Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24302 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

175 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

781 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5739 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

647 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

551 Posts

Cloud Native Application Protection

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Cloud and Cloud Identity Engine discussions.

470 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

3958 Posts

Activity in Discussions

GlobalProtect Name Normalization issue

Hello, I have set up GlobalProtect using AZURE SSO for the sign in and for group mapping I am using LDAP. However, in the GPSVC logs, I see users being returned as domain\\username2 slashes. This is causing issues with users not being able to get a client config as I am putting users in specific subnets according to their AD membership.The usern...

PAN-OS-PHP Combining actionss

Hi I am trying to use the PAN-OS-PHP to bulk edit some rules. My question is can I chain/combine actions together. The documentation says that I can but when I try I get a syntax error Before I send the command to the Firewall I just want to check the rules that will be updated I don't think I am to far away but its just the sytax. If a...

PAN-OS-PHP-Action.jpg

PAN-OS 12.1, IPv6 and Region/GeoIP

Hi, With PAN-OS 12.1, IPv6 addresses are now also showing what Region they belong to. However, this seems to be limited to logs. Security policies, using specific regions/countries, will still not match the IPv6 addresses, even though the same IPv6 addresses shows the appropriate country code in the logs. Is this a known issue (internally perh...

Submit false positive - Generic.ml

File hash:946489974ee15fc44d6257edc16ba101ea5b167a2001e7d94ec0594d7fc518f5 Link to VirusTotal report:https://www.virustotal.com/gui/file/946489974ee15fc44d6257edc16ba101ea5b167a2001e7d94ec0594d7fc518f5/detection Current VirustTotal Verdict: Generic.ml Description: This 32 bit file is a component file of the text-to-speech software Panopreter at ...

woeruw by L1 Bithead
  • 58 Views
  • 0 replies
  • 0 Likes

Microsoft Photos.exe

Hi, Does anyone experience receiving alerts from photos.exe due to "Suspicious File Modification" and the Module is "Anti-Ransomware Protection" even the program is legitimate?Other factors I'm seeing is due to possibly outdated version of the said program. *See attached reference photo*I'm hoping from anyone's advice from other members with the...

J.Indoc by L0 Member
  • 92 Views
  • 1 replies
  • 0 Likes

Cortex XDR Device Control Violation Alerts

Hi All, We enabled device configurations to block external devices connecting to endpoints in the organization and its work fine. In the Cortex XDR console, I can see the device control violations. We want to create alerts to detect the Device Control Violation based on a BIOC rule, as this is the only available option. I tried several...

Device Certificate Enforcement Issue Encountered

Hi, I am following the instructions to apply the device certificate, but I am blocked by the following error:“Unable to execute OTP install operations command to some firewalls. Please identify the firewalls that failed the process from Panorama and retry OTP.” I followed the instructions provided in this link:https://live.paloaltonetworks.com/t...

Unable to apply Device Certificate

Hi Everyone, I am following the instructions to apply the device certificate, but I am blocked by the following error:“Unable to execute OTP install operations command to some firewalls. Please identify the firewalls that failed the process from Panorama and retry OTP.” I followed the instructions provided in this link:https://live.paloaltonetwo...

Expired license CDSS

Hello, we received an alert regarding the expiration of CDSS licenses on February 11, 2026, following a change in operation on the Palo Alto side. All our equipment is running at least version 10.2.13-h5. The partner portal does not show any affected devices. We would still like to know if this will have any impact on certificate management, act...

Windows Update - automatic policy without manual address definition

Hi,is there a way on Palo Alto firewalls to allow Windows Update traffic without manually defining a list of addresses?For example, is it possible to create a policy that automatically determines or updates the list of these addresses, without requiring manual administrator intervention?I would appreciate any information on whether such solution...

Management IP address is getting changed

Hi All, Kindly help me troubleshoot the issue related to a Management IP address is getting changed automatically in Firewall. We have 2 devices are in active-passive mode and managed by Panorama. But somehow passive device Management IP is getting changed to active device IP automatically.

Vulnerability assessment report

Hello, In viewing this report I've noticed its still flagging servers that have been patched already and wondering how often that checks against all endpoints? I can go on a server and its not showing any updates needed and then look in the report and its in there showing it needs 68 updates which all come from a cumulative update (windows) but ...

Notepad++ block specific hash version

Guys, Does anyone know if it is possible to block the hashes associated with older versions of Notepad++? My goal is to allow only Notepad++ version 8.9.1 to be executed, and to block the installation and execution of all other versions.

tlmarques by L4 Transporter
  • 294 Views
  • 3 replies
  • 0 Likes