• 524,408 Members
  • 1,389 Online
  • 1,130,854 Posts
  • 19,623 Solutions
  • 53,379 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

MSSP Deployment Reference: Cortex XSIAM and Cortex Cloud Multi-Tenant Operations Guide

Field-developed operational reference for multi-tenant #CortexXSIAM and #CortexCloud deployments in MSSP environments. In operational use with MSSP partners across NAM, EMEA, and APAC. What the guide covers Multi-tenant architecture patterns for XSIAM and Cortex Cloud Licensing model considerations for master and child tenant separation Onboard...

Screenshot 2026-09-09 at 1.45.25 PM.png

Migration Panorama from ESXi to Nutanix AHV

We're currently looking at replacing our VMWare ESXi hypervisors with Nutanix AHV hypervisors. We are currently using Panorama in VM mode. 1. Do you know whether Panorama is Nutanix AHV-compatible? Does the publisher support the Nutanix AHV hypervisor (or Redhat KVM)? 2. If yes, does Panorama support migration from VMWare to Nutanix AHV with Nut...

Mamoudou by L2 Linker
  • 7669 Views
  • 12 replies
  • 1 Likes

Resolved! Fast Path vs Slow Path with Content ID

Hi, newish to Palo Alto so trying to understand the demarcation between Fast-Path and Slow path when using Content ID. My understanding is that when a new traffic flow starts App-ID is used to determine the application and once the flow is established traffic moves to Fast path. Am I right though that if Content-ID is used that the traffic m...

Browser Extension Exfiltration Lab

Companion lab to the MCP Prompt Injection Kill Chain, focused on malicious browser extensions attempting credential exfiltration. What the lab covers Five distinct attack patterns, all inert, walking through how a malicious browser extension attempts credential theft under different technique variations. Each pattern includes XSIAM correlation w...

browser_extension_detection_layers.png

Cortex AES: MCP Prompt Injection Kill Chain - Self-Provisioning Lab for Agentic AI Attack Demonstration

Self-provisioning demonstration lab that walks partners through an end-to-end agentic AI attack scenario and shows how #CortexAES catches the threat across the four-layer detection model. The scenario Tool description mismatch in a Model Context Protocol (MCP) integration leads to credential exfiltration. The lab demonstrates the full kill chain...

mcp_kill_chain_detection_layers.png
vvadwlas by L1 Bithead
  • 17 Views
  • 0 replies
  • 0 Likes

Cortex Portfolio: Partner Opportunity Cockpit - Five-Layer Scoping Surface for First Meetings

First-meeting scoping tool for MSP and GSI partners running discovery conversations with new prospects. Structures the opportunity across the Palo Alto Networks platform - #Strata, #Cortex (including #CortexCloud), and #Idira - using a five-layer cybersecurity taxonomy. What the tool does Five-layer landscape - every PANW product across Strata,...

Screenshot 2026-09-09 at 11.45.44 AM.png
vvadwlas by L1 Bithead
  • 21 Views
  • 0 replies
  • 0 Likes

Cortex AES (Koi): AES Compass - Three-Question Routing Tool for Partner Enablement

Lightweight routing tool that surfaces the right #CortexAES (formerly Koi) field enablement resource from a curated library in three questions and about thirty seconds. What the tool does Partners answer three quick questions - role, conversation stage, and biggest gap - and the tool routes to the best-match resource: sizing guide, technical dem...

Screenshot 2026-09-09 at 11.15.19 AM.png
vvadwlas by L1 Bithead
  • 19 Views
  • 0 replies
  • 0 Likes

Cloud-to-SOC Reference Implementation - GCP Edition: Self-Provisioning Partner Lab for Cortex

Cloud-to-SOC Reference Implementation - GCP Edition A self-provisioning Google Cloud Platform lab that generates real Cortex Cloud posture, runtime, and identity signals into #XSIAM cases within about an hour of setup. Partners spin up the lab in their own GCP environment as a presales proof surface - no PANW resource required to demonstrate the...

vvadwlas by L1 Bithead
  • 42 Views
  • 1 replies
  • 0 Likes

XSIAM + AgentiX: CU Intelligence Platform for Partner Sizing Conversations

Interactive web tool for sizing Cortex Compute Unit consumption across #XSIAM, #AgentiX, and MSSP multi-tenant deployments. Built from partner field engagement and developed with input from Palo Alto Networks product management. What the tool does Models CU allocation across multiple tenants for MSSPs running downstream customer workloads Proje...

Screenshot 2026-09-09 at 11.02.28 AM.png
vvadwlas by L1 Bithead
  • 21 Views
  • 0 replies
  • 0 Likes

Globalprotect Portal not generating cookie after login

Hi everyone,i ran over an cookie generation issue with my GlobalProtect Portal.To minimize login requests we are generating Authentication override cookies on the portal side and set the lifetime on the gateway side to 5 minutes.The first time i connect to the portal (windows client) the cookie is issued and logged in gp logs 'portal-gen-cookie'...

FWs no longer forwarding logs to Panorama

Not sure what happened but it seems that all my firewalls stop sending logs to panorama (local log collector). I have a ticket open with PAN support but not really getting anywhere. Recently upgraded PANORAMA to 11.1.13-h3 and added additional collector disks to PANORAMA. Also forwarded logs from PANORAMA log collector to our syslog serv...

drewdown_0-1788476521190.png
drewdown_2-1788476742998.png
drewdown_1-1788476583659.png
drewdown_3-1788476808559.png
drewdown by L4 Transporter
  • 114 Views
  • 1 replies
  • 0 Likes

Gateway certificate issue on Android Globalprotect

I've currently got a support case open for this, but I'm trying to see if other users are having the same issue. From what I've seen: 6.1.11 - No issue 6.1.12 - No issue 6.1.13 - Issue Occurs 6.1.14 - Issue Occurs (current version on Play Store) The issue seems to be that the client doesn't trust the certificate for the gateway. I'm not s...

jsalmans by L4 Transporter
  • 324 Views
  • 6 replies
  • 0 Likes

Whitelisting AI?

Hi, is there a way for XDR to create an AI whitelist so that only access to permitted AI executables is allowed and everything else automatically blocked?

Idira Secure Cloud Access Pre-Implementation Checklist

1 min read

Preparing to implement Idira Secure Cloud Access? Palo Alto Networks Idira® is the next-generation identity security platform designed to help organizations discover, control, and govern access across human, machine, and agentic identities. As part of your Idira Secure Cloud Access implementation, completing the necessary prerequisites ahead ...

sprince by L1 Bithead
  • 46 Views
  • 0 replies
  • 0 Likes

few remote users on global protect 6.2.8-c948 are facing connectivity issue "the network connection is unreachable or the portal is unresponsive

few remote users on global protect 6.2.8-c948 are facing connectivity issue "the network connection is unreachable or the portal is unresponsive. The global protect logs doesn't show any errors but users are facing difficulties connecting to the global protect VPN.

Upcoming Fuel Events

Top Solution Authors
Top Contributors