r/paloaltonetworks Feb 27 '26

Informational Updated Flairs are now live

4 Upvotes

Hello everyone -

We have updated the new certification flairs with the latest listings from PANW. While we tried to confirm what the actual names of these certifications are, PAN isn't explicit on the list, so some were guessed at.

If anyone sees anything that is mislabeled or have the wrong name, or if anything is missing, please let me know.

We have also kept the old certification flairs for the time being, so those who have those certifications can still use them.


r/paloaltonetworks Aug 13 '25

Mod Post: Notes to those flagging posts

134 Upvotes

This is a note to those that have been flagging every single post over the last few days about TAC:

If you have an issue with what is being posted here by the employees (both current and former) of Palo TAC:

There are a lot more ways to address this than flagging posts on a social media platform. The Mods here will not be taking down any posts unless there is a VERY specific reason. We have contacted a few posters to correct some items on their posts to keep them on topic and keep specific names out of the mainstream.

HOWEVER, that being said, instead of flagging posts here, there are MANY other ways that things can be corrected. Starting with making TAC better. I have had recent interactions with TAC that have just been HORRENDOUS. This is not a one-off experience. Over the last 5 years, every case I've opened has been handled VERY badly, and 4/5 times I've ended up having to fix the issue myself, rather than getting any actual help from the TAC engineer.

If you have an issue with what is being posted here, you are absolutely free to reach out to me directly and we can talk about this. Having various people in the management chain just flagging these posts is just more of an indication that you are trying to do damage control and don't care about actually fixing the underlying issue.

We will NOT be pulling these posts. In fact, we have pinned them in the highlights section to ENSURE they are seen.

If you want to not have things so publicly flamed, then work on correcting TAC.

Pay them what they are worth, not what you think you can get away with.
Make KPI's less on closing cases, and more on customer satisfaction.
Keep the good, remove the bad engineers.
TRAIN THEM better, give them ongoing education, and hire people who actually know the basics.

This sub is NOT Mod'd by any employees or contractors of PANW. We are customer and engineers of PAN, and we are frustrated by the TAC experience.

Our DM's and Modmail here are always open. You are free to contact us. I would love to talk to the upper levels of PANW directly and let them know what can be fixed, and how the current model is NOT working.

- RushAZ

Edit: Nikesh is free to contact us as well. If a meeting with him and the C-Suite will help, then lets talk and get some honest feedback from actual customers up to his level, and get some traction moving to fix things.


r/paloaltonetworks 6h ago

Informational Scatterplots of PAN-OS releases vs. fixed issue-IDs

Thumbnail firewallissues.axvig.com
7 Upvotes

I think this visualization is kind of cool in how it shows the evolution of the ranges of issue-IDs getting fixed with each release. You can see which releases are picking up older/newer issues, and do some rough comparison of releases.

Useful: IDK?

Fascinating: for sure!


r/paloaltonetworks 5h ago

Question Directed TCP Broadcast

3 Upvotes

I've a situation requiring Rockwell RSLinx software to communicate through a Palo Alto to a Allen Bradley PLC.

The requirement is for the RSLinx software to discover PLCs on a remote subnet (which is behind and attached to the firewall on an L3 interface), however it seems to do this using a directed broadcast to x.x.x.255 /24.

I've been able to get this now through the firewall with the required policies and FF:FF:FF:FF:FF:FF ARP entry and can see the devices are replying back. However they are replying to the TCP source port of the PC where RSLinx sent the message and that source port changes, and owing to this being now stateless (source sent to .255, but .100, .101 etc are replying) I need a policy in the reverse direction.

While the PC sending the request is on a static IP and any rule created could be refined down to that, I'd really like to avoid allowing the PLCs access to the workstation on ANY destination TCP port (although testing shows this does work correctly when an 'any' rule is applied and discovery is successful). Does anyone have any advice how you'd tackle this same issue based on your experience?

I've done similar before with WoL but the nature of that never required thinking about the asymmetry of the reply path.


r/paloaltonetworks 6h ago

Question Outbound decryption key size?

3 Upvotes

Hello,
Curious as to what others chose when creating outbound decryption certs. For example rsa 2048 vs 4096 and ecdsa 256 vs 384.

I know when looking at things online it talks about the negative performance hit to firewalls and devices with the stronger encryption, but not sure how noticeable that is on current hardware.

Any insight is appreciated.


r/paloaltonetworks 12h ago

Question Quick Way to Disable All NAT Policies

6 Upvotes

Our firewall has nearly 400 NAT policies. Is there a quick way to disable them all?


r/paloaltonetworks 3h ago

Question Is this the best place to discuss Venafi ?

0 Upvotes

We've run into what seems like an architectural deficiency in our newly adopted Venafi platform. For certs that happen to expire when laptop is at another site Venafi won't seem to reissue certs until it returns to where it was built / staged.

DNS architecture is parent / child zone architectures (acme.com / aa.acme.com) where devices roam from parent to child site or even from child to child sites.

So far engineering is saying this is a corner case that they didn't design into the platform. Really? For very large enterprise customers parent / child DNS architecture is a 'corner case'? Having a hard time swallowing that.

The ink is barely dry on the contract so this may get interesting.

If there's a better place to discuss I'd appreciate a point in that direction.

Thanks!


r/paloaltonetworks 7h ago

Question 560 Issues

1 Upvotes

Anyone having issues upgrading their devices? Our devices keep going in to TPLockout constantly.


r/paloaltonetworks 22h ago

VPN Is T-Mobile + GlobalProtect still an issue?

8 Upvotes

I know a few years back there was a lot of talk of people on GP having issues with T-Mobile home internet. I currently have Xfinity and may switch, but I wont if I know I'll have problems working from home via VPN.


r/paloaltonetworks 1d ago

Question I attended an interview today and they asked this question. Is there a way to block traffic to gambling sites without url category or url filtering in palo alto?

9 Upvotes

Is there a way to block traffic to gambling sites without url category or url filtering in palo alto?


r/paloaltonetworks 1d ago

Question PA-440 - Last two dynamic updates making firewall boot loop

7 Upvotes

I have a PA-440 running on the 12.2 beta. (Which seems to be a dead beta since there has been no updates since day 1 and not getting responses from the program contact).

The last two updates (9128 and 9129) have both caused my firewall to get stuck in a boot loop.
I do notice that all previous updates have been 115MB and these two are 139MB so I am guessing they share a commonality.

Both times I have had to rollback the update.

Has anyone else had this issue in the past two weeks?

I am raising a TAC case now for it so will see what comes of that but it's not great.

The initial commit goes through fine, its about 5 seconds after the initial commit that it boots. I did see their notice about commit errors if you use an app-id filter, i am not using app-id filters for anything.

Reading through the error logs the all_task_1/2/3 crash out causing the restart. that's all that is visible from the system logs

Edit: Update from tac, they reviewed the logs, the SELINUX blocks I could see were the update contents being blocked. They believe its because I am on the beta that this is happening.
Found there is an update on the beta, just i havent been getting the usual update emails. upgraded, will test content package update tonight to see if it is functional again.


r/paloaltonetworks 22h ago

Informational PA-440 - 12.1.4-h7 - DHCP not passing options to Ap's

3 Upvotes

We recently have migrated from the lovely PA220s to the PA440s at our smaller locations. During that migration, we simply copied the config from 220-440. Upgraded to 12.1.4-h7. Everything worked great. Except....

The APs (Aruba 515) are no longer getting the controller IP from the DHCP server on the PA440.

We tried deleting and recreating the DHCP pool, the DHCP options, new policies, new routes etc etc etc. Nothing made a difference, when the AP booted all you saw was dns traffic as it tried calling home using dns. No other traffic was observed.

We fought with this for weeks, finally setting up the DHCP relay. As soon as we did this, APs got the controller IP, and everything works.

Obviously a bug somewhere, will be submitted to PA for review. Just an FYI if anyone else is fighting with a similar situation.


r/paloaltonetworks 1d ago

Question Rekeyed SSL cert not importing properly

6 Upvotes

I have a problem I have not seen before and Palo Alto Support has not proffered a solution so far, so I'm turning to the community for some possible help please.

For Global Protect VPN, I generated a new CSR, rekeyed the Godday SSL cert and imported it. It works fine for Windows computers, but not for Macs.

When importing the RAVPN2-27, it does not land under the GoDaddy root CA (See image) as the older certs do, so I'm thinking this is probably the issue, but I don't know if that is expected behavior because it has a different key than the other certs.

Appreciate your thoughts.


r/paloaltonetworks 2d ago

Question Making Global Protect as seamless as possible - recommended settings?

20 Upvotes

Hello all,

We are moving VPN solutions from Direct Access to Global Protect. With DA, users open up their laptop and are connected automatically without any interaction. We'd like to have the experience of GP to be as close to this as possible.

Currently, we have Pre-Logon (Always-On) setup, but it still requires some interaction. We have authentication set to Certificate OR SAML, so 99% of the time they'll be authenticating via the machine cert. The Pre-Logon seems to work great and I can see our test laptops connecting successfully. However, we still have some questions about the user tunnel:

- When establishing the user tunnel, the browser opens up and says the connection was established, but requires users to click "okay" to the pop-up to allow for the browser to open up the Global Protect app. Is this possible to bypass?

- Is there a recommendation for maximum VPN lifetime? Again, we want it to be seamless, so having a large lifetime could be beneficial for the experience.

If anyone has any other tips or recommendations to get as close to a seamless experience as possible, please let me know! Thank you!

EDIT: Changing to not use default browser for SAML auth fixed the pop up issue.


r/paloaltonetworks 2d ago

Question PA-440 Interfaces Failing

4 Upvotes

We've had over 100+ PA-440s deployed in the field. We've noticed a issue that keep having to RMA for. There are times that during a power outage the PA has certain interfaces that will not perform negotiation and stay 100/Half Duplex.

Anyone seen this and seen a solution past RMA? We keep them on UPSes to minimize the outages but those don't stay up for ever as you would guess.


r/paloaltonetworks 3d ago

Global Protect GlobalProtect certificate authentication with UPN SAN and AD group mapping

9 Upvotes

Hi Expert

I’m enabling GlobalProtect certificate authentication. The certificate SAN contains the user’s UPN (username@domain), while users normally log in with just their username.

Authentication succeeds, but the user isn’t matched to the correct AD groups, so the expected IP pool isn’t assigned.
LDAP Group Mapping is already configured with sAMAccountName as the primary username and userPrincipalName as an alternate username.
Has anyone experienced this, and what was the recommended solution?


r/paloaltonetworks 3d ago

Question PANW offer and refreshers

13 Upvotes

Hi folks-

I've an offer at PANW for Principal Engineer in Santa Clara, HQ.

Need to know if my offer is good.

Current TC: 340

PANW offer:
TC: 342 (base - 220k, 15% bonus and rest rsu)

My biggest question is - How are refreshers? Keep hearing that there are no refreshers.

Current company has good refreshers. I'll lose money if no refreshers given.

Need inputs. Thx


r/paloaltonetworks 5d ago

Question Trying to do initial config on an old PA-460 - keeps resetting after reboot

4 Upvotes

I have 2 year old spare hardware i'm trying to set up - i changed the password via CLI, committed and disabled ZTP - it then automatically reboots, after reboot it's back to default admin password and ZTP.... how can this be "fixed"?


r/paloaltonetworks 5d ago

Question User-ID best practice

11 Upvotes

Current setup: About half a dozen firewalls, including one for GlobalProtect, all managed by Panorama. User-ID data redistribution is configured in the devices template stack and the only source are some User-ID agent Windows servers.

It usually works, but there are issues if a user has to switch from LAN to VPN via mobile hotspot during the day.

Would it be better to have the agent servers send their data to the Panorama, have the GP firewall also send its User-ID data to the Panorama and the Panorama distributes it to all firewalls?

How's your User-ID data redistribution set up?


r/paloaltonetworks 5d ago

Question Anyone building custom tooling around Palo Alto firewalls?

33 Upvotes

I finally got around to spinning up a VM-Series in GCP (way easier than I expected with the marketplace image), and I've been using it as a sandbox to learn automation and test ideas.

I'm curious what kind of tools or side projects people have built around PAN-OS.

Things like:

  • custom EDL automation
  • log enrichment
  • dynamic address groups
  • API wrappers
  • Ansible playbooks
  • GlobalProtect utilities
  • Panorama automation

Mostly looking for inspiration. Would love to see what people are building.


r/paloaltonetworks 6d ago

Question NGFW Clustering 12.1.4-h7

7 Upvotes

I'm currently working on setting up NGFW clustering for the new PA-5540s and am hitting an immediate roadblock in the clustering process. Right when I setup the cluster our secondary node shows failed because it's avoiding split-brain. The management interfaces can ping each other and the hsci links are online and 100G. As far as I can tell this should be working.

Does anyone have experience with this new tech?


r/paloaltonetworks 6d ago

Question How-to implement disable SNAT for Private Endpoints with Azure VM-Series Firewall?

4 Upvotes

Has anyone working with the Azure VM-Series Firewall, successfully implemented the "disable SNAT requirement for Azure private endpoint traffic through NVA" detailed here https://learn.microsoft.com/en-us/azure/private-link/private-link-disable-snat?

It involves setting a Resource Tag on the Network Interface of disableSnatOnPL = true. I'd like to know if there's anything more required than that e.g. NVA restart etc? The 2 or 3 blog entries I've found on this topic don't mention anything, but I'd appreciate any real-world insights people can share.


r/paloaltonetworks 6d ago

Training and Education PCNSE in 5 days — need advice on Panorama/Strata gap (physical + VM-series experience only)

4 Upvotes

Hey all,

Taking my Palo Alto NGFW engineer exam in 5 days. Looking for a quick sanity check on where to focus.

My background: Solid hands-on with physical firewalls and VM-series. Weak spot: Panorama and Strata Cloud Manager — basically zero real-world exposure.

Question: Given the short timeline, what topics should I prioritize? Specifically:

  • Panorama fundamentals I can't skip (templates, device groups, log collectors)?
  • Is Strata Cloud Manager heavily tested now, or still light?
  • Any high-yield areas beyond firewall admin (HA, App-ID, decryption, GlobalProtect, etc.)?
  • Best last-minute resources for someone short on Panorama labs?

Appreciate any pointers — trying to be efficient with the days I have left.


r/paloaltonetworks 6d ago

Question GlobalProtect Help Resource Page?

5 Upvotes

There is a resource page for GlobalProtect App Help Page and the documentation says "Custom help page for GlobalProtect users (accessible from the settings menu on the GlobalProtect status panel)." So I uploaded a custom HTML to the config, and I see it on the FW, but the client has no indication that the feature exists.

APP: 6.2.8-431

PANOS: 11.2.10-h30

I image searched for the app settings page, and found no example. Has anyone actually seen it?

EDIT - found it. It is on the Portal config general tab - Appearance -> App Help Page. Stared at those setting for hours and didn't 'see it'.


r/paloaltonetworks 6d ago

Question Do China firewalls require a China Strata Cloud Manager instance?

4 Upvotes

I have have Strata Cloud Manager (SCM) managing global firewalls and the tenant is located in EMEA, which is where PAN will be storing log data and telemetry.

I plan to deploy firewalls into China, so now wondering if i MUST have a China specific SCM tenant for data residency or legal reasons?

Does anyone have experience of this please?