the Customer Support Portal

8 min read

Episode Transcript: John: Hello PANCasters and welcome back. Today we have Daniel back with us to talk about some administrative processes on the Customer Support Portal. Welcome Daniel. Can you tell us what we will be going through today? Daniel: Hi John, today we are going to talk about How to Create a Support Portal User account, How to...

IMG_0390.jpg
ozheng by L4 Transporter
  • 62 Views
  • 1 replies
  • 0 Likes

User-id mapping domain name issue

Hi everyone, I recently set up GP user-id mapping in our network. It's showing domain.local\username in the logs. I was also told to set up User-ID mapping using the windows agent as well since our users would need to disconnect from GP occasionally. The logs that we get from the windows agent is domain\username. Issue now is that when we se...

Firewall not connecting to Strata Logging Service

Hi everyone, I've started setting up the Strata logging service and I've added in the necessary app-ids. After adding the app-ids and with destination any, it started sending out the logs to Strata without any issues. We currently have an issue when we try to add in the FQDNs either as an address group or url category that the firewall just w...

RPerez481389_0-1787812617479.png

Cortex XDR JDP method instrumentation causing severe Java runtime slowness (agent 9.2.0.120) — follow-up to solved cyjagent crash thread

This is a follow-up to a previously solved thread: Cortex XDR cyjagent.dll injection causes JVM startup crash, where @susekar confirmed the known JDP/JVM conflict (CPATR-38467 / CPATR-18158). Thanks for that confirmation. Since the solution there is already accepted, raising this as a separate topic: we've now observed a second symptom from the ...

Upcoming Fuel Events

Top Solution Authors
Top Contributors