• 526,768 Members
  • 946 Online
  • 1,132,009 Posts
  • 19,737 Solutions
  • 53,571 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

How to block all AI-based applications

Hi Team, 1) We have a customer who wants to block all AI-based applications but the applications are not getting blocked.2) Initially, we created a application group policy in Security Policy and added all AI-based applications with action as deny. After commit the AI applications were getting blocked successfully. However, Claude AI was still a...

How to build SCM Managed NGFW with no management internet access

I am trying to deploy a Palo Alto VM-Series firewall and manage it with Strata Cloud Manager (SCM). The challenge is that I only have a single internet-connected port available in my cloud environment, while the management interface has no internet access. Ideally, I would like to keep the management interface private so that I can manage the fi...

Help with file blocking security profiles

Hello everyone, Let me say I am new to the live community, I am trying to figure out if possible to Block file downloads using the "File download" security profile. I enabled it added it to my in to out policy and it still downloaded the files. After doing some more research I found out that the "Allow HTTP partial response" is enable it w...

VPN Issues with SAP

I got intermitent connection affecting production PA-5220 VERSION 11.1.13 . Global protect 6.2.8-1045 troubleshooting : The VPN tunnel temporarily disconnected and routing entries associated with the tunnel were removed. The GlobalProtect client subsequently recreated and reconfigured the virtual adapter. A new IP address assignment was re...

F.Pinar by • L3 Networker
  • 33 Views
  • 0 replies
  • 0 Likes

Globalprotect for Android failing to connect

We're having an issue with GP where all other clients (Windows, Linux, MacOS, iOS) are able to connect with the exception of android devices. Users authentication successfully, get the MFA prompt from DUO, and then get this error: The network connection is unavailable or the gateway is unresponsive. Check the network connection and reconnect. ...

Pre-Logon Behavior with SAML Login

I recently found interesting behavior in GlobalProtect with pre-logon when using SAML. I started off by following these instructions: Remote Access VPN with Pre-Logon The customer I was working with had certificates in the user-store they did not want to access during pre-logon or user login. We specified "Machine" in the "Client Certificate ...

I am facing an issue during the upgrade Panorama (PANOS 11.1.4-h7) to PANOS 12.1.7

I am facing an issue during the upgrade Panorama-VM (PANOS 11.1.4-h7) to PANOS 12.1.7, After uploaded PANOS version 11.2.10 base version able to upgrade successfully to PANOS 11.2.10-h13. After that when try to upgrade to PANOS 12.1.7 and uploaded images it gives an error "Failed to load image into software manager" If anyone faced this issue...

Gourab_H by • L1 Bithead
  • 77 Views
  • 2 replies
  • 0 Likes

Cortex XDR Linux Agent: IPC error 107 caused by SELinux denying execution of pmd

Cortex XDR Linux Agent – IPC error 107 / traps_pmd.service failed to start Environment Palo Alto Networks Cortex XDR Agent for Linux Oracle Linux SELinux: Enforcing /opt: XFS /opt was mounted without noexec Symptoms After installing the Cortex XDR Agent, cytool status failed with: Failed to get status summary data from the agent, err...

Failed Connection

Is anyone else seeing "Failed Connections" fire on iphlpsvc after [an agent/content update / IPv6 GPO change]? Did a specific content version introduce it? What's the recommended tuning approach here — an alert exclusion/exception scoped to iphlpsvc, or addressing the underlying network/IPv6 config so the failures stop?

Fuel Technical Alliance: FireMon - Better Policy. Less Complexity.

2 min read

On September 24th, Fuel hosted another great Fuel Technical Alliance (FTA) event where we heard from FireMon about how they can help improve your security posture by removing stale and unused policies, assist with security audits, and more! Our speakers, Tim Woods, Vice President of Technology Alliances and Ricardo Fierro, Sales Engineer Team...

FTA - FireMon - September 2026.png

Virtual Test Lab

1 min read

The Virtual Test Lab (VTL) offers an environment where users can practice and get familiar with the Palo Alto Networks Next-Generation Firewall. The pre-built lab environment provides access to a Windows Server OS, two Linux server OSes and a Palo Alto Networks Next-Generation Firewall. It allows users a fully isolated environment to freely con...

Masharad by • L4 Transporter
  • 121384 Views
  • 74 replies
  • 19 Likes

Website blocked automatically by the firewall

I am using PA-410. In our network, one specific website is blocked automatically by the firewall. I created a URL filtering, added URLs to the whitelist, and allow in the profile. Nevertheless, users cannot access the website. When I monitor the traffic, there is "undecided" in front of the application. End Reason is unknown. State is Active.Cou...

gdu_palo by • L1 Bithead
  • 223 Views
  • 5 replies
  • 0 Likes

sizing firewall

Hi,I am looking for a firewall for 3000 users, and 500 vdi access expecting approximately igb internet traffic Please help to size,Ho much throughput I needed Thanks

simsim by • L4 Transporter
  • 12631 Views
  • 7 replies
  • 0 Likes

Upcoming Fuel Events

Top Solution Authors
Top Liked Authors
Top Contributors