Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24205 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

173 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

766 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5571 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

641 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

535 Posts

Cloud Native Application Protection

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Cloud and Cloud Identity Engine discussions.

507 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

3863 Posts

Activity in Discussions

Error opening support ticket

Hello, I’m trying to open a support ticket, but the system won’t allow me to create a new case. Whenever I attempt to submit a request, nothing happens and the ticket is not created. I keep getting the error: System has encountered an error. Failed to create the case. Is there any known issues?

High Data Plane Utilization During Business Hours

Hello, We are experiencing an issue that is becoming hard to isolate, our end users noticed network slowness about a few days ago. During Isolation and investigation it led us to our NGFW PA-3260's. This causing extremely High latency when reaching out from our Inside to Internet interfaces. Resource utilization (%) during last 24 h...

HungTrinh_0-1763749511805.png

Need better approach to solve wrong commits on Content Pack

Scenario: Two developer working on same playbook on Dev environment. For ex Playbook Name: XXX_playbook Developer A & Developer B working on XXX_playbook and both make changes independently. 'A' makes first commit on develop branch. Then, 'B' makes second commit. B assumes his changes are ready to be promoted to prod. But, 'A' not. Now, i...

Upgrade VM300-500 needs to readded in panorama?

I have a cluster in Panorama. We are going to upgrade these 2 machines from VM300 to VM500. So i understand the SN will change and we will need to readded in panorama? is that right? i understand that being a different model i wont user command "replace old SN new SN" in panorama to readded. Right?

BigPalo by L4 Transporter
  • 47 Views
  • 0 replies
  • 0 Likes

Trendmicro application identified as "ssl" despite of proper SNI, CN, SAN.

We have the Trend Micro agent installed on the endpoints, and it is running smoothly. However, the application is still being identified as "ssl", even though the packet captures show the correct SNI value in the Client Hello. In the Server Hello, both the SAN and CN fields contain multiple wildcard entries ending with *.trendmicro.com. The URL...

Issue with allowing AnyDesk on a no-internet policy

Hey, I have a need to block all internet traffic at a specific site. I have created specific policies to allow needed services, and at the bottom of the policy, I have added a drop all. I have created a URL category for *.net.anydesk.com and allowed the ports according to this URL https://support.anydesk.com/docs/firewall but traffic from client...

Firewall cortex and Windows 11

Hello, I have a question regarding the Cortex Firewall. Does the Cortex Firewall component take control of the Windows Firewall? In other words, if the Windows Firewall is active on an endpoint, will Windows Defender show that it's being managed by Cortex? Thanks.

Preventing Access to "Resolve & Create Exclusion " based on Role

Hello Livecomm, I have a trivial question. Does anyone know how to prevent users from a specific role to '"Resolve & Create Exclusion " when closing a case? I have reviewed the various options the role provides but there is no mention of this feature. We want to prevent low level analysts from using this feature. Many thanks, MSysec Cortex ...

Submit false positive

File Hash: bfe4a414d5adec12d0679f05711d2f1af07572c6d8f0b0d7fcd09110930ef03f Link to Virustotal report for the file: https://www.virustotal.com/gui/file/bfe4a414d5adec12d0679f05711d2f1af07572c6d8f0b0d7fcd09110930ef03f Current VirustTotal Detection: Generic.ml We are software development company, one of our .exe files has been detected as malwa...

VirusTotal False Positive (Generic.ml)

File Hash: 7c0feaf9231ced1629c167e08a9bc997f01452ceab72e38fb180c3fbfd9d3bd6 Link to VirusTotal report for the file:https://www.virustotal.com/gui/file/7c0feaf9231ced1629c167e08a9bc997f01452ceab72e38fb180c3fbfd9d3bd6 Current VirusTotal Verdict: Generic.ml (False Positive) Description:This file belongs to my macro automation software (“TGMacro”). ...

trksyln by L0 Member
  • 77 Views
  • 0 replies
  • 0 Likes

Performance impact of using higher DH group for site-to-site VPNs

“Clarification on the meaning and performance implications of ‘Integrated Crypto Assistant’ for PA-1420 IPSec VPNs” Hi all, I’m working with a PA-1420 appliance in a site-to-site VPN deployment and I’d like to better understand the hardware/crypto architecture. Specifically: The PA-1420 architecture diagram lists “Integrated Crypto Assistant...

We are experiencing a problem, data may not be up to date. Please try again in a few minutes.

Hello All, I've been seeing the following message on our Cortex XDR Dashboard for the past few days: "We are experiencing a problem, data may not be up to date. Please try again in a few minutes." There's also a link to Download support file included. Has anyone else encountered this issue or have any insights into what might be causing it? ...

Alarm contacts /Power supply PA-1420

Hey, I was wondering if the PA-1420 model had physical alarm contacts or done through ethernet. Also by looking at the front panel in the datasheet only, I see a USB-C? Can I surmise that this is where the power supply can connect to the firewall?

emilynicholson_0-1763575765298.png