Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24274 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

175 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

778 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5701 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

644 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

545 Posts

Cloud Native Application Protection

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Cloud and Cloud Identity Engine discussions.

470 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

3930 Posts

Activity in Discussions

False positive : HelpDesk Viewer

A false positive has been detected for HelpDeskViewer.exe. File Hash: <c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264> Link to Virustotal report for the file: <https://www.virustotal.com/gui/file/c08193adcefec15716fb0c76566e834677563636caf65151d7c9447392d28264/details> Current VirustTotal Verdict: <Generic.ml&...

PAN-OS 11.1.13 Predefined reports displaying IPv4 addresses in IPv6 format

We have been experiencing an intermittent problem with our nightly predefined reports displaying IPv4 addresses in IPv6 format.An IPv4 address like 192.168.1.1 is being displayed as an IPv6 address like ::0101:a8c0:ffff:0 We are currently running PAN-OS 11.1.13 but we have seen this same behavior under 11.1.12. Behavior like this apparently ha...

Why do the same Windows Server data collected using XDRC and WEC agents show different statuses in the following fields?

Why do the same Windows Server 2022 std (Traditional Chinese) data collected using XDRC and WEC agents show different statuses in the following fields? _Collector_type = `WEC` ,Event Log display is 【`English`】,Fields have 【Message】、【 _RAW_LOG】。 _Collector_type = `XDR Collector` ,Event Log display is 【`Traditional Chinese`】,Fields Only have 【Mes...

jchen644219_0-1768787166072.png
jchen644219_3-1768788509185.png
jchen644219_2-1768787586281.png

Multiple High/Critical Alert Detected via Port 18264 | Possible FP

Hi , i would like to seek clarification clarification regarding a threat detection observed on our Palo Alto firewall, which we believe may be a false positive. During our review of the threat log, we noticed that the detection from below source and destination via port 18264 references several filenames as win.ini, fake.cgi, note.txt, jhjr60x...

Multiple High/Critical Alert Detected via Port 18264 | Possible FP

I would like to seek a verification and clarification regarding a threat detection observed on our Palo Alto firewall, which we believe may be a false positive. During our review of the threat log, we noticed that the detection from below source and destination via port 18264 references several filenames as win.ini, fake.cgi, note.txt, jhjr60x8....

recv rst from server or recv from zero win from server

I'm using Global Protect to connect to the server. When I open YouTube to watch videos or run a speed test, I always receive an RST packet or a zero window message from the server. Then the client disconnects from the VPN. I want to know what's causing this? I will show the tcp dump in attach.

Juns_Net by L1 Bithead
  • 1718 Views
  • 4 replies
  • 0 Likes

Global Protect Connectivity Issue

I am deploying GlobalProtect and have configured the Gateway Agent Client Settings with the following Source User in the Config Selection Criteria: connect\vpnusers I am a member of this group. The group is retrieved from our internal LDAP server via User Identification → Group Mapping, with the following attributes configured: Primary Usernam...

H.Thiam by L1 Bithead
  • 1686 Views
  • 3 replies
  • 0 Likes

China mainland Mobile users questions

Hi expert, If we do not have Prisma Access China license, but still want to connect China mainland mobile users to closed MU-SPN overseas, say Japan pop. If this will be blocked by Greate FW, and if it is, if any workaround. Also, can connect to the overseas SC and then send traffic to Prisma Access Cloud ? If can do that, how to achieve it. ...

Strange Gateway change issue on network with Prisma Access GP Client

Having some strange behavior with GP client 6.3.3-711 that runs within the prisma access product. When user is on network, or in office, gp changes gateways at times and changes the timezone of the client computer. The client doesn't have issues off network like at coffee shop or home. Not sure what's going on. I am not using any internal host d...