Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24294 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

175 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

780 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

5728 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

646 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

550 Posts

Cloud Native Application Protection

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Cloud and Cloud Identity Engine discussions.

470 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

3952 Posts

Activity in Discussions

API for exceptions?

Hi,looking for API for adding exceptions, is it exists ?I'd like to add programmatically exceptions which are done by UI > Settings > Exception Configuration > Legacy Agent Exceptions > Add Rule

ITApps by L0 Member
  • 327 Views
  • 1 replies
  • 0 Likes

Question on PA-440 Failover

Question regarding PA-440 and failover. How can I setup a failover in a PA-440 between two physical ports on that PA-440 firewall. For example: If Eth1/7 was connected to a cradlepoint and port 8 was a ipsec tunnel. What is the proper way to config pa-440 to failover from cradlepoint to another interface going over ipsec tunnel? Can the fi...

SD-WAN with ION's running 6.5.1-b5 performance issues

I wanted to find out if anyone has had issues with running 6.5.1-b5 on their ION's (3000/3200/9000). We have been running this version since late October. We receive random reports of slow performance and we can't figure out where the issue lies. I'm not singling out the ION's or the software version because we have had these reports before we u...

Strange IP exiting our network and erasing its logs

Hi everyone! Good Afternoon, I'm from Brazil, and my organization have two appliances PA 3220 in HA. This morning we've noticed some suspicious traffic exiting our network with IPv6 ::b638:2a0a:ffff:0 (for example), there was more than one those IPv6. The payload was huge, something about 4.2GB. This can be an exfiltration data attack? Could ...

UNIRIO by L1 Bithead
  • 680 Views
  • 1 replies
  • 0 Likes

Cortex XDR | Azure AD Single Sign On Unauthorized. Unauthorized - 4010507

Hello all, I am trying to setup SSO on my XDR tenant but I am getting the following message when login inUnauthorized. Unauthorized - 4010507 In the console "Management Audit Logs" i see the below logs: Custom Idp Saml User Invalid Error | invalid user: email address missing or misconfigured, please verify SAML attributes mapping I followed th...

user-id - Firewall is not learning upn name format

Hi All, I hope you are doing well. I am testing a scenario in my lab. I have AD configured with user-id agent installed on that AD server. I am login into machine with upn name (ankur@ankur.local) but in firewall user-id logs I see ankur\ankur. I user-id agent logs, I see below logs:01/30/26 14:09:41:236[Debug 398]: UserIpMap: IP 192.168.220.62 ...

Network connection unreachable on MAC OS newer version 15.3.2 o higher

Hi All, PAN-OS version: 11.1.10-h1 GlobalProtect Agent version: 6.3.3-711 We experiencing on the all MAC OS with The connection cannot be established and the following error message is displayed:“The network connection is unreachable or the portal is unresponsive. Check the network connection and reconnect.” We able to resolve for the olde...

Regarding ADNSR Licensing and Region Support

Attention: Global TPM team, I have several questions about the Advanced DNS Security Resolver (ADNSR) licensing and region support. In the activation documentation, I noticed the instruction “Select a Region where you want to deploy your product.”Advanced DNS Security Resolver Activation However, I could not find any documentation descri...

User Removed From LDAP Authentication Group Still Able to Connect to VPN

Hello everyone, I have a user who I removed form all VPN LDAP authentication groups about a week ago and they are still able to connect to the VPN. I was thinking it may have to do with the cookie re-auth but we have it set to expire after 24 hours. I am at a loss as to why they are still able to connect. I was hoping someone has had a simila...

cmaciel by L0 Member
  • 1477 Views
  • 1 replies
  • 0 Likes

IPSEC VPN for the FW MGMT

Hi There,I would like to establish an IPSEC VPN connection between the Palo Alto firewalls and the Fortigate. This setup is necessary to allow remote access to the Palo Alto firewalls from the Citrix servers. This is for Management connectivity.The inquiry is, IPSEC VPNs are generally configured to facilitate the passage of data traffic1. I want...

About UIA SSL connection

Hello Team, I'm currently dealing with an issue where UIA is unable to validate certification. The certificate does not have a SAN setting. I plan to change the certificate to one that has both CN and SAN set, but have not been able to do so yet. The certificate validation has occurred since applying an OS patch, so I have asked the OS ven...

Error when calling “Get number of users at location(s)” API in Prisma SASE Aggregate Monitoring APIs

Attention: JAPAC TPM TeamHello Team, I am testing the Prisma SASE Aggregate Monitoring APIs(https://pan.dev/sase/api/mt-monitor/) and encountered an issue. When calling the “Get number of users at location(s)” endpoint:https://api.sase.paloaltonetworks.com/mt/monitor/v1/agg/locationsUsersusing the “User Count across Locations” operation, I co...

Push Cortex XDR datasets/logs to dedicated syslog server

Hi everyone,I’m looking for some guidance on whether it’s possible to forward Cortex datasets to a dedicated syslog server for long‑term retention. Has anyone successfully done this, or is there a recommended method?I’m also considering using Microsoft Sentinel as a destination, but I’m not sure if all Cortex datasets can be pushed there.Any ins...