General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols

Hi Team I got a question : During a previous session with end user, it was determined that, following the migration from PEAP to TEAP on the metropolitan area’s wireless network, 802.1X authentications fail to complete correctly when traversing the site-to-site VPN between a branch and the corporate headquarters.From a technical standpoint, t...

F.Pinar by L3 Networker
  • 377 Views
  • 2 replies
  • 0 Likes

Avoid reauth in Captive portal

Hi, I have captive portal for auth users with SAML. Users are being prompted to reauthenticate after 20 minutes more or less. Where can the timeout be increased, or how can the requirement to reauthenticate every X amount of time be removed?

BigPalo by L4 Transporter
  • 434 Views
  • 2 replies
  • 0 Likes

Is PAN-OS 11.1.4-h33 vulnerable?

Dear Community Members, I want to ask couple of things: Is the PAN OS 11.1.4-h33 vulnerable based on CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI and should be upgraded to PAN OS version 11.1.4-h34 and above? For PA-14020 it came with a base of 11.1.0, can this support to move to other based P...

EDL MS Intune All URL misses an entry

Dear all We got a question assigned about the PaloAlto EDL for MS Intune, the EDL "MSIntune All URL" (accessible via https://saasedl.paloaltonetworks.com/feeds/msintune/all/url). By 30th of April 2026, Microsoft added the URL "lgmsapeswiss.blob.core.windows.net" to her list, which can be reviewed here: Network endpoints for Microsoft Intune - ...

What is the Best Practice to block iCloud relay?

What is the best practice method to block iCloud relay without impacting iOS users too much? Apple says to NXDOMAIN the following below. mask.icloud.com mask-h2.icloud.com Prepare your network or web server for iCloud Private Relay - iCloud - Apple Developer For the PA though,... should we... create a policy to block, deny or use a URL custom b...

phampx by L0 Member
  • 8415 Views
  • 4 replies
  • 0 Likes

Resolved! Global Protect with multiple portals and gateways.

I have a working portal and gateway on PA3020 running 8.0.12.I want to setup another portal and geteway and repliciate all the settings.Second GP will be used for testing purposes.Only changes would be to use another public ip ,create another tunnel and loopback interface and ip pool.Just want to make sure I dont break prod global protect while ...

Authentication Failure at Home Network

My Authentication does work correctly on Office Network, But It does not work on my Home Network. Lan Cable, Wifi and Mobile Hotspot does not work at all. I did drop a mail from my official email id, somebody please help.

Globalprotect Connection two Browser Tabs

Hi There, we are using 10.1.5-h2 and Globalprotect 6.0.1 VPN. Our Users logging in via SAML and it works very good. The only thing which is annoying is that during the connection two similar Browser Tabs are Opening. After that, the Connection is established. Is there a way to reduce the tabs to one? We are using a Active Directory local Group a...

Resolved! Can 'admin' account be deleted?

1) We have several PA-3020's running 6.0.1 in our organization with only a few admin user accounts which integrated with AD, so audit wants to know if we can delete the generic accounts like "admin" or "panorama"? Any negative implications to doing so?2) We get a different list of users acccounts depending upon whether we use WebUI or CLI. T...

Resolved! NGFW with two different Support Structure in one CSP

Hi Folks, Does anyone know if I can register two NGFWs with different support structures (one has Premium Support and the other one has Partner-Enabled Premium Support) in one CSP account? If it is allowed, any consideration on how to manage the support cases for these firewalls? Thank you in advance for your insights.

security policies

hello , i need to extract security policies from palo alto appliance Model (PA-460) is there a way to schedule the report or grant read only access to audit function ?

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels