Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24426 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

176 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

804 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

4969 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

655 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

578 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

4613 Posts

Activity in Discussions

User-id mapping domain name issue

Hi everyone, I recently set up GP user-id mapping in our network. It's showing domain.local\username in the logs. I was also told to set up User-ID mapping using the windows agent as well since our users would need to disconnect from GP occasionally. The logs that we get from the windows agent is domain\username. Issue now is that when we se...

Palo Alto with Azure Issue

We are having weird issue going on that we can't resolve. I would appreciate if someone can help me in this. On prem palo is connected to ISP WAN switch that has direct internet connection no other device between these two. We have on prem new Palo Alto with all configuration pulled from Azure Panorama over SD-WAN tunnel that is on on prem ...

Sending case to a third party tickiting system

Hello, i hope you re doing well i want to know the steps to send cases when there generated to our third party tickiting system , how to do it via API or weebhook. can someone already worked on a similare case share with me all the steps and configuration required. thanks in advance Cortex XDR

Does the GlobalProtect Credential Provider CLSID change between versions?

Hi all, We are considering using the Windows GPO “Assign a default credential provider” so that GlobalProtect is selected by default even on the “Other user” sign-in screen. It looks like we need to specify the CLSID (GUID) of the GlobalProtect Credential Provider in the GPO. I would like to confirm: 1. Is the GlobalProtect Credential Prov...

Cortex XDR cyjagent.dll injection causes JVM startup crash (EXCEPTION_ACCESS_VIOLATION in ntdll.dll)

We run an enterprise Java server application (Zulu OpenJDK 11, Windows Server) and are seeing consistent JVM crashes at startup on hosts protected by Cortex XDR. The agent injects cyjagent.dll (Java Deserialization Protection module) into the Java process, and the JVM crashes in native code: # EXCEPTION_ACCESS_VIOLATION (0xc0000005) # Problem...

'release-date' shows wrong timezone after Panorama push (PAN-OS 12.1.6)

Hi community, I'm seeing a minor display issue on a PA-460 (PAN-OS 12.1.6). Both the firewall and Panorama are correctly set to the JST timezone. When installing a content update pushed from Panorama, the installed versions are correct, but the release-date in the show system info CLI output goes backwards by 16 hours. However, it still displays...

I.Awano by L0 Member
  • 83 Views
  • 0 replies
  • 0 Likes

Starlink DHCP Route Injection dropping if DHCP expires briefly

This is a remote location with a Starlink connected directly into a Palo Alto 510. We have another backup satellite connection provider which should be used for emergency / comms only when Starlink goes offline. Starlink renews its DHCP lease every 5 minutes. Normally, this works fine, and gets renewed successfully without interruption. Once...

Parsing rule and data model Rule

Hi Everyone, We are currently ingesting syslog data from our Aruba switches into Cortex XSIAM/XDR using the HPE Switch content pack, but the logs are not automatically normalizing into XDM fields. In our environment, when we query other datasets like Office 365, Zscaler, or AWS, the logs are automatically parsed and normalized into xdm.* fields ...

GlobalProtect Mobile Initial SAML Authentication with ID Fails After Upgrading to PAN-OS 10.2.18-h6

Hi , Observed Behavior- Before upgrading to PAN-OS 10.2.18-h1, GlobalProtect SAML authentication using ID worked normally on all platforms.- After upgrading to PAN-OS 10.2.18-h6, only Android, iPhone, and iPad are affected.- Initial SAML authentication fails only on mobile clients.- Windows clients continue to authenticate successfully using t...

connection failed unsupported URL.jpg
connection failed ERR_UNKNOWN_URL_SCHEME.jpg

Endpoint Traffic Policy Enforcement on Prisma Access

Hello, I am trying out the "Endpoint Traffic Policy Enforcement" feature on GP to enforce users who are actively trying to avoid connecting to VPN (even if this is set to connect automatically). I have set this setting to "All traffic" on a small test group and it was working great. However, one of the users tried to connect to a Windows 11 ...

GP logs

We are using Prisma access global protect services. with SAML authentication. we have around 2000 users . we are looking a solution if any users unable to connect the global protect gateway so we can to get the email alert. XYZ users are not able to connect global protect gateway ______ reason. can anyone help to get this solution.

New Internet connection - break up HA pair to provision?

We have a pair of PA440s as our main firewall, with a fairly complex but not totally weird configuration - all physical interfaces in use, some with sub-interfaces, NAT to some inbound servers, VPN, URL filtering, etc etc. We have a new Internet connection - same provider, but with upgraded service that precluded just turning up the speed. ...