• 524,708 Members
  • 2,519 Online
  • 1,131,016 Posts
  • 19,637 Solutions
  • 53,401 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

How to check Cloud NGFW for Azure OS upgrade history

We are using Palo Alto Cloud NGFW for Azure and need to verify the OS/software upgrade details for our deployed firewalls. Could you please let us know: How to check the current PAN-OS/software version running on Cloud NGFW? Where can we find the OS upgrade start time and end time for previous upgrades? Are upgrade logs available in Azure Porta...

Palo Alto Networks Announces Cloud NGFW Credit Unification

4 min read

Cloud NGFW is a cloud-native Next-Generation Firewall fully managed by Palo Alto Networks. Starting August 2026, Palo Alto Networks customers can use Software NGFW (VM-Flex) credits to fund Cloud NGFW for AWS and Azure resources. This feature establishes a single, unified currency for both Software NGFW and Cloud NGFW services, offering unmatche...

title.png
tenant usage details.png
SmartCredit Used.png
bcreado by L0 Member
  • 44 Views
  • 0 replies
  • 0 Likes

Resolved! [SOLVED] THE NGFW's DHCP SERVER AND DHCP RELAY SUDDENLY ARE NOT WORKING!!

Hello, LiveCommunity team! I created this post to share my experience with an issue on our branch PA-1420 NGFW, which is configured to act as both a DHCP server on the ethernet1/4 interface and a DHCP relay agent, but suddenly stopped working! About 20 days ago, our DHCP server and DHCP relay agent stopped functioning as expected. We use our PA ...

DanielSRomero_2-1789087056190.png

Quest Asc - TSF Upload take forever

I am trying to upload a TSF to the Quest Asc tool, The TSF is 120 MB. When I upload no error but it keeps spinning. I have tried it few times and no luck. I have a good stable internet and good upload/download speed. Tried different browser but no luck. The only thing I can think off is Netskope but don't see any blocks either.

ArunKu by L0 Member
  • 1033 Views
  • 4 replies
  • 0 Likes

High availability failover: GARP doubts.

Hey guys!. First time poster here.To begin with, I am beginner to PA and learning my way through. I have just reached the HA part, and have a few questions.In an active/passive deployment, when the Active unit fails and the Passive unit starts taking over, it sends GARP and updates the downstream/ (upstream?) switches CAM tables with the new in...

Nadeem69 by L0 Member
  • 1481 Views
  • 2 replies
  • 0 Likes

Idira and Cortex XSIAM: Partner Integration Framework for Identity Signal Correlation

Partner integration framework for operationalizing identity signals from #Idira (the Palo Alto Networks identity platform, built on the CyberArk acquisition and launched at IMPACT 2026) into #CortexXSIAM for detection and automated response. What the framework covers Technical integration pattern for Idira identity signal ingestion into XSIAM S...

Screenshot 2026-09-09 at 2.42.03 PM.png
vvadwlas by L2 Linker
  • 115 Views
  • 2 replies
  • 0 Likes

Unable to Commit Changes after Installing New Certificate

I was asked to assist with a new wildcard certificate that was uploaded to the firewall yesterday, update the SSL/TLS Service Profile and confirmed settings for GP. Commit failed so began reviewing configuration. The 2 reasons listed for the failure were: client useridd phase 1 failureclient gp_broker phase 1 failure Double checking and the...

DJ_1924 by L2 Linker
  • 214 Views
  • 4 replies
  • 0 Likes

AI Visibility with On-Premise NGFW

Looking for recommendations or best practice items for monitoring/searching for AI usage through on-premise NGFWs. Standard app-id/URL classifications already being used, but is there anything else that might help or make things more visibile?

Looking for XSIAM Demisto SDK

Hello everyone!We develop custom integrations for Cortex clients.We have always used the XSOAR Demisto SDK (https://xsoar.pan.dev/docs/reference/api/demisto-class). However, we now need to write integrations for XSIAM, and we suspect that, as XSIAM is a much larger platform than XSOAR, its Demisto SDK will have more features.We can’t find this S...

Globalprotect Portal not generating cookie after login

Hi everyone,i ran over an cookie generation issue with my GlobalProtect Portal.To minimize login requests we are generating Authentication override cookies on the portal side and set the lifetime on the gateway side to 5 minutes.The first time i connect to the portal (windows client) the cookie is issued and logged in gp logs 'portal-gen-cookie'...

Resolved! Monitoring new network interface connections (USB NICs) via BIOC / XQL — Looking for best practices

Hi everyone,I am looking for guidance or community insights on how to monitor and track the connection and usage of networkndevices (especially USB Ethernet adapters, Wi-Fi dongles, and USB tethering) on Windows endpoints. Our goal is to detect whenever a new network interface is attached/enabled, capture its timestamp, and ideally trigger an al...

FWs no longer forwarding logs to Panorama

Not sure what happened but it seems that all my firewalls stop sending logs to panorama (local log collector). I have a ticket open with PAN support but not really getting anywhere. Recently upgraded PANORAMA to 11.1.13-h3 and added additional collector disks to PANORAMA. Also forwarded logs from PANORAMA log collector to our syslog serv...

drewdown_0-1788476521190.png
drewdown_2-1788476742998.png
drewdown_1-1788476583659.png
drewdown_3-1788476808559.png
drewdown by L4 Transporter
  • 158 Views
  • 2 replies
  • 0 Likes

Antivirus mismatch without license

We have a cluster of firewalls with an antivirus mismatch alert. The thing is that there is no antivirus license.This issue happpened after one of the nodes went down and we had to perform a factory reset. We are seeing this by cli: av-version: 0 av-release-date: threat-version: 0 threat-release-date: 2025/02/10 19:10:10 CET I know it does not a...

Is it possible to have 2 portals and 2 gateways, each for different "VPN" connectivity and users?

Hi, hoping someone can guide me. I am trying to see if it's possible to have, basically, 2 VPN's on the same firewall. One portal/gateway would be for employees using radius/AD/DUO authentication and the new one would be for consultants. Same authentication methods although the consultants would be in a different AD group for auth/DUO. Basically...

Upcoming Fuel Events

Top Solution Authors
Top Contributors