Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1672 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

691 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

108 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

16 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

154 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

818 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

2005 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

30 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

6 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

15 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

11 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

37 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

1 Posts

Activity in Network Security

Issue with allowing AnyDesk on a no-internet policy

Hey, I have a need to block all internet traffic at a specific site. I have created specific policies to allow needed services, and at the bottom of the policy, I have added a drop all. I have created a URL category for *.net.anydesk.com and allowed the ports according to this URL https://support.anydesk.com/docs/firewall but traffic from client...

Performance impact of using higher DH group for site-to-site VPNs

“Clarification on the meaning and performance implications of ‘Integrated Crypto Assistant’ for PA-1420 IPSec VPNs” Hi all, I’m working with a PA-1420 appliance in a site-to-site VPN deployment and I’d like to better understand the hardware/crypto architecture. Specifically: The PA-1420 architecture diagram lists “Integrated Crypto Assistant...

Limit User-ID Agent queries to cerain Windows event-IDs

We have been using PA-User-ID Agent for years an it was working fine. The Agent is connecting to Domain-Controller Log and maps user-name and ip-address of successful logins for firewall-policy usage. Yesterday we changed GPOs on the Domain Controller to enable Kerberos-Ticket Logging and since then we received unwanted mappings: A user starting...

SBegass by L0 Member
  • 53 Views
  • 0 replies
  • 0 Likes

GlobalProtect VPN Client windows 11 crash

Hi, I am using GlobalProtect GlobalProtect App version 6.2.8-263. It is the latest version i could download from network. When i am using connectioni got bluescreen crash whch i can reasume to: Bugcheck code: 0x1E This is MODE_EXCEPTION_NOT_HANDLED, which means that a kernel-mode component threw an exception that was not handled. Excep...

PiotrH by L0 Member
  • 85 Views
  • 1 replies
  • 0 Likes

How to activate and associate firewall PA410 to the inventory of strata logging instance

yesterday I found that my PA410 has no logging service at management page for enable cloud logging.and CLI have no command to support PSK code to add firewall to inventory of strata logging instance.then copilot replied that it may need CSP provide OTP .but I do not know the command to enter OTP and do not know where to generate OTP , because PS...

can-not-activate-with-auth-code-in-hub-page-2.png
can-not-activate-with-auth-code-in-hub-page.png
click-activate-but-no-response.png
common-service-still-disabled.png

Request Advice – BGP Failover Route-Based IPsec VPN With WatchGuard (WG)

Hi Everyone, I’m looking for guidance on the best-practice way to set up redundant route-based VPN tunnels using BGP between a Palo Alto firewall (PA-VM) and a WatchGuard firewall. The goal is to implement primary/secondary failover with dynamic routing instead of static proxy-ID tunnels. Environment Palo Alto: PAN-OS 10.x VM-Series WatchGu...

Cannot Access Primary in HA Pair – Need Failover & Recovery Advice"

**Subject: Unable to Access Primary Firewall in HA Setup — Need Guidance on Failover and Recovery**Hello Palo Alto Community,We are currently facing an urgent issue with our Active/Passive Palo Alto firewall setup:Palo Alto Model:PA-3220VERSION:10.2.5UPTIME:765 DAYS- The primary firewall (IP .165) is active but we have lost admin login access du...

ChatGPT User-ID, AD and IP mapping issue

There is an issue with Palo Alto firewall which has to do with user IP mapping and AD. User is grated access via policy in the format source-user = corp\employee. After that's done, the user works fine today accessing ChatGPT but then the user is not able to use chatgpt the next day after working fine the day before. What is the problem? Any in...

Issue with IOS 26 and SMTP

Hi everyone, We are experiencing a persistent issue with SMTP sending from iOS devices (specifically 26.1) when SSL Forward Proxy / Decryption is enabled on the firewall(10.2.16-h4). Is there any bug or limitation published related to this? Thanks in advance!

Unable to connect VPN

Hi , I am using GP 6.2.8-183 and use radius server to get authentication. However, I signout from the GP and when i tried to connect VPN , it prompts invalid user name or password. It was working before i signedout from the existing VPN connection. Same was noticed a new user created last Friday. It there a way that that can be resolved?

Few Objects are missing on firewall while Migrate a Multi-vSYS enabled Firewall HA Pair to Panorama Management

Hi Palo Alto Team and Community, I am experiencing an issue while migrating a Multi-vSYS enabled Firewall HA pair to Panorama management. All objects appear correctly in Panorama; however, some objects are missing on the firewall after pushing the configuration. For example: Panorama shows: ~5000 objects Firewall shows: ~4500 objects I h...

Al-Amin by L2 Linker
  • 132 Views
  • 1 replies
  • 0 Likes

ChatGPT User-ID, AD and IP mapping issue

There is an issue with Palo Alto firewall which has to do with user IP mapping and AD. User is grated access via policy in the format source-user = corp\employee. After that's done, the user works fine today accessing ChatGPT but then the user is not able to use chatgpt the next day after working fine the day before. What is the problem? Any in...