Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1586 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

709 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

109 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

16 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

155 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

853 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

2077 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

33 Posts

AI Runtime Discussions

Welcome to the AI Runtime Security discussion area! Here, you can engage in conversations about AI Runtime Security, explore new insights, and stay updated on ongoing discussions.

5 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

8 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

17 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

19 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

63 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

1 Posts

Cloud Identity Engine Discussions

Cloud Identity Engine is the industry's first cloud-native identity synchronization and authentication service providing a single, secure user identity across Palo Alto Network's on-prem and cloud product lines.

40 Posts

Activity in Network Security

[SOLVED User-ID Domain Mismatch]: Resolving Domain's Conflicts Between Prisma Access GlobalProtect (CIE) and On-Premises Server Monitoring

Hello LiveCommunity Team! I created this post to share my experience regarding an issue involving the User-ID domain mapping issue between the Prisma Access Mobile Users GlobalProtect conflict with the NGFW On-Premises. The conflict arises when an On-Premises NGFW and Prisma Access GlobalProtect use a different user identity sources and domain N...

DanielSRomero_0-1781263908489.png

GlobalProtect Logs Showing Only a Few Days of Retention on Panorama

Hello Community, We are experiencing an issue with GlobalProtect log retention on Panorama. Our Panorama manages 6 firewalls, and all firewalls are configured to forward logs to Panorama. However, on Panorama, the GlobalProtect logs for the managed firewalls are only retained for about 6 days. When we check the output of the command show sys...

Global Protect Android client failing with certificate error after upgrading PAN-OS

Dear all, I have a strange error after I upgraded my firewall to PAN-OS 11.1.15 to fix a GP vulnerability. (18990)06/04 17:44:57:208734 - PanKeyManager: Issuers: CN=ixxx, DC=ixxx, DC=local(18990)06/04 17:44:57:208841 - PanKeyManager: Use Cert: gp_user_new(18990)06/04 17:44:57:208883 - PanKeyManager: getPrivateKey for alias: gp_user_new(1899...

GlobalProtect VPN fails to launch on Linux [Solved]

As an Ubuntu desktop/laptop admin at my company, I've had my fair share of gripes with Globalprotect VPN for Linux. So I wanted to share my home-grown fixes for various issues I've encountered. Yesterday, I encountered another such issue which the developers have kindly created for me. The issue is that Linux users with a UID > 60000 cannot l...

jamesps by L1 Bithead
  • 92 Views
  • 1 replies
  • 0 Likes

Impossible to migrate an ae interface to a different speed in Panorama?

Quite new to Panorama, but have been working with Palo Alto standalone firewalls for a little while. Client has 2 Active Passive HA FW's in Panorama and an ae1 interface with 4x 1G interfaces as members. They want to switch this to 4x of the 10G interfaces during an outage window. Am I right that I should be able to just remove the 4x 1G membe...

Getting Started with the Strata Cloud Manager Terraform Provider

In this guide, we will walk through the end-to-end process of setting up and managing your infrastructure as code using the Strata Cloud Manager (SCM) Terraform Provider. We will begin with the prerequisites—creating a service account and securely configuring your provider block—before initializing your Terraform workspace. Once the foundation...

image23.png
image9.png
image8.png
Screenshot 2026-06-10 at 5.27.06 PM.png
ariqbal by L2 Linker
  • 92 Views
  • 0 replies
  • 0 Likes

NAT policy conversion

hello, im currenly converting the cisco asa's configuration to paloalto . so in cisco asa , the nat policy is configured as following : object network VMAnat (ADM,inside) static 10.15.65.3so if i get it right , this policy means that the traffic from the source VMA and source interface is ADM which is an object already created to destination an...

Can we create a custom log forwarding to syslog server for PAN OS greater then 11.0.0

In our Panorama syslog forwarding we can see logs are sent in the Default Format . We need to change it to a customized format . Default Format :<14>May 27 20:07:50 FW1 1,2026/05/27 20:07:49,016201049542,CONFIG,0,2562,2026/05/27 20:07:50,10.252.40.134,,set,ADMCREGT,Web,Succeeded, deviceconfig high-availability group,7618904982443524109,0x8...

ADEM Shows Gaps In Synthetics Trends

New to Prisma/ADEM and GlobalProtect in a SASE environment. I'm using ADEM/Activity Insights to troubleshoot a user experiencing Citrix Disconnects. We noticed high Memory Utilization (> 85%) and believe that is it. However, I'm perplexed- ADEM shows two ~ 5-minute gaps in Synthetic Performance Metrics graphs in the user's Experience graphs b...

Resolved! basic network, complex problem (please help)

Hello Everyone!i have encountered an issue with my network testing environment and would like to ask for your opinion.I wanted to test for connectivity in my environment so the only policy rule is a full any/any on any service with action allow, so it overshadows everything. my layout is such:eth1/4 192.168.1.1/24 eth1/14.1 192.168.20.1/24eth1/1...

PanGpHip in the official ARM64 build

Hi. I'm trying to install GP on Raspbery PI 4b (aarch64, debian trixie).Our admin downloaded PanGPLinux-6.3.3-c31.tgzInside there are: GlobalProtect_deb-6.3.3.1-638.debGlobalProtect_deb_aarch64-6.3.3.1-638.debGlobalProtect_deb_arm-6.3.3.1-638.debGlobalProtect_rpm-6.3.3.1-638.rpmGlobalProtect_rpm_aarch64-6.3.3.1-638.rpmGlobalProtect_rpm_arm-6.3.3...