· via dev.to (home feed)
Internet-wide scan counts 613 exposed GlobalProtect portals among 20,383 Palo Alto services
Fresh ZoomEye measurements reported on dev.to put hard numbers on Palo Alto Networks' internet-exposed footprint: 20,383 matching services overall and 613 reachable GlobalProtect VPN portals.

What the measurements show
A post published on dev.to on 26 September 2026 puts fresh, internet-scale numbers on how much of Palo Alto Networks' installed base answers to the open internet. The author collected the figures on the same date using the ZoomEye cyberspace search engine's Python SDK, running a small set of queries against the whole reachable address space.
The results: a query for the app pattern "Palo Alto Networks" returned 20,383 services, a query for "GlobalProtect" returned 613, and a query for "PAN-OS" matched just 3. A separate query on port 9440, described in the post as a commonly documented management port for this product family, produced a single result.
Each query was also run with ZoomEye's web sub-type, which restricts results to services where a web component has been identified. Every one of those returned zero — a detail the author is careful to interpret rather than take at face value.
The zeros are a fingerprinting gap, not missing interfaces
According to the dev.to post, empty web results do not mean the appliances lack web interfaces. They mean ZoomEye's web-identification layer did not attach a component attribution to those result sets. Edge appliances are usually recognized through patterns embedded in their vendor login pages, and those patterns do not always translate into a web component classification.
The post draws a similar lesson from the ratio between the three counts. If 20,383 vendor-branded services, 613 GlobalProtect hits and 3 PAN-OS hits described a single coherent estate, then roughly 97 percent of deployments would use no recognizable naming at all — a conclusion the author calls almost certainly wrong. The more plausible reading is that internet-wide identification of this vendor's gear rests on a narrow collection of page signatures, and most deployments respond with something a scanner cannot map back to a vendor string. In effect, these figures are a floor rather than a census.
Why 613 portals carries the operational weight
The GlobalProtect count is the number the post treats as most meaningful. A GlobalProtect portal is a remote access entry point: it authenticates users, brokers VPN sessions, and stands in front of the network that everything else is meant to protect. The author notes that 613 is small in absolute terms, but each reachable portal is an entry point into one particular organization's internal network.
The single hit on port 9440 points in the opposite direction. Whatever the state of the data plane, exposing a management interface to the open internet appears to be rare across this vendor's fleet.
What defenders can do with a small, precise number
The post's central argument about small numbers is that they can be worked through one by one. An organization tracking GlobalProtect exposure gets an exact count rather than an estimate, because the identification method is narrow and the population is limited — the opposite of generic web server fingerprints, where counts reach into the hundreds of millions and the only practical question is scale.
Two actions follow, per the post. First, check whether the organization's own portal shows up in a ZoomEye result for the GlobalProtect pattern, which answers the external reachability question directly. Second, treat any portal that does appear as an authentication system first and a network device second: the patching, account-review and logging rigor normally reserved for identity infrastructure belongs here too, because that is what the portal functionally is.
Why it matters
Measurements like this turn a vague worry — is our VPN edge reachable from anywhere? — into a checkable fact. A population of 613 portals is small enough that defenders, researchers and vendors can reason about it individually, and each owning organization can establish definitively whether it is on the list. At the same time, the gulf between 20,383 vendor-matched services and the tiny product-name counts is a reminder that internet-wide scans see through a keyhole: the true estate is larger than any fingerprint query suggests. A clean scan result is therefore weak evidence of safety, while a hit is strong evidence of exposure and a prompt to act.
- #network-security
- #vpn
- #attack-surface
- #zoomeye
- #cloud