General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Best Practice Configuration for SD-WAN Policy

Hi Everyone, I'm currently designing SD-WAN policies for our Palo Alto environment and would appreciate hearing about real-world best practices and deployment experience. I'm trying to determine which applications and traffic types should be assigned to Best Available Path versus Weighted Session Distribution. My current thinking is: Best Avail...

GlobalProtect Release for Ubuntu 26.04 LTS ?

Hello together.recently was the new Ubuntu 26.04 LTS release, until now the provided GlobalProtect client supports only Ubuntu 24.04:https://docs.paloaltonetworks.com/compatibility-matrix/reference/globalprotect/where-can-i-install-the-globalprotect-app?otp=linux#linux When can we expect the new GlobalProtect version for Ubuntu 26.04 ? Best re...

Github EDLs missing IPs?

Hi everyone, we've been using the Palo Alto managed GitHub EDL to allow access to GitHub and recently noticed some connections being blocked because the destination IPs aren't covered by the EDL. For example, we see successful connections to addresses like 140.82.121.x that are allowed from the EDL, but also connections to 20.250.119.67 and ...

Clarification on Strata Logging Service and eDLP Log Forwarding

Hi Team, We are an MSSP and have received a request to support eDLP. Since we do not have access to these devices/services in our environment, we primarily rely on the available documentation to understand and support them. I have a few questions regarding how Strata Logging Service (SLS) works. We currently support Prisma Access using SLS. Wh...

Does the firewall need to have Panorama IPs in its permitted IP list for MGMT interface?

Does the firewall need to have Panorama IPs in its permitted IP list for MGMT interface? I tested and it seems I only need Panorama to allow FW IP. But from the article below for MGMT interface profile it mentions adding Panorama IP is required. https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-m...

nahiar by • L1 Bithead
  • 175 Views
  • 4 replies
  • 0 Likes

Palo Alto 1420 - Invalid username or password.

Dear all, We have face an issue recently with our Palo Alto HA pair. When we try to login with our 3 different admin accounts using web gui, ssh, and even consoel. it shows the same Invalid username or password I am more than sure that we have not changed the password at all. The only recent change we have implemented was the CIS Device H...

How to block all AI-based applications

Hi Team, 1) We have a customer who wants to block all AI-based applications but the applications are not getting blocked.2) Initially, we created a application group policy in Security Policy and added all AI-based applications with action as deny. After commit the AI applications were getting blocked successfully. However, Claude AI was still a...

Issues with connectivity between HA PAs and Nexus Leaf Switches

I've inherited a setup which has PAs with two vsys each connecting:external switch/router > PA external vsys > A10 Load Balancers > PA internal vsys > Cisco Nexus Leaf switches We run a full mesh setup (1x interface from each side of the PA HA pair to each (upstream switch, external A10, internal A10) internal device, both primary an...

rmeskill by • L0 Member
  • 278 Views
  • 2 replies
  • 0 Likes

empty HIP after last Microsoft updates (09.2026)

Hi, Following the recent Microsoft updates KB5124008 and KB5126052, we have observed a significant issue with GlobalProtect’s operation, manifested by the transmission of empty or invalid HIPs. PANOS version 10.2.16-h6 (but also on 11.2.10-h13—I was in the middle of the update but rolled back to limit its impact). GP client version—primarily 6.3...

JacekL by • L2 Linker
  • 1088 Views
  • 6 replies
  • 0 Likes

the Maintenance support for Palo Alto Networks hardware components

In Japan, the maintenance support SKUs for the PAN-PWR-450W-AC (spare 450W power supply for PA-3400, PA-1400, ION 5200, and ION 9200) and the PAN-SFP-PLUS-SR (SFP+ form factor, SR 10Gb optical transceiver, 300m short reach, OM3 MMF, duplex LC, IEEE 802.3ae 10GBASE-SR compliant) are ZAPA-PWR-450W-AC-BS1 and ZAPA-SFP-P-SR-BS1, respectively.However...

Commit Failed

Hello , I am using a Palo Alto PA-5220 running software version 10.2.11-h12, and I am currently experiencing an issue with Commit Failed and Dynamic Updates. For the Antivirus/Threats dynamic updates, I have configured the schedule to Download, and the download completes successfully. However, the update is not being installed automatically. Cou...

Commit-Failed.png
Karaked by • L1 Bithead
  • 408 Views
  • 7 replies
  • 0 Likes

Failed Connection

Is anyone else seeing "Failed Connections" fire on iphlpsvc after [an agent/content update / IPv6 GPO change]? Did a specific content version introduce it? What's the recommended tuning approach here — an alert exclusion/exception scoped to iphlpsvc, or addressing the underlying network/IPv6 config so the failures stop?

How to build SCM Managed NGFW with no management internet access

I am trying to deploy a Palo Alto VM-Series firewall and manage it with Strata Cloud Manager (SCM). The challenge is that I only have a single internet-connected port available in my cloud environment, while the management interface has no internet access. Ideally, I would like to keep the management interface private so that I can manage the fi...

Globalprotect for Android failing to connect

We're having an issue with GP where all other clients (Windows, Linux, MacOS, iOS) are able to connect with the exception of android devices. Users authentication successfully, get the MFA prompt from DUO, and then get this error: The network connection is unavailable or the gateway is unresponsive. Check the network connection and reconnect. ...

  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels