Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1619 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

526 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

88 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

15 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

113 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

726 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

1690 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

35 Posts

AI Runtime Discussions

Welcome to the AI Runtime Security discussion area! Here, you can engage in conversations about AI Runtime Security, explore new insights, and stay updated on ongoing discussions.

5 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

8 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

17 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

20 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

65 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

1 Posts

Cloud Identity Engine Discussions

Cloud Identity Engine is the industry's first cloud-native identity synchronization and authentication service providing a single, secure user identity across Palo Alto Network's on-prem and cloud product lines.

28 Posts

Activity in Network Security

GP logs

We are using Prisma access global protect services. with SAML authentication. we have around 2000 users . we are looking a solution if any users unable to connect the global protect gateway so we can to get the email alert. XYZ users are not able to connect global protect gateway ______ reason. can anyone help to get this solution.

Software NGFW Credit Pool Activation Lag (Ramp Status Showing INACTIVE)

Hello Community, I am looking for some clarification regarding the renewal and activation timeline of our Software NGFW Credits. Our renewal order for 350 credits has been successfully deposited into our Customer Support Portal under Ramp 2. However, looking at our portal dashboard, the status for Ramp 2 (Start Date: 08/07/2026, End Date: 08/0...

スクリーンショット 2026-08-07 095552.png

Time-Based Access Restriction and Password Expiration for Local Users

Hello Palo Alto Community Team, I need your assistance with configuring local user accounts on a Palo Alto Networks firewall. My requirements are: Configure time-based access restrictions for specific local users. For example, allow a user to log in only during a specified time period (such as Monday–Friday, 8:00 AM to 5:00 PM). Configure passw...

Resolved! Intermittent IPsec connection

We recently setup IPsec tunnel between PA-1410 and 3rd party device. We can see the tunnel is up, but when testing ping between endpoint on our side to endpoint on the peer's side there are frequents request timed out.Our configuration for IKE crypto using sha256, aes-256-cbc, DH group 19, lifetime 24 hours. For IPsec crypto we use sha256, aes-2...

i.rifai by L1 Bithead
  • 164 Views
  • 4 replies
  • 0 Likes

The XFF IP is the same, but the country of origin appears differently; please let me know why.

Hello everyone, As shown in the screenshot, you can see that the traffic has the same X-Forwarded-For (XFF) value, but one session is allowed while the other is denied. The allowed session matched our custom application policy. The denied session matched the any deny policy. Based on what I am seeing, it appears that when the session is al...

JiHwanHam_0-1785823048716.png

LACP Port Channel Link Flap between Cisco PA-445 and IR9320

Hello,We have a Palo Alto PA-445 firewall connected to a pair of Cisco IE9320 core switches configured as a stack, with one link connected to each switch. The links are configured in a Port-Channel on the Cisco side and as an AE (Aggregate Ethernet) interface on the Palo Alto firewall. Additionally, the MAC persistency timer is configured to 0 o...

Him143u by L0 Member
  • 91 Views
  • 1 replies
  • 0 Likes

CIE sync Entra Group to all DC NGFW

Hi All, Current I had 2 pair firewall sit at different location and integrated with CIE. GP always on to DC-1 without any issue by using Entra ID grouping , since authenticated at DC-1 so DC-2 doesnt contain any user ip mapping information, so the security policies with groupping don work. What I tried 1. Data redistribution - It work with ...

VLim by L2 Linker
  • 79 Views
  • 1 replies
  • 0 Likes

Globalprotect for android ver 6.1.14 issue

Hello Team, I am recently having problem with GlobalProtect agent for Android phones. previously everything was fine and no problems until version 6.1.11.x. now upgraded to Globalprotect for android version 6.1.14.x. since this version was installed o the mobiles, we are having problems connecting to the portal. as soon as yo...

IP Validation for GlobalProtect Public IP

Hi All, We are currently attempting to complete GlobalSign IP address validation for our GlobalProtect public IP address.GlobalSign's validation process requires access to a challenge file under:/.well-known/pki-validation/However, our understanding is that Palo Alto does not normally host files under this path.In addition, HTTP validation via p...

Prisma Access Agent "Cannot reach server" Error

Hi All, I recently ran into this problem and resolved it so thought I would share it here. I am currently running a POC for PAA and had installed it with no issues on a MAC, when I can to install on Windows11 I got the above error, after digging into the CLI with epm status command the issue seemed to be an SSL handshake error caused, it seems...

Panorama Commit Best Practices for Large Environments

Hi everyone, I'm looking for some guidance on Panorama commit workflows in larger environments. For those managing multiple device groups and templates, what has worked best for reducing commit times and avoiding unnecessary changes? Do you typically use selective commits whenever possible, or do you have another workflow that has proven reliabl...

kosarbnu by L1 Bithead
  • 56 Views
  • 1 replies
  • 0 Likes

Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

I’ve got an iPad that has the GlobalProtect client installed. I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert). I get this error “A valid client certificate is required for authentication. If the issue persists, contact your system administrator”. I’ve been troubleshooting ...

IMG_0623.jpeg
IMG_0620.png
IMG_0619.jpeg
IMG_0617.png