Articles
Find LIVEcommunity articles and technical documentation about Palo Alto Networks products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Articles
Find LIVEcommunity articles and technical documentation about Palo Alto Networks products.

Browse the Community

General Articles

LIVEcommunity's General Articles area is home to how-to resources, technical documentation, and discussions with Accepted Solutions that turn into articles related to all Palo Alto Networks products.

156 Posts

Support FAQ

Support FAQ on LIVEcommunity is where customers can find answers to their most common queries, in collaboration with Palo Alto Networks Knowledge Base.

8 Posts

Activity in Articles

Policy-Based Forwarding Symmetric Return Overview

4 min read

This article was created by @aalex Enabling symmetric return ensures that return traffic is forwarded out through the same interface through which traffic ingresses. This feature is useful when the requirement is to access servers through two ISP connections (on different ingress interfaces) and the return traffic must be routed through the I...

kiwi_3-1686129028146.png
kiwi_4-1686129261081.png
kiwi by Community Team Member
  • 19841 Views
  • 2 replies
  • 1 Likes

Tips & Tricks: Palo Alto Global Counters for Layer 1 to Layer 4 issues troubleshooting like MTU and DOS

6 min read

Hello everyone, I wanted to share some knowledge I've gained about investigating common Layer 1 to Layer 4 issues, such as MTU mismatches and DoS attacks, using key Palo Alto Networks firewall features like Global Counters, Flow Debug, and packet captures. The first steps in troubleshooting these issues are always to check your routing, run ...

nikoolayy1_3-1751356122244.png
nikoolayy1_1-1751354923520.png
nikoolayy1_0-1751354721007.png
nikoolayy1_2-1751360016326.png

Support FAQ: Flood Attacks - Configuration & Troubleshooting Best Practices

13 min read

Written by Alex Laulhe. With special thanks to Anupam S. & Amogh G. for their contributions. This guide is designed to help firewall admins effectively understand flood attack prevention and troubleshoot flooding incidents detected by Palo Alto Networks firewalls. Whether the event is triggered by packet buffer protection (PBP), Zone Pro...

Title_Flood-Attacks_palo-alto-networks.jpg
Fig 1_Flood-Attacks_palo-alto-networks.jpg
Fig 2_Flood-Attacks_palo-alto-networks.jpg
Fig 3_Flood-Attacks_palo-alto-networks.jpg
emgarcia by Community Team Member
  • 6377 Views
  • 3 replies
  • 3 Likes

Tips & Tricks: App-ID Debugging

5 min read

This article is inspired from Tips & Tricks: Flow Basic Debugging written by @kiwi and I recommend reading that article first before reading this one. Palo Alto Networks NGFWs use App-ID to detect the exact application inside a traffic stream but sometimes traffic will be first classified for example as App-ID "SSL" and after the decrypti...

nikoolayy1_0-1750327626537.png
nikoolayy1_2-1750327766322.png
nikoolayy1_1-1750327679712.png
nikoolayy1_0-1750325909323.png

Support FAQ: Upgrading PAN-OS and Upgrade Paths

4 min read

Let’s discuss upgrading your PAN-OS. It might sound routine, but without proper planning, it can turn into a real nightmare. Consider this: Do you actually need to upgrade? On many occasions, I talked with customers that were upgrading just for the sake of upgrading. Think about these first: Do you absolutely need the new features from the l...

kiwi by Community Team Member
  • 24468 Views
  • 8 replies
  • 5 Likes

TPM lockout

2 min read

New Generation Firewalls are equipped with TPM chips to help secure the devices These systems are designed to "Lockout" after 32 abrupt power down events(Power Failure, Pulling power cord to turn the device down).For every ungraceful shutdown(Power Failure, Pulling power cord to turn the device down).the TPM counter is incremented by 1 , after 3...

agawade by L2 Linker
  • 7146 Views
  • 2 replies
  • 7 Likes

Prisma Access SASE Extra Security Tips and Features

10 min read

1. Allowing only on-prem outbound connections to the Prisma Access SASE cloud (VPN responder/passive mode) 2. Why there is no need for XFF(X-Forwarded-For HTTP) headers to be inserted 3. Prisma Access SASE DNS proxy and resolution 4. GlobalProtect Agent Explicit Proxy support 5. Prisma Access ADEM (Access Autonomous Digital Experience Managemen...

Title_Prisma-Access-SASE-tips_palo-alto-networks.jpg
Figure 1_Prisma-Access-SASE-tips_palo-alto-networks.png
Figure 2_Prisma-Access-SASE-tips_palo-alto-networks.png
Figure 3_Prisma-Access-SASE-tips_palo-alto-networks.png

Nominated Discussion: Configure Split Tunneling by Domain

1 min read

This Nominated Discussion Article is based on the post "Configure Split tunneling by domain" by @BigPalo and responded to by @Raido_Rattameister and @BPry Read on to see the discussion and solution! Hi, I just configured split tunneling by domain using this domain test: *.portal.microsoft.com (port 443) But i can not see this traffic going ...

kiwi by Community Team Member
  • 303 Views
  • 0 replies
  • 0 Likes

How to Write Palo Alto Networks Custom Vulnerability and Application Signatures with Examples

7 min read

How to Write Palo Alto Networks Custom Vulnerability and Application Signatures with Examples Palo Alto Networks NGFW and Prima Access have many predefined IPS vulnerability signatures but sometimes extra custom signatures are needed that are specific to the application being protected as this need internal domain knowledge. I'll provide e...

nikoolayy1_0-1746717480189.png
nikoolayy1_2-1746719732662.png
nikoolayy1_1-1746710994586.png
nikoolayy1_0-1746720073083.png

Demystifying Selective Push on Panorama

8 min read

What is Selective Push? Selective Push on Panorama lets you deploy specific configuration to your firewalls instead of pushing everything all at once. Terminology Push Scope: The final admin view of committed changes with an option to select the changes that will be pushed to the selected target firewalls. Config Audit Window: This window is ...

Screenshot 2025-06-09 at 9.03.11 PM.png
shv_5-1749483597680.png
shv_6-1749483707514.png
shv_7-1749483817471.png
shv by L3 Networker
  • 1816 Views
  • 0 replies
  • 0 Likes

Tips & Tricks: Flow Basic Debugging

14 min read

You can use debug filters to enable the Palo Alto Networks firewall to collect packet captures for troubleshooting purposes. However, there are situations where you may require a more in-depth understanding of the firewall's internal operations. Flow basic provides an extensive view into every stage of the firewall process, including packet ...

kiwi by Community Team Member
  • 53673 Views
  • 4 replies
  • 14 Likes

Nominated Discussion: Dual ISP Global Protect Redundancy

2 min read

This article is based on a discussion, Dual ISP Global Protect Redundancy, posted by @DonohoeRobert. Thank you for the insight! Hi Team, I hope ye all are well. We recently worked a case for a customer that had dual ISP configuration and wanted the Palo Alto Networks device to provide redundancy for the Global Protect Portal and Gateways i...

interfaces.PNG
loopback.PNG
natRules.PNG
VirtualRouters.PNG
JayGolf by Community Team Member
  • 7667 Views
  • 2 replies
  • 3 Likes

Palo Alto Networks 7-byte Custom Signature Minimum Removed in Newer Versions and Why it Matters!

1 min read

Palo Alto Networks 7-byte Custom Signature Minimum Removed in Newer Versions and Why it Matters! In the newer versions after 9.1, Palo Alto Networks now does not have 7-byte minimum length limit and is really useful, as an example, to make a signature that will block traffic to a web page if too many times the login parameter "user" is seen in...

nikoolayy1_0-1746792158016.png

Palo Alto Networks NAT Session Distribution as a Way to Implement Server Load Balancing

1 min read

Palo Alto Networks NAT Session Distribution as a Way to Implement Server Load Balancing The Palo Alto Network Destination NAT Session Distribution can be used to implement similar to Load Balancer functionality by using one of the "distribution" methods. You need to allow the traffic with a with a security policy rule from the correct sour...

nikoolayy1_2-1747492747777.png
nikoolayy1_1-1747492645684.png
nikoolayy1_0-1747493140861.png
nikoolayy1_0-1747492597436.png

Support FAQ: How to Troubleshoot BGP on Palo Alto Networks Firewalls

5 min read

Most days, BGP runs quietly in the background. BGP advertises routes that keep your WAN, VPN, cloud environments, and public services connected and reachable. Until it doesn’t. And when BGP breaks, it’s not just a routing issue, it’s unreachable services and frustrated users. This guide will help you troubleshoot BGP on Palo Alto Networks fire...

JayGolf by Community Team Member
  • 3538 Views
  • 0 replies
  • 3 Likes
Register or Sign-in
Top Contributors
Top Liked Authors