Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24313 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

175 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

782 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5768 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

648 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

554 Posts

Cloud Native Application Protection

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Cloud and Cloud Identity Engine discussions.

470 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

3976 Posts

Activity in Discussions

Custom BIOC Rule won't apply to Prevention Profile

We are attempting to make a custom BIOC rule to prevent the use of certain softwares on our servers. Applying the BIOC to a prevention profile works, except for when we add any exceptions. Say we are attempting to block Google Chrome on servers, we add an exception for a prefix used for end user device names and the BIOC can no longer be applied...

PAN-OS HA UGRADE PATH

Hi All, Please I'm upgrading a palo alto firewall in HA mode remotely, I'm having some issues with remote access and for me not to loose access and be able to finish my upgrade is it ok to upgrade the Passive first before failing over to the passive and then upgrade the Active ?

Best practices for Palo Alto security policy when destination IP/FQDN is dynamic or unknown

Group Company A is implementing surveillance cameras and requires communication to send data from the cameras to an external cloud server. The cloud server (destination) cannot be restricted by IP address or FQDN (only ports can be restricted), so IP addresses and FQDNs must be opened with ANY. ※ Restricted ports are TCP 443 (HTTPS), UDP 123 (NT...

Tuning Panorama HA Timers to Stop False HA1 Alerts over MPLS

Hello Community, I’m looking for some advice on tweaking our Panorama HA timers. We are seeing "false" failover alerts and want to ensure our plan to fix them is balanced correctly. Setup:Two Panoramas in an Active/Passive HA pair located in different Data Centers.Communication is over a WAN MPLS link.These manage two sets of firewalls (one set ...

Prisma Access Explicit Proxy — Anti‑Spyware behavior when DNS bypasses Prisma (logging subtype + test methodology)

Attention: JAPAC TPM TeamHello Team, I have a question about the Anti-Spyware profile behavior in a Prisma Access (Explicit Proxy) environment. Scenario- Clients use Explicit Proxy to reach Prisma Access for web traffic.- DNS resolution does not traverse Prisma Access (it is resolved by a local resolver / another path).- An Anti-Spyware prof...

Migrate PA-3260 cluster to 3420 (managed by panorama both)

Hi, i have to do this migration. So my steps will be: 1) Install the same version 11.1.x as the old cluster. 2) install licenses 3) add new cluster tu panorama 3) add the device group old cluster to the new one. 5) clone template old cluster to the new one cluster and check the possible interfaces/clusterHA-ID changes to the new cluster. IS th...

BigPalo by L4 Transporter
  • 419 Views
  • 1 replies
  • 0 Likes

Cortex XDR 8.9 Non-Persistent Citrix Servers and Cache Write Issue

Hello everyone, We have encountered and issue where the target servers do not get content updates. The citrix Windows servers reboot nightly with the golden image configurations but do not receive the latest content updates. At the same time, around noon we have to reboot the target servers due to write cache filling up to 100%. Have you enco...

Palo Alto Webinars

Hi,I've attended two Palo Alto webinars:- PAN-OS 10.1 Expert-Led Webinar on the 10th of February- Live upgrade demo on the 18th of FebruaryI was told we would be given the video recordings and slides from these webinars, but I don't know where they are. The tutors were saying the recordings would be available on the Live community page, but I ca...

Windows Installer DB: Current agent installation is missing

I am currently experiencing an issue while attempting to upgrade agents in the Cortex XDR console. The upgrade process fails with the following error message: "Windows Installer DB: Current agent installation is missing." I attempted to clean the endpoint; however, the process was unsuccessful. I would like to ask if there is any alternative...

Create a IOC without incident

Good morning, Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: PDFEditor_*.exe, but I would also like to block the process without generating an incident. Is that ...

Unable to block download and upload for chatgpt and messengers

Hi Friends, Recently i am trying to acheive an requirement where i want to allow messenger and chatgpt in my network but files uploading and downloading should be blocked. I tried configuring decryption and flie blocking profiles along with two seperate policies blocking chatgpt-base and messenger-base applications. I am able to decrypt the...

Satyak by L3 Networker
  • 71 Views
  • 0 replies
  • 0 Likes

Cortex XDR Pro / Browser extensions

Has anyone ever configured their environment to detect on unauthorized or unsupported browser extensions? Or conduct a threat hunt based on known facts? We've seen some slip through the cracks and I know Cortex doesn't natively detect abused or malicious extensions. Any XQL ideas out there perhaps?

Service Health Probes

Hello, I'm trying to configure service health probes over standard VPN tunnels. I've configured a new probe and a new probe profile. added the new profile to the category circuit. I see it under monitoring but I get 100% packet loss. I don't see any flow for the endpoint ip address. is anyone using this feature ? Regards, Elad

Resolved! About PAN-183404

Attention: Global TPM team, Hi, I have a question about PAN-183404.// PAN-OS 11.1.10 Known Issueshttps://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-known-issues Q1)How often does this issue occur? Best regards,MasaW

MasaW by L2 Linker
  • 391 Views
  • 1 replies
  • 0 Likes

Resolved! About PAN-293673

Attention: Global TPM team, Hi, I have a question about PAN-293673.// PAN-OS 11.1.10 Known Issueshttps://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-known-issues Q1)How often does this issue occur? Best regards,MasaW

MasaW by L2 Linker
  • 116 Views
  • 1 replies
  • 0 Likes
Register or Sign-in
Top Liked Authors