Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1584 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

705 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

109 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

16 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

155 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

847 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

2067 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

33 Posts

AI Runtime Discussions

Welcome to the AI Runtime Security discussion area! Here, you can engage in conversations about AI Runtime Security, explore new insights, and stay updated on ongoing discussions.

3 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

6 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

17 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

19 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

60 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

1 Posts

Cloud Identity Engine Discussions

Cloud Identity Engine is the industry's first cloud-native identity synchronization and authentication service providing a single, secure user identity across Palo Alto Network's on-prem and cloud product lines.

39 Posts

Activity in Network Security

SCM Sub-interface Configuration

Attention: Global TPM team, We have noticed that the sub-interface option is grayed out in Strata Cloud Manager. Could you confirm whether it is expected behavior that sub-interfaces cannot be configured from SCM? Regards,

Multi-VSYS 11.2.8 - How to assign a dedicated Forward Trust Certificate per VSYS for SSL Decryption

Hi everyone,I’m running PAN-OS 11.2.8 with Multi-VSYS enabled (3 VSYS). I need a different Forward Trust Certificate per VSYS for SSL decryption, but since my certificates are imported in the Shared store, I can only select one Forward Trust Certificate globally.Should I import the certificates directly at the VSYS level instead of Shared to fix...

Need a similar setting of Global Protect in Prisma Access Agent

In Global Protect, there is an option called Disable Duration time, which is the time that automatically connects when the time reaches. For example, if the disable duration for 30 minutes, when the user disconnects the Global Protect, after 30 minutes, it gets automatically connected. Is there any similar setting like this in the Prisma Access ...

False positive High-Risk classification for legitimate healthcare SaaS (gmedic.co)

Hello, https://gmedic.co is a legitimate healthcare SaaS platform used by healthcare professionals in Colombia. The domain is correctly categorized as Health-and-Medicine, however it is currently flagged as High-Risk. We already verified:- no malicious content- no phishing- no malware- clean reverse IP- dedicated legitimate hosting The issue see...

Resolved! resolve hostname in logs now working in panorama

The "Resolve Hostname" feature can resolve the ip address in a log entry to the corresponding hostname using the address objects configured on the firewall or by doing a DNS lookup. When this box is checked, the firewall tries to resolve the ip addresses in the logs to the corresponding hostnames. When the checkbox is selected, the device will f...

ET by L3 Networker
  • 224 Views
  • 1 replies
  • 0 Likes

GlobalProtect 6.3.3 + Duo SAML MFA loop after normal Windows login (works only via GP Credential Provider at Windows logon)

Hi everyone, we are currently facing a strange issue with GlobalProtect + Duo MFA and have been able to narrow it down quite a bit. I wanted to check if anyone has already seen this behavior. Environment GlobalProtect Client: 6.3.3-c876 Prisma Access Mobile Users Dataplane Version: 10.2.4 Authentication: SAML via Cisco Duo Cisco Duo federated t...

Palo Alto Site to Site VPN ipsec tunnel up but unable to ping Source to destination

Dear Team, When I am doing implement Site to Site VPN ipsec tunnel then tunnel status is down & Ike gateways is down after test commands manually trigger negotiation, then all up. But still source to destination unable to ping. Already on virtual router point to tunnel interface for all traffic on both firewall. On security policies allow ...

Regarding the migration from HDD to SSD for PA-VM running in the Azure environment

Hello everyone,We are deploying and building a PA VM on Azure.During deployment, there was no option to select between HDD and SSD, so we built it on an HDD.Therefore, as a test, we stopped the virtual machine (Palo Alto) and migrated it from HDD to SSD in Azure.Afterward, we started Palo Alto and performed a differential check, and there were n...

Otsuka by L1 Bithead
  • 177 Views
  • 2 replies
  • 0 Likes

[SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT

Hello LiveCommunity Team! I created this post to share my experience regarding an issue involving GlobalProtect users from Prisma Access who attempt to run gpupdate /force to update GPO policies from the DC server, and who encounter the following error:CMD ERROR GPUPDATE /FORCEC:\WINDOWS\system32>gpupdate /force Updating policy...User polic...

DanielSRomero_1-1778369596055.png
DanielSRomero_2-1778369715172.png
DanielSRomero_4-1778370034165.png

Globalprotect Client 6.2.7 disconnects multiple times

We are encountering several users, where Globalprotect disconnects the GP-tunnel on Windows 11. In PanGPS.log I found the messages: CheckPanGpAgentThread: PanGPA process #### exits, ret is 00000057. and GlobalProtect agent terminates unexpectedly. Skip StopThreads(). Has anybody a suggestion, how to get rid of this failure?

halladm by L0 Member
  • 219 Views
  • 2 replies
  • 0 Likes

Global Protect count current users not match statistics

Hey thereThe counts are not matching between: >show global-protect-gateway summary detail GlobalProtect Gateway: connect-gtw:Current Users: 675Previous Users: 4520current-user : 675 Also with MIB OID .1.3.6.1.4.1.25461.2.1.2.5.1.3.0 panGPGWUtilizationActive Tunnels shows 675 But >show user ip-user-mapping all type GPTotal: 225 usersi...

kuschg by L0 Member
  • 133 Views
  • 0 replies
  • 0 Likes