Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1625 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

529 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

88 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

15 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

114 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

727 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

1699 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

37 Posts

AI Runtime Discussions

Welcome to the AI Runtime Security discussion area! Here, you can engage in conversations about AI Runtime Security, explore new insights, and stay updated on ongoing discussions.

5 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

8 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

17 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

21 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

65 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

2 Posts

Cloud Identity Engine Discussions

Cloud Identity Engine is the industry's first cloud-native identity synchronization and authentication service providing a single, secure user identity across Palo Alto Network's on-prem and cloud product lines.

28 Posts

Activity in Network Security

How to Update Specific Versions of Content via the CLI

Hello Palo Alto Networks Support Team, I would like to ask about the current method for updating content via the CLI. Previously, we used the following command to install a specific content version: request content upgrade download <content version> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/cli-commands-for-upgra...

Managing GlobalProtect Through SOTI MobiControl - Android

We are trying to manage GlobalProtect through SOTI MobiControl by locking down the portal address. I have the Managed App Config enabled in MobiControl with the portal address defined which does lockdown the portal address field in the settings. The issue is when there is an error connecting to the portal address for whatever reason, GlobalProte...

ernestogutierrez_0-1787867782268.png

Guidance Required for VM-500 Redeployment in Azure Due to Root Partition Limitation

Hello All,We are running two VM-500 firewalls in Azure configured in an Active-Passive HA pair. Currently, we are encountering high root partition utilization on both firewalls.A TAC case was opened, and although some files were deleted to reduce disk usage, the root partition utilization remains high. Palo Alto TAC has informed us that to incre...

kganesh by L0 Member
  • 38 Views
  • 0 replies
  • 0 Likes

Firewall not connecting to Strata Logging Service

Hi everyone, I've started setting up the Strata logging service and I've added in the necessary app-ids. After adding the app-ids and with destination any, it started sending out the logs to Strata without any issues. We currently have an issue when we try to add in the FQDNs either as an address group or url category that the firewall just w...

RPerez481389_0-1787812617479.png

Global Protect 6.3.3 Issues

I am on Global Protect Version 6.3.3-1121. I can connect on my Windows Device just fine. On a Mac version 26.6.2 when i try to connect, the client says "you are redirected to an embedded browser to authenticate and connect". It just stays there and never connects

pschaeve by L0 Member
  • 123 Views
  • 2 replies
  • 1 Likes

Max limit for URL Categories in a single Security Policy Rule?

Hi everyone, I'm trying to find the exact maximum limit for how many URL Categories (predefined + custom) can be added as match conditions in a single Security Policy Rule (under the Service/URL Category tab). Checking the official capacity limits documentation (specifically for VM-500), I see limits for total custom URL categories (500 per VSYS...

Gateway certificate issue on Android Globalprotect

I've currently got a support case open for this, but I'm trying to see if other users are having the same issue. From what I've seen: 6.1.11 - No issue 6.1.12 - No issue 6.1.13 - Issue Occurs 6.1.14 - Issue Occurs (current version on Play Store) The issue seems to be that the client doesn't trust the certificate for the gateway. I'm not s...

jsalmans by L4 Transporter
  • 65 Views
  • 0 replies
  • 0 Likes

PAN-294687 - HIP Report synchronization and GlobalProtect Gateway behavior in NGFW Clusters

Hi Team, We are investigating PAN-294687 and would like clarification on the following points. 1. In an NGFW Cluster, how are HIP Reports shared between Panorama, the Leader Node, and Non-Leader Nodes? Specifically, is HIP Report synchronization between the Leader Node and Non-Leader Nodes performed directly, or through Panorama? 2. Publi...

f.yanai by L0 Member
  • 89 Views
  • 0 replies
  • 0 Likes

Resolved! Version update for quantum computing

Good day, I had a quick question, from my understanding to protect ourselves from quantum computing, our firewalls need to be at least version 12. I am currently at 11.1.13-h5 for the firewalls and 11.2.4-h17 for panorama. This is actually a two part question now that I think of it, I can upgraded directly from version 11 to 12 correct? Also t...

My Panorama account is locked. Is there any way to fix this?

Hello Team, There are two saved configurations: one before the password expired and one after. The Panorama is currently factory reset, and the session disconnected immediately after inserting the pre-expiration configuration. No commit was performed at that time. Is there another way to handle this? Thank you, Best Regards.

Looking for a genuine factory-default PA-Series running-config.xml for audit-tool development

Hi everyone,I'm developing a firewall configuration-audit/parser tool and I'm looking for a genuine factory-default Palo Alto Networks firewall configuration for testing.I'm interested in any PA-Series firewall. A PA-5220 would be preferred, but configurations from other PA-Series models are also useful.PAN-OS 11.x would be preferred, but config...

Copilot said: Migrating a configuration from a FortiGate firewall to a Palo Alto Networks

Copilot said: Migrating a configuration from a FortiGate firewall to a Palo Alto Networks (PAN-OS) firewall is not a direct import/export process because the two vendors use different configuration architectures. The migration typically involves exporting the FortiGate configuration, converting it, validating the objects and polici...

fadhili by L0 Member
  • 87 Views
  • 1 replies
  • 0 Likes

Error: Domain's DNS name is missing in Active Directory Authentication

Hi guys, while working on setting up user-id, I got this 'Error: Domain's DNS name is missing in Active Directory Authentication' while trying to commit. I found this instruction: Using the Web GUI:1. Navigate to Device ➔ User Identification ➔ User Mapping.2. Click the Gear Icon next to Palo Alto Networks User-ID Agent Setup.3. Click on the Ser...

tinhnho by L3 Networker
  • 76 Views
  • 1 replies
  • 0 Likes