• 527,605 Members
  • 1,083 Online
  • 1,132,366 Posts
  • 19,761 Solutions
  • 53,624 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Triggering of Packet based protection under Zone protection profile

In the PA documentation, it says Zone protection is applicable to new connections that does not have any existing session. To mitigate flood protection that will works definitely. However under Zone protection profile we have packet based attack protection which deals packet based attacks which uses certain option in layer3 and 4 of a packet. ...

Best Practice for Managing Short-Lived Public Certificates on Panorama-Managed Firewalls?

Hi everyone, With the industry moving toward shorter validity periods for publicly issued SSL/TLS certificates, I'm trying to plan ahead for certificate management on our Palo Alto firewalls. We have several firewalls that are managed through Panorama, and some of them will also be using SAML for authentication. Since public certificates will ne...

kosarbnu by • L1 Bithead
  • 243 Views
  • 1 replies
  • 0 Likes

Automating Tasks in PA

Hello, Is there a way to automate tasks in Palo Alto PANORAMA? For example, I want to create a script that allows me to add a “bulk list of objects”—including both IP addresses and domains—and then add them to an existing group. The goal is to automate the blocking of security bulletins that arrive in our email inboxes every day. Doing this manu...

GP Agent Machine Certificate Check

Hello, I am trying to find out more information about a GP portal setting called Machine Certificate Check under Portal Configuration / Agent / Agent Config / Config Selection Criteria / Device Checks. I was hoping to use a machine certificate check outside of the authentication tab to allow or disallow machines based on user/user group, but I...

Need help in validating XQL query to identify suspicious MFA registration from new GEO location + new device

dataset = okta_sso_raw| filter (debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE") and (eventType in("user.mfa.factor.activate", "user.lifecycle.create", "system.import.user.create"))| alter user_id = if(eventType = "user.lifecycle.create" or eventType = "system.import.user.create", json_extract_sc...

Cortex XDR Post-Quantum

Hi team, I would like to inquire about formal information and guidance regarding the post-quantum cryptography (PQC) strategy within the Cortex XDR ecosystem. What developments, features, or updates planned on the Cortex roadmap could you share with us? Is there currently any functionality, pilot, or integration in the console or agents that add...

Help with file blocking security profiles

Hello everyone, Let me say I am new to the live community, I am trying to figure out if possible to Block file downloads using the "File download" security profile. I enabled it added it to my in to out policy and it still downloaded the files. After doing some more research I found out that the "Allow HTTP partial response" is enable it w...

GlobalProtect Release for Ubuntu 26.04 LTS ?

Hello together.recently was the new Ubuntu 26.04 LTS release, until now the provided GlobalProtect client supports only Ubuntu 24.04:https://docs.paloaltonetworks.com/compatibility-matrix/reference/globalprotect/where-can-i-install-the-globalprotect-app?otp=linux#linux When can we expect the new GlobalProtect version for Ubuntu 26.04 ? Best re...

Github EDLs missing IPs?

Hi everyone, we've been using the Palo Alto managed GitHub EDL to allow access to GitHub and recently noticed some connections being blocked because the destination IPs aren't covered by the EDL. For example, we see successful connections to addresses like 140.82.121.x that are allowed from the EDL, but also connections to 20.250.119.67 and ...

Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback

Hello Everyone, We are currently evaluating Prisma Access as a replacement for our traditional GlobalProtect deployment and are considering using Prisma Access as our primary cloud-delivered security platform for remote users. Our goal is to leverage the full security stack, including: URL Filtering WildFire DNS Security Advanced Threat Preve...

Clarification on Strata Logging Service and eDLP Log Forwarding

Hi Team, We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them. I have a few questions regarding how Strata Logging Service (SLS) works. We currently support Prisma Access using SLS. Wh...

Does the firewall need to have Panorama IPs in its permitted IP list for MGMT interface?

Does the firewall need to have Panorama IPs in its permitted IP list for MGMT interface? I tested and it seems I only need Panorama to allow FW IP. But from the article below for MGMT interface profile it mentions adding Panorama IP is required. https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-m...

nahiar by • L1 Bithead
  • 158 Views
  • 4 replies
  • 0 Likes

Upcoming Fuel Events

Top Solution Authors
Top Contributors