• 524,820 Members
  • 1,712 Online
  • 1,131,049 Posts
  • 19,638 Solutions
  • 53,406 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

User-ID in FIPS-CC

Hello, I am having an issue setting up user-id when the firewall is in FIPS-CC mode. Here is the following issue: Environment: PA-3440, PAN-OS 11.2.10-h7, FIPS-CC mode enabled Windows User-ID Agent v11.0.3-134 (identical version on both hosts) Issue:I have two Windows-based User-ID Agents configured under Device > Data Redistribution &g...

PAM for Full Databases Office Hours Slide Deck- September 2026

1 min read

View the slide presentation from our Success Office Hours that took place September 9, 2026. The session focused on modernizing the database identity security lifecycle using Idira® Privileged Access Manager SaaS, by Palo Alto Networks. We will explore how organizations can automate discovery, streamline credential rotation without heavy legacy ...

sprince by L2 Linker
  • 101 Views
  • 0 replies
  • 0 Likes

How to check Cloud NGFW for Azure OS upgrade history

We are using Palo Alto Cloud NGFW for Azure and need to verify the OS/software upgrade details for our deployed firewalls. Could you please let us know: How to check the current PAN-OS/software version running on Cloud NGFW? Where can we find the OS upgrade start time and end time for previous upgrades? Are upgrade logs available in Azure Porta...

PAN-OS 11.1.16, Unable to connect to VPN Portal or Gateway, winhttpObj, error!

We have a NGFW hosted by Rackspace in the US. Any new attempt to connect to the Global Protect gateway portal fails. We can ping and tracert to the I.P. address and domain of the gateway, but whenever we go to connect via the Global Protect VPN client or we attempt to go to the web portal via browser the connection fails with an EMPTY_RESPONSE. ...

josh by L0 Member
  • 52 Views
  • 0 replies
  • 0 Likes

Palo Alto Networks Announces Cloud NGFW Credit Unification

4 min read

Cloud NGFW is a cloud-native Next-Generation Firewall fully managed by Palo Alto Networks. Starting August 2026, Palo Alto Networks customers can use Software NGFW (VM-Flex) credits to fund Cloud NGFW for AWS and Azure resources. This feature establishes a single, unified currency for both Software NGFW and Cloud NGFW services, offering unmatche...

title.png
tenant usage details.png
SmartCredit Used.png
bcreado by L0 Member
  • 326 Views
  • 0 replies
  • 0 Likes

Resolved! [SOLVED] THE NGFW's DHCP SERVER AND DHCP RELAY SUDDENLY ARE NOT WORKING!!

Hello, LiveCommunity team! I created this post to share my experience with an issue on our branch PA-1420 NGFW, which is configured to act as both a DHCP server on the ethernet1/4 interface and a DHCP relay agent, but suddenly stopped working! About 20 days ago, our DHCP server and DHCP relay agent stopped functioning as expected. We use our PA ...

DanielSRomero_2-1789087056190.png

Quest Asc - TSF Upload take forever

I am trying to upload a TSF to the Quest Asc tool, The TSF is 120 MB. When I upload no error but it keeps spinning. I have tried it few times and no luck. I have a good stable internet and good upload/download speed. Tried different browser but no luck. The only thing I can think off is Netskope but don't see any blocks either.

ArunKu by L0 Member
  • 1048 Views
  • 4 replies
  • 0 Likes

High availability failover: GARP doubts.

Hey guys!. First time poster here.To begin with, I am beginner to PA and learning my way through. I have just reached the HA part, and have a few questions.In an active/passive deployment, when the Active unit fails and the Passive unit starts taking over, it sends GARP and updates the downstream/ (upstream?) switches CAM tables with the new in...

Nadeem69 by L0 Member
  • 1504 Views
  • 2 replies
  • 0 Likes

Idira and Cortex XSIAM: Partner Integration Framework for Identity Signal Correlation

Partner integration framework for operationalizing identity signals from #Idira (the Palo Alto Networks identity platform, built on the CyberArk acquisition and launched at IMPACT 2026) into #CortexXSIAM for detection and automated response. What the framework covers Technical integration pattern for Idira identity signal ingestion into XSIAM S...

Screenshot 2026-09-09 at 2.42.03 PM.png
vvadwlas by L2 Linker
  • 167 Views
  • 2 replies
  • 0 Likes

Unable to Commit Changes after Installing New Certificate

I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP. Commit failed so began reviewing configuration. The 2 reasons listed for the failure were: client useridd phase 1 failureclient gp_broker phase 1 failure Double checking and the...

DJ_1924 by L2 Linker
  • 237 Views
  • 4 replies
  • 0 Likes

AI Visibility with On-Premise NGFW

Looking for recommendations or best practice items for monitoring/searching for AI usage through on-premise NGFWs. Standard app-id/URL classifications already being used, but is there anything else that might help or make things more visibile?

Looking for XSIAM Demisto SDK

Hello everyone!We develop custom integrations for Cortex clients.We have always used the XSOAR Demisto SDK (https://xsoar.pan.dev/docs/reference/api/demisto-class). However, we now need to write integrations for XSIAM, and we suspect that, as XSIAM is a much larger platform than XSOAR, its Demisto SDK will have more features.We can’t find this S...

Globalprotect Portal not generating cookie after login

Hi everyone,i ran over an cookie generation issue with my GlobalProtect Portal.To minimize login requests we are generating Authentication override cookies on the portal side and set the lifetime on the gateway side to 5 minutes.The first time i connect to the portal (windows client) the cookie is issued and logged in gp logs 'portal-gen-cookie'...

Resolved! Monitoring new network interface connections (USB NICs) via BIOC / XQL — Looking for best practices

Hi everyone,I am looking for guidance or community insights on how to monitor and track the connection and usage of networkndevices (especially USB Ethernet adapters, Wi-Fi dongles, and USB tethering) on Windows endpoints. Our goal is to detect whenever a new network interface is attached/enabled, capture its timestamp, and ideally trigger an al...

Upcoming Fuel Events

Top Solution Authors
Top Contributors