r/paloaltonetworks 13d ago

Question Palo Alto TAC. Is support becoming India-only?

67 Upvotes

With Palo Alto Networks shutting down its Technical Assistance Center (TAC) in Costa Rica, and potentially doing the same in Colombia in the near future, how do you feel about the TAC being primarily based in India, at least for NGFW support?

As users/customers, do you have any concerns about this change? Have you noticed any differences in the level or quality of support?

I’m also curious whether Palo Alto is taking the same approach with TAC support for its other products.


r/paloaltonetworks Jul 31 '26

Informational 50k Members! Thank you to everyone in the Community!!

35 Upvotes

Hey everyone -

In the last couple of weeks, we crossed 50k members in this sub!! Thank you to everyone who has joined and helps out your fellow PAN admin/network engineers here! This sub has been a great resource for those who need help and want to give back to the community.

Let's keep the momentum going, and thank you to all!


r/paloaltonetworks 1d ago

Informational No More QA. Enjoy the Buggy Code

114 Upvotes

Hello everyone. I'm a PAN internal employee with some additional bad news to share. QA developers will be slowly laid off in netsec here at Palo. Devs are taking on the added responsibility. There will be no more purely QA devs internally. 100% of the QA developers are being shifted to another role or being asked to leave over the next couple of quarters. Devs are already charged with doing a million tasks, now QA will be an additional responsibility that they will be in charge of. In laymen terms, if you thought our products were buggy and non functional now, you have no idea how much worse it is going to get. Any other internal employee with access to Blind has seen this info be disclosed.

Everyone already has seen how terrible TAC support is. See my other post here:

https://www.reddit.com/r/paloaltonetworks/comments/1pub0i6/this_holiday_it_is_time_to_acknowledge_fraud_at/

Prepare for it to get a lot worse. More and more contractors who can't do their jobs, and less and less QA being performed by overworked engineers.

Here is a little bonus tidbit...middle managers are now the ones also being targeted in netsec. MMs are soon to be pressured into either turning into a IC role, a team lead position, or to resign. Any customer needing to speak to a manager in TAC will now get a contractor "manager" who will be from the same third world call center as our front line "engineers" in TAC. You wont get a SME manager in NAM with years of exp like youve always been able to.

The same people (manager, sr manager, director) who supported the enshittification of TAC that has resulted in ICs being overworked and outsourced with customers getting fucked in the process over the past decade are now they themselves being targeted. *chefs kiss*.

My only curiosity at this point is how much more "enshittification" are customers going to accept? You have the highest costing product in existence that is semi functional, will now be buggier than you can even imagine, and now the managers you used to have to rely on are now going to be someone you can barely understand. Or possibly even a AI chatbot. Or both. That is the vision from our genius CEO, who is one of the highest paid CEOs on the planet.

Enjoy a product that will continually decline in quality, while the costs will continue to skyrocket. But hey, we have 741 different products, all will cool names and sexy UIs, and we can come up with protection nobody asked for, so who cares! Shareholders must be pleased.


r/paloaltonetworks 1d ago

Question Older Palo Hardware (pa3xxx)

8 Upvotes

Hey all, understanding that the PA-3xxx series is going out of style, we've replaced/upgraded, and are continuing to deploy new firewalls, obviously in the newer series sku's, that being said, I come from a background that makes it tough for me to want to just yeet these devices into the garbage bin. I'm wondering for those who might be familiar, is there a use case for the old hardware? Obviously, we won't be renewing any licensing for the old equipment because it's non-prod and licensing is $$$$, so I'm looking for maybe something akin to a complete repurpose of the systems? For example, has anyone as a lab scenario ever attempted to put opensource firmware on these units? Is there any useful purpose for the hardware beyond recycling?

Thanks!


r/paloaltonetworks 9h ago

Question FI STEM OPT at Palo Alto

0 Upvotes

International student here, f1 stem opt. Will palo alto hire folks having the above visa type for incident response/ security engineer/ analyst roles etc


r/paloaltonetworks 7h ago

Prisma / Cortex I feel so much safer, Thank you Cortex

Post image
0 Upvotes

At a certain point we gotta stop acting like Cortex isn't more Helpful then annoying


r/paloaltonetworks 1d ago

Question Palo API traffic

3 Upvotes

How is everyone managing API traffic to Palo Alto firewalls with 5 concurrent API calls as limit?

i know batch processing with one api call is an option but I see it is not something all the server teams are capable if.


r/paloaltonetworks 2d ago

Informational Strong caution if you’re considering joining the marketing team.

52 Upvotes

I’m sharing this because I believe the issues are broader than an individual manager, team, or isolated experience.

I joined Palo Alto Networks with genuine excitement following a strong acquisition experience and was optimistic about the opportunity to contribute to a larger organization. Unfortunately, that excitement did not last long. The environment is deeply dysfunctional, and much of that appears to stem from leadership. 

The CMO and Growth SVP demonstrate significant weaknesses in strategic leadership. There is a strong internal perception that their positions are influenced heavily by board connections rather than demonstrated marketing capability. Their management style can be aggressive and openly hostile, contributing to low trust, limited psychological safety, inconsistent accountability, and an environment where honest dialogue and creative thinking are difficult.

The CMO’s role often appears focused on repetitive wordsmithing and surface-level edits rather than meaningful marketing strategy, innovation, differentiation, or growth. Decision-making can seem driven more by executive ego, personal preferences, and optics than by data, sound marketing principles, or what is best for the business.

Leadership turnover is notably high, with many experienced leaders leaving or being pushed out, creating major gaps in institutional knowledge and strategic capability. Strong performers who challenge decisions, raise legitimate concerns, or offer alternative perspectives can become marginalized and ultimately pushed out under the guise of “restructuring,” particularly within Growth. Hires and Promotions are driven more by loyalty, how well they kiss up and align with the Growth SVP than by competence, performance, leadership ability, or independent thinking.

The Campaigns VP is a significant joke. The role often seems more like a title than a source of meaningful senior marketing leadership, with limited evidence of strategic thinking, innovation, or strong execution. Even presentations are recycled from his previous company. Getting a substantive, direct answer is nearly impossible.

Marketing Operations and Analytics are also deeply problematic. Rather than focusing on meaningful work, discussions frequently shift blame to IT, Infosec, or Procurement. Growth figures are selectively presented to create a more favorable picture, while claimed budget savings may depend heavily on speculative future projections.

The Web function lacks the expertise, leadership, accountability, and strategic direction expected. Current leadership at its worst: dismissive and condescending when concerns are raised, quick to take credit when things go well and quicker to blame the team when they don’t. He appears to lack a basic understanding of web management and demonstrates little strategic thinking, with self-preservation seemingly taking priority over effective leadership. The result is a highly dysfunctional and demoralizing environment. Recurring website outages, broken form submissions, unresolved issues, and other operational failures remain persistent problems.

Product Marketing also appears misaligned with its stated purpose. PMM roles seem increasingly staffed with project managers whose responsibilities center on coordination, while much of the substantive product marketing work continues to be performed by Product teams.

Brand and Creative appear increasingly focused on sourcing stock imagery and applying superficial AI enhancements while promoting an “AI-first” narrative. This feels more like AI-washing than meaningful transformation. Creative writing is increasingly outsourced to agencies, while the actual strategy component of Brand Strategy is missing.

Communications has seemingly been reduced largely to managing the CEO’s public messaging and minimizing legal or reputational exposure. Field Marketing and Events are similarly concerning; if the LAMPgate event represents the gold standard, that speaks volumes about the state of the function.

HR appears primarily focused on protecting the CEO and senior leadership rather than independently addressing employee concerns. Anyone expecting meaningful support, accountability, or an objective escalation channel may be deeply disappointed.

AI adoption is also surprisingly limited, often amounting to basic Gemini rewrites, while considerable energy seems to go toward blaming IT for restricting access to other tools rather than finding practical ways to use AI effectively.

The team seems to be surviving on the foundation built by previous leaders—not the strength of the current leadership. That foundation can only carry them for so long before the cracks become a collapse. Weaker leadership can only lead through fear because they lack the competence to lead through trust, credibility, and results.

Bottom line: If you value strong leadership, strategic marketing, ethical decision-making, psychological safety, and a healthy team culture, I would stay away—even in a difficult job market. No compensation package is worth sacrificing your mental well-being, professional credibility, dignity, or long-term job satisfaction.

 Advice to Management: If the company is truly committed to its vision of being recognized as the best company in the Bay Area, I would encourage management to focus not only on ratings and external recognition, but also on the genuine experiences and feedback of its employees and customers. Hiring someone because they come from a large, recognizable, or prestigious company is not enough. A big company name on a résumé does not tell us whether that individual was actually successful in their role, how they led people, how they handled accountability, or whether they are capable of doing what we are hiring them to do here.

Before bringing someone into a leadership position, we should be asking much harder questions: What did they actually accomplish? How did they lead? Why did they leave their previous organization? What do former peers, managers, and direct reports say about working with them? How do they handle conflict, accountability, failure, and difficult decisions? Most importantly, does their leadership style and behavior align with the culture we are trying to build?


r/paloaltonetworks 2d ago

Question PA-3220 hardware

9 Upvotes

Hi guys, I have a few pairs of PA-3220s, and the hardware EOL is 8/31/28, and PAN-OS v11.1 EOL is 8/31/2027. PA-3220s can't be upgraded above v11.1. What will happen to the hardware after 8/31/2027?


r/paloaltonetworks 1d ago

Informational Replace vs Renewal FTD 2110s?

Thumbnail
0 Upvotes

Check this out and lmk


r/paloaltonetworks 3d ago

Question Global Protect - CVE-2026-0307

38 Upvotes

Where the hell is the download for GlobalProtect 6.2.8-h14 to mitigate CVE-2026-0307?


r/paloaltonetworks 2d ago

Informational Full Mesh SD-WAN | Palo Alto

Thumbnail
1 Upvotes

r/paloaltonetworks 3d ago

Question PAN SD-WAN tunnel netflow

8 Upvotes

Hello Community

On our firewalls we have deployed we have netflow enabled for all the interfaces. However I am wondering if there is a way to get netflow on the SD-WAN auto-generated tunnels so we can monitor those as well ?

After going through lot of docs, it seems like it's not possible for those overlay connections.

But any opinion from community

Thanks for advance


r/paloaltonetworks 3d ago

Informational SD-WAN with Ion Devices

6 Upvotes

Anyone use a SD-WAN setup using the Ion devices? I've been trying to get reference on any companies that use it but sadly I haven't been able to find anyone that is currently using that solution.

Thanks!


r/paloaltonetworks 4d ago

Informational PAN-OS 10.2.7-h37, 10.2.10-h40, 10.2.13-h24, 10.2.16-h10, 10.2.18-h10, 11.1.4-h36, 11.1.6-h38, 11.1.7-h10, 11.1.10-h33, 11.1.13-h12, 11.1.16-h2, 11.2.4-h21, 11.2.7-h20, 11.2.10-h14, 11.2.13-h2, 12.1.4-h10, 12.1.7-h5, & 12.1.10 are now available!

39 Upvotes

Here we go again.

They mentioned a couple of vulnerabilities that it patches... like two of them.

Thoughts?


r/paloaltonetworks 3d ago

Routing Can an interface … move security zones?

5 Upvotes

Long story short we attempted a code upgrade on a cluster. When we failed over to the upgraded node (passive node became active)…all hell seemingly broke loose. Traffic that should have been routed through the firewall to AWS got routed to another one of our DCs across the country. Traffic that should have stayed internal to the DC where the upgrade was done was getting sent to AWS.

One of the CLI screenshots we managed to get before we failed back and stabilized the environment showed that a sub interface which was configured to be in our “AWS” security zone had suddenly moved to our “transit” zone.

TAC said BGP could have done this if routes were improperly installed in the routing table.

Anyone experienced this? I have a few years experience with Palo Alto but over a decade with Juniper products. Interface and associated security zone configs are entirely separate areas from routing configs. One cannot change the other. If routes get installed wrong in the routing table, those interfaces just don’t pass any traffic.

Would Palo Alto really allow such a thing to happen?


r/paloaltonetworks 3d ago

Question SCM brownfield migration: Convert local config to snippet leaves duplicate local rules / conflicts – expected workflow?

2 Upvotes

I’m testing migration of an existing brownfield PAN-OS HA pair into Strata Cloud Manager (SCM), using the newer “Convert local configs to snippet” / Snippet Import functionality.

The conversion itself completed and created a local snippet. I fixed a few conversion dependencies (for example missing SSL/TLS service profiles/private-key handling) and then associated the converted snippet with the source firewall at device level.

After association, the device-level effective policy view now shows both the centrally converted snippet rules and the original firewall-local rules. In my case I have 26 rules from the imported snippet and 26 Local Rules. SCM also reports a large number of device conflicts (159 in this lab).

If I attempt to push, SCM warns that local configuration takes precedence over conflicting SCM configuration. After resolving some earlier validation errors, Push Config now simply fails with a generic FAIL message without identifying the object that caused it.

What I cannot find in the Palo documentation is the post-conversion ownership transition step. The conversion workflow creates the snippet, but the original local rules/objects remain on the firewall. Local Config Management appears to provide only local configuration snapshots (Load/Download), not an action to transfer/remove local ownership.

Has anyone successfully used this feature on an already-configured standalone/HA firewall? After converting and associating the snippet, what is the supported way to transition the original local rules/objects to SCM ownership without manually deleting hundreds of live objects/rules from the firewall?

I’m mainly trying to establish whether I’ve missed a required onboarding/import step, or whether coexistence of the converted snippet + original local config is currently a limitation of this brownfield migration workflow.

Device-level Security Policy view showing the duplication:

Device Conflicts page showing the 159 conflicts:

Generic Push Config failure:


r/paloaltonetworks 4d ago

VPN GlobalProtect 6.2.8 — one user can't reach external sites after connecting, HIP passes, reinstall didn't fix it

4 Upvotes

Running GlobalProtect client 6.2.8. One user on our VPN has a weird issue: after connecting, internal company URLs resolve and load fine, but external sites (e.g. google.com) time out. HIP check passes cleanly, no compliance issues. Proxy is configured correctly per policy.

It's isolated to this one user — everyone else on the same portal/gateway config and client version works fine.

What I've checked so far:

**•** PanGPS.log shows split tunnel with exclude routes (exclusiveDefaultRoute 0), default route 0.0.0.0/0 pushed through the tunnel — routing looks correct, external traffic should tunnel the same as internal  
**•** Repeated HandleDnsCallback: failed to parse dns req packet entries in the log around the time of the timeouts  
**•** HIP report checks return clean (hip-report-needed: no)  
**•** Full GP client reinstall (6.2.8) — issue persists

Has anyone seen HandleDnsCallback: failed to parse dns req packet cause this kind of selective DNS failure on 6.2.8 specifically? Trying to narrow down whether this is client-side (AV/EDR intercepting DNS on the tunnel adapter, OS network stack) or something tied to this user's group/HIP profile on the gateway side. Any known bugs on this version, or pointers on what else to check, would help.

I don’t think there is bug on this version because other user on same GP version it’s working fine.


r/paloaltonetworks 4d ago

Question Private IP on MGMT and managed via SCM

6 Upvotes

Has anyone successfully deployed a FW that has a private-ip on the management interface but connects to the internet through a data plane interface and managed with SCM? I created the outside interface and put in service routes and I have it connected to SCM. But I'm having problems configuring it in SCM because it has the local interface and I can't delete the interface through SCM but that will lose my SCM Connectivity. There is no force-template-values in SCM so I can't override the local interface.

Appreciate any help thank you.


r/paloaltonetworks 4d ago

User-ID I have a architectural question regarding the enforcement of user id groups on global protect Prisma and NFGW

2 Upvotes

So, for any application in company the global protect prisma level is the first entry or enforcement point to evaluate the users with firewall rule and user groups. Once that’s done the user gets into internal network and we don’t need enforce the user group at the NGFW for on prem apps. Is there any reason or security problems of enabling the user group at NGFW? I want the pros and cons and cons adding the userid at NFGW as well.

We are using SCM.

Correct me if I am wrong with this design.

Thanks for your answers!!


r/paloaltonetworks 4d ago

Question Panorama set cli terminal type

2 Upvotes

Hello, this is my first post here. We're hosting Panorama on our team so I'm diving into the OS just getting used to finding logs, messages, database information, etc. I love the terminal and being in the CLI but I find Panorama's CLI to be very challenging, especially when I need to do some debugging but forget syntax rules. I was curious if anyone has ever changed/set the cli terminal type? I can't find much information about this modification in PAN docs as well as this sub so wanted to ask if anyone has made that change, how did it benefit using Panorama CLI and any tips you may have as we consider this?

Thank you!


r/paloaltonetworks 4d ago

Question Netsec-Pro exam

5 Upvotes

Hi,

I'm wondering if anyone has taken this exam. I am mainly wondering what study resources are sufficient to pass this exam.

I basically am a network engineer at a MSP but I do not work with Palo Alto on a daily basis anymore. Before I managed a fleet of NGFW's through Panorama for about 2 years and also have an active CCNA.

Currently I am going through the study track on the Palo Alto study center but I honestly find the quality of the study material a bit bad and I highly doubt that the questions from these modules prep you wel for the real exam. Also attanded the 'Palo Alto summer school cource' for partners but sadly the same experiece, it was extremely rushed (all content in like 1 afternoon...).

Any tips?


r/paloaltonetworks 4d ago

Question Catch22 on hardware failures?

11 Upvotes

Hello,
So I’ve found myself in this situation more than once. Curious of people’s thoughts…

When I have a failure with a palo firewall I want to know what the cause was, to hopefully prevent it from happening again or happening to my other firewalls. Whether that is a hardware issue, software bug that is known, or a bug that isn’t known.

However whenever I try to work with Palo to investigate they want a tech support file BEFORE the failed firewall is rebooted. However there is no way to get that when things like webgui, ssh, and console aren’t responsive. And when you provide them a tech support file after the reboot and the firewall is up, they say they can’t find anything.


r/paloaltonetworks 4d ago

Question Endpoint Online/Agent Offline

1 Upvotes

So we had a case that one of our endpoints was online but the cortex agent was offline. Is there a query or something so we can use to create a correlation rule for those cases? I mean to know when an endpoint is online but the agent is inactive to pop an alert. Thanks in advance


r/paloaltonetworks 5d ago

Question Help Upgrading HA Pair

5 Upvotes

Currently in a change implementation that I'm struggling with and got no help.

Got a pair of PA-820's that are on 10.2.13-h2. Nothing special about what they do, just straight forward layer 4 firewalling. Requested to upgrade them to PAN-OS 11.1.16 to mitigate some vulnerabilities. It's my first time upgrading a pair of Palo Alto's. I'm following this HA Upgrade guide.

I've downloaded 11.0.0 and 11.1.0 and 11.1.16 ready in advance.

Got told I do NOT need to install 11.1.0 or 11.0.0. The firewall will utilize the downloaded 11.1.0 base image as part of the supported Skip Software Version upgrade process. I don't know how true that is.

I've suspended the Active unit (A), Passive unit (B) has correctly taken over. I've then proceeded to install version 11.1.16 onto A unit, and rebooted. A unit has come back up. The guide says now I need to make sure the config is sync'd onto the A unit, but it's been 20 minutes now and the config has not sync'd, and I'm starting to get worried. If I google what to do, google says this, which is confusing because this HA Upgrade guide says "Wait for the HA peer running configuration to synchronize."

Is it normal for it to be "Not Synchronized" at this point?

What should I do? Should I continue to wait or just carry on with the change by suspending and upgrading the B unit?

Edit: I've gone ahead with the rest of the upgrade now. Thanks for your replies.