Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24416 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

176 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

804 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5211 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

655 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

575 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

4604 Posts

Activity in Discussions

Commit failed and firewall now down after reboot

Hi, I have a weird issue on a cluster of two firewalls on active/active mode. Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck. On the secondary I tried to commit localy and I had this error : Unable to generate IKE VPN transform(Mod...

PA-220 Login issue

Hi Everyone We have a load of PA-220's in HA at variuos different sites, after a set period of time the devices stop allowing use to login. Does not matter what method of Auth we try, it just does not work. To compond the problem, if we do not resolve this issue eariler enough both devices at the site go offline taking the whole site down. ...

R.Moth by L0 Member
  • 22 Views
  • 0 replies
  • 0 Likes

Prisma Access HIP object Windows patch management

We have created a HIP profile and configured windows patch management. However, the options under this is not very clear. I have to get some clarifications on thisMissing Patches - Severity When the operator is set to Greater Than or Equal To, what values are valid in the field? We currently use 3, assuming this represents Critical Windows sec...

GlobalProtect Fails During Pre-Login with WinHttpReceiveResponse Error 12152

GlobalProtect is unable to connect during the pre-login phase. Verified all required certificates are installed on the endpoint. Confirmed certificates are located in the appropriate certificate stores. Collected and reviewed: GlobalProtect logs TSF Firewall packet captures We got the following error in PanGPS.log:2 3(P5136-T8916)Debug(54...

Verification of Panorama (HPV) Upgrade Procedure

Attention:Global TPM team,Environment:Existing Panorama HPV environmentCurrent version: 11.2.7-h2Target version: 12.1.4-h3 We received an inquiry from a customer regarding an upgrade from Panorama 11.2.7-h2 to 12.1.4-h3.First, we provided the base image Panorama-HPV-12.1.2.vhdx, followed by the base OS Panorama_pc-12.1.2 and the target version...

PA-460 VERSION 11.1.13-H7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 40 Views
  • 0 replies
  • 0 Likes

HA FW on AWS

I want to deploy two firewalls on AWS, in different availability zones. I understand from the guide that this isn't recommended, but that it is supported. I've managed to complete the deployment without any issues. However, I have some questions. Since it’s not possible to move an ENI between AZs, if there’s a failure with FW-A or AZ-A, FW-B wil...

pa-460 version 11.1.13-h7

Hi Team, please help me out with this issue an incident occurred on the PA-460 version 11.1.13-h7 A firewall, initially associated with intermittent issues on the Internet connection provided by Totalplay.During the incident analysis, it was determined that it was not possible to access the firewall’s graphical management interface. Access via ...

F.Pinar by L3 Networker
  • 66 Views
  • 0 replies
  • 0 Likes

Long Running Integration

Is it possible in xsiam to make a custom data collection integration use the long running integration option (https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Developer-Guide/Long-Running-Containers) or is that only available for integrations that palo alto networks provides? Is this an effective way to get over the 10min doc...

HTTP partial response - Security protection bypass

The Palo Firewall supports HTTP partial response and is enabled by default, best practice is to disable HTTP partial response but this is a global setting. Doing so will break access to numerous internet based systems like youtube, and a number of other systems that utilise chuck encoding, including palo's own content updates. When HTTP parti...

DaMonk by L1 Bithead
  • 70 Views
  • 0 replies
  • 0 Likes

Alternate of Expedition Tool

Hello Palo Alto Networks Community, I would like to introduce PAN-Tool, a web-based platform designed to simplify multi-vendor firewall migration and Palo Alto Networks configuration conversion. Many engineers currently use tools like Expedition for configuration migration and optimization. PAN-Tool is built with a similar objective — providing ...

Issues with connectivity between HA PAs and Nexus Leaf Switches

I've inherited a setup which has PAs with two vsys each connecting:external switch/router > PA external vsys > A10 Load Balancers > PA internal vsys > Cisco Nexus Leaf switches We run a full mesh setup (1x interface from each side of the PA HA pair to each (upstream switch, external A10, internal A10) internal device, both primary an...