Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Network Security
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

Browse the Community

Next-Generation Firewall Discussions

Palo Alto Networks Next-Generation Firewalls provide true, complete visibility everywhere, along with precise policy control. Ask your questions or provide insightful answers in the discussion forum specific to NGFW.

1693 Posts

VM-Series in the Public Cloud

The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.

699 Posts

VM-Series in the Private Cloud

Use the VM-Series form factor to safeguard Private Cloud deployments. Use this forum to discuss deployments from VMware ESXi, VMware NSX-V, VMware NSX-T, KVM, Nutanix, Hyper-V, Openstack, and Cisco ACI.

108 Posts

CN-Series Discussions

CN-Series is the Palo Alto Networks' container native version of the ML-powered Next-Generation Firewall designed specifically for Kubernetes environments.

16 Posts

AIOps for NGFW Discussions

This forum is to ask questions, provide answers, and troubleshoot queries related to Palo Alto Networks’ AIOps for NGFW, the industry’s first AIOps solution for Next-Generation Firewalls.

154 Posts

Panorama Discussions

Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

821 Posts

GlobalProtect Discussions

GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.

2020 Posts

Strata Logging Service Discussions

Strata Logging Service (formerly known as Cortex Data Lake) enables AI-based innovations for cybersecurity with the industry’s only approach to normalizing and stitching together your enterprise’s data. Join the discussion now.

32 Posts

AI Runtime Discussions

Welcome to the AI Runtime Security discussion area! Here, you can engage in conversations about AI Runtime Security, explore new insights, and stay updated on ongoing discussions.

2 Posts

Strata Copilot Discussions

Welcome to the Strata Copilot discussion area! Here, you can engage in conversations about Strata Copilot, explore new insights, and stay updated on ongoing discussions.

6 Posts

Web Proxy Discussions

Welcome to the Web Proxy discussion area! Here, you can engage in conversations about Web Proxy, explore new insights, and stay updated on ongoing discussions.

15 Posts

Advanced SD-WAN for NGFW Discussions

Welcome to the Advanced SD-WAN for NGFW discussion area! Join us to discuss field topics, address customer and field concerns, share suggestions, community recommendations, new feature requests, or exchange best practices and design ideas.

13 Posts

Strata Cloud Manager

Strata Cloud Manager is our AI-powered solution that enhances network security management, prevents disruptions, and simplifies operations across SASE and NGFW platforms. The names for AIOps, NGFW, Prisma Access, and SD-WAN have been updated to Strata Cloud Manager in the product UI.

39 Posts

Quantum Security Discussions

Palo Alto Networks customers can now start to protect their encryption from the threat of Quantum computers, by migrating to Post Quantum Cryptography (PQCs). Ask your questions or provide insightful answers in the forum specific to Post Quantum Cryptography.

1 Posts

Cloud Identity Engine Discussions

Cloud Identity Engine is the industry's first cloud-native identity synchronization and authentication service providing a single, secure user identity across Palo Alto Network's on-prem and cloud product lines.

38 Posts

Activity in Network Security

Chatgpt enteprise login only

How are people policing logins to Chatgpt for enterprise only logins?https://help.zscaler.com/zia/adding-tenant-profilesZscaler does it. Palo does it for microsoft.....How are people doing this with decryption and Palos native app id, NOT the ACE subscription?Is this possible?

Sec101 by L4 Transporter
  • 135 Views
  • 0 replies
  • 0 Likes

Security Policy with Destination Criteria

We have created Security Policy with following criteria Source: User Destination Address : Any, URL Category: Worldwide URL, Tenant Restriction: Dropbox, Application: Any, Service: Application Default, and Action: Allow In This Scenario Any Traffic, Worldwide URL and Dropbox will be allowed or how it is?

Resolved! Which AWS Instance Type Meets VM-300 Requirements? Documentation Seems Inconsistent

I’m confused because there seems to be a contradiction in the documentation regarding the choice of AWS instance type for deploying a VM-300 using NGFW Software Credits.Could you clarify which AWS instance type meets the requirements for running VM-300? ■VM-Series Performance & Capacity on Public Clouds – VM-Series on Amazon Web Services Per...

How does the Azure Virtual Network discovers that there is Palo Alto Gateway Interface

Hello, I am trying to wrap my head around the PA deployment in azure using PA Series. I am basically following this video on setting up 2 zones, 2 Virtual routers, and route rules.In my setup the two spoke vnets have UDR with 0.0.0.0/0 route to the trust interface of the PANFW. I created two VRs and associated with the Interfaces. I have also a...

rswarnkar_0-1766036895351.jpeg

PA Global Protect

I have 4 portals and 4 gateways (4 different PA fw/vm ) of a GlobalProtect. PA is integrated with azure (an azure app per each gateway).I added one more new portal and one more new subnet to the one of the existing gateways, a new dns a-record and a new azure app. ISSUE: Clients can't connect to this portal, it's getting stuck after connection a...

Tunnel Monitoring

Hello Team, I have two ISP for site A and site B. we have configured tunnel.1,2,3,4. for all the tunnels i configured tunnel monitoring for failover. My primary tunnel is up and working fine. However, all the backup tunnels are down the tunnel status are showing red. anyone tell me is this expected?

jhussain1_0-1765985998674.png
jhussain1_1-1765991082868.png

Resolved! linux /etc/iproute2/rt_tables filled with 231 pangp.include and 232 pangp.exclude

system:* fedora 43 x86-64 fully patched* GP client 6.3.3the linux file for giving routing tables a name is getting stuffed with the same things over and over. there were over 2100 duplicate entries!!# head /etc/iproute2/rt_tables 231 pangp.include 232 pangp.exclude 231 pangp.include 232 pangp.exclude 231 pangp.include 232 pangp.exclude 231 pangp...

Detect RC4 traffic

How do we detect RC4 traffic without decrypting using the Palo Alto toolset (NGFW, SCM, SLS, IoT, etc.)? In SLS, I can currently filter down to: Application Subcategory = 'auth-service' AND Application = 'active-directory-base' However, there is no option to identify the use of weak ciphers (e.g., RC4).

How to Patch Vulnerability - Plugin 43160 (CGI Generic SQL Injection) on GlobalProtect

Body: We have detected a blind SQL injection vulnerability (Plugin ID: 43160) on GlobalProtect login CGI (/global-protect/login.esp) using Nessus. Details: - CVSS Score: 7.5 (High) - Affected Parameter: 'action' - Example: /global-protect/login.esp?action=';WAITFOR DELAY '00:00:3';-- Environment: PAN-OS version: [Your Version] GlobalProtect ...

NGFW admin account is locked. What should I do?

Hello all, I received a report that I couldn't log in to my GP account. Upon checking my firewall, I discovered that the admin account was also locked, blocking GUI/CLI access. Q1. Is there a connection between the GP account and the admin account being locked? Q2. I reverted to the previous settings, but the issue persisted. Is a factory re...

Global Protect - Connection Issue

I tried to connect the GlobalProtect with my syngenta mail and it stops after a while connecting to it. showing that the 'The network connection is unreachable or portal is unresponsive.Check the network connection and reconnect"But my colleagues are able to connect the Globalprotect with my syngenta mail-id.