Discover LIVEcommunity — Watch Now

  • 493,398 Members
  • 3,254 Online
  • 171,084 Posts
  • 18,106 Solutions
  • 50,617 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Asymmetric Routing - Palo Edge Firewall Active/Passive to Nexus Core

We have (2) equal cost L3 links from our Nexus core switches to an upstream Palo edge firewall HA pair, active/passive. On the firewall, this is an aggregation ethernet with layer 3 subinterfaces defined. There is an SVI on each Nexus switch for routing with a layer 2 port-channel to a breakout switch in between the firewall and core, and we ar...

Does User ID Agent 10.2.4 compatible with PAN OS 11.1.13?

I’m planning to upgrade my PA-440 from PAN-OS 10.2.8-h3 to 11.1.13. Based on what I’ve read, PAN-OS 11.1.13 is not compatible with my existing User-ID Agent version 10.2.4. I tried upgrading the User-ID Agent to version 11.0.3, but I encountered an error saying “The RPC server is unavailable.” Previously, there were no issues when using User-ID ...

Global Protect Connectivity Issue

I am deploying GlobalProtect and have configured the Gateway Agent Client Settings with the following Source User in the Config Selection Criteria: connect\vpnusers I am a member of this group. The group is retrieved from our internal LDAP server via User Identification → Group Mapping, with the following attributes configured: Primary Usernam...

H.Thiam by L1 Bithead
  • 2013 Views
  • 5 replies
  • 0 Likes

PAN-OS 11.1.13 Predefined reports displaying IPv4 addresses in IPv6 format

We have been experiencing an intermittent problem with our nightly predefined reports displaying IPv4 addresses in IPv6 format.An IPv4 address like 192.168.1.1 is being displayed as an IPv6 address like ::0101:a8c0:ffff:0 We are currently running PAN-OS 11.1.13 but we have seen this same behavior under 11.1.12. Behavior like this apparently ha...

Cortex XSIAM XQL: How to find incidents where playbook failed / errored?

I’m new to Cortex XSIAM and XQL, and I’m still learning how things work. I need some help with an XQL query. I’m trying to create an XQL query where I can see: Incident ID, Incident name , Playbook execution status (failed / error), Playbook name, Error message or failure reason (if available). I checked the incidents dataset, but I couldn’t f...

R_BhlpMe by L0 Member
  • 181 Views
  • 0 replies
  • 0 Likes

Strange Gateway change issue on network with Prisma Access GP Client

Having some strange behavior with GP client 6.3.3-711 that runs within the prisma access product. When user is on network, or in office, gp changes gateways at times and changes the timezone of the client computer. The client doesn't have issues off network like at coffee shop or home. Not sure what's going on. I am not using any internal host d...

How to Configure XQL to detect logs not reporting rule

I am able to retrieve logs successfully using XQL in Cortex XSIAM.However, I need to configure an analytics rule that triggers when any single expected source stops sending logs (for 10 minute,1 hours,4 hours). Detect when any one host / source stops reporting logs Alert should be raised per missing entity Should work with Scheduled Analyt...

XSIAM Dashboard

Hi, I'm working on creating a dashboard for the concept below. Has anyone already tried this or have any insights they can share? sudden spike for data ingestions Data ingestion exceeded threshold Data source with correlation rules per source

Palo Alto to Azure vpn tunnel fails at random

We installed a PA 3440 at a customer site which is being used to create a VPN tunnel with Azure. Two links have been configured in fail over mode (currently manual). The VPN tunnel fails randomly and needs to be rest manually. we have raised the case with PA who are struggling with logs since last 2 weeks without a fix. Basic configuration of...

Virtual Test Lab

The Virtual Test Lab (VTL) offers an environment where users can practice and get familiar with the Palo Alto Networks Next-Generation Firewall. The pre-built lab environment provides access to a Windows Server OS, two Linux server OSes and a Palo Alto Networks Next-Generation Firewall. It allows users a fully isolated environment to freely con...

Masharad by L3 Networker
  • 57820 Views
  • 39 replies
  • 12 Likes

False positive : HelpDesk Viewer

A false positive has been detected for HelpDeskViewer.exe. File Hash: <c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264> Link to Virustotal report for the file: <https://www.virustotal.com/gui/file/c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264/details> Current VirustTotal Verdict: <Generic.ml&...

False positive (generic.ml): HelpDesk Viewer

A false positive has been detected for HelpDeskViewer.exe. File Hash: <c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264> Link to Virustotal report for the file: <https://www.virustotal.com/gui/file/c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264...> Current VirustTotal Verdict: <Generic.ml> D...

Gowtham by L1 Bithead
  • 2113 Views
  • 2 replies
  • 0 Likes

Upcoming Fuel Events

Top Solution Authors
Top Contributors