General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4436 Views
  • 0 replies
  • 0 Likes

OID for check proxy

Hi teamWe need a check check for the Palo Alto Firewalls that alerts in case of not having synchronization with the Proxy. In case of not synchronization, alerts appear and can be viewed in: Monitor > System > '(subtype eq 'url-filtering') and !(severity eq 'informational')'. How we can obtain an OID to create a check in Centreon's monitor...

Alpalo by L4 Transporter
  • 892 Views
  • 2 replies
  • 0 Likes

Cortex XSIAM API to get available custom fields in incident

We have an api to update an incident, in it we can also set values for the custom fields we created in the UI.POST https://api-<fqdn>/public_api/v1/incidents/update_incidentBODY{"request_data": {"incident_id": "<incident_id>","update_data": {"field_1": " field_1_value","field_2": "field_2_value"}}}Is there an API to get a list of cus...

iawan by L1 Bithead
  • 1268 Views
  • 2 replies
  • 0 Likes

PA-200 upgrade steps

Hi All, New to PA firewalls and have an old EOL PA-200 running PanOS5.0.6 I would like to upgrade to 8.1.26 but every upgrade attempt fails from the GUI or CLI I downloaded PanOS 6.0.0 and 6.0.15 but it also fails requiring content version 401 or higher <-- no idea what that means What am I missing at this point? Is there a way to sim...

Resolved! Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication

Just wanted to share in case others run into this. My company has recently started to use Microsoft's SSPR process which is embedded into the Windows 10/11 OS. Specifics on how it works here: Self-service password reset for Windows devices - Microsoft Entra ID | Microsoft Learn This specific section is going to be an issue for GP VPN envir...

Resolved! HTTP-Proxy allow or deny app

Hi Everyone,I have a inbound rule in place fro my forward facing web-server and am tightning the policy down to only allow a few apps and a few default ports ssl and web-browsing When i was looking at what traffic was hitting the rule, Isaw the following applications SSL 443 = iexpectedweb-browsing (80) =expected however i am noticing http-proxy...

GlobalProtect prelogon and internal gateway detection

I've been doing mixes of internal and external gateways with customer forever (I usually forget that "always-on" must be enabled for internal gateway detection to even be allowed in the first place). I'm working on a pre-logon implementation that also would benefit from leveraging internal gateways/no-tunnel while inside the enterprise network...

Screenshot 2025-03-06 at 11.26.49 AM.png
Screenshot 2025-03-06 at 11.23.39 AM.png
Screenshot 2025-03-06 113028.png

Best method to permit SAML auth and Radius for Globalprotect at the same time?

Greetings all, I hope you can help me. I currently have Globalprotect set up on a single firewall - both portal and gateway. We're using Radius for authentication, it is working well. We want to transition to SAML. For testing purposes, we'd like to have SAML configured for a specific test user (or group), while leaving the current authentic...

mannix_0-1715099765068.png
mannix by L1 Bithead
  • 6190 Views
  • 7 replies
  • 0 Likes

REQUEST: Grace period for GlobalProtect patch checking

Problem: Because of occasional issues with vendor patches, like MS had early this year, (see URL below), very few companies release patches/updates to clients or servers on the day of release. They test the updates first, then release them days or even weeks later after testing has shown no major issues. GlobalProtect has no capability to delay ...

Resolved! Site flagged as GRAYWARE Please Help!!

Hi, a site I am working on with a client is being flagged as Grayware. This is a landing page for a digital agency product and shouldn't be flagged. Can this be reclassified? This is the domain: https://audiencexlerator.com/ Thanks in advance, Matt

PROTIP: Factory Reset from MacOX

tl;dr use the command "cu" instead of "screen". I have been trying to factory reset a PA-3200 for about 45 minutes. I am using a standard RJ-45 to DB9 serial cable with a USB serial adapter. Following the instructions I get to the step where I have to select the factory reset and it says "maintenance reason". Hitting "q" to go back a screen...

wstuart by L1 Bithead
  • 693 Views
  • 1 replies
  • 0 Likes

DNS sinkhole

Hello everybody, How many policy we need for block and review source of infected hosts? One or two? Internal dns is using but we can not see source of users.

valizada by L0 Member
  • 1043 Views
  • 3 replies
  • 0 Likes
  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels