<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama management for Cloud NGFW in Cloud NGFW for Azure Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563206#M19</link>
    <description>&lt;P&gt;Yes, I have followed the instructions and have the recommended version of the plugin. The Cloud NGFW instance was provisioned with a registration key from Panorama and there were no issues during any part of the process. We even went through this process twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I don't see any connected devices, I have nothing to select to when trying to push config to devices (Panorama will manage only this cloud NGFW for start). And under Cloud NGFW in Azure plugin I have nothing under "Associated Cloud NGFW Resources"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="santonic_0-1698300543847.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54685iC25CB7B242E89A56/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="santonic_0-1698300543847.png" alt="santonic_0-1698300543847.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 06:10:22 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2023-10-26T06:10:22Z</dc:date>
    <item>
      <title>Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563086#M17</link>
      <description>&lt;P&gt;We are deploying&amp;nbsp;Cloud NGFW in Azure and want to manage it from Panorama. We have decided for&amp;nbsp;Cloud NGFW in a vWAN option. We followed all the instructions and there weren't any issues. But we can't seem to push policy from Panorama to Cloud NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can we verify the status of integration between Panorama and Cloud NGFW? As Panorama is in Azure as well and&amp;nbsp;Cloud NGFW deployed as a vWAN there shouldn't be any communication issues between them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we select Commit and Push option, the Commit and Push button is unavailable. If we select Push to Devices and Edit Selections we don't have any DG to choose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What should be the status in Azure plugin under Cloud NGFW?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cloud NGFW for Azure" id="Cloud_NGFW_for_Azure"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 08:35:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563086#M17</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-10-25T08:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563135#M18</link>
      <description>&lt;P&gt;Are you running the recommended panorama version for cloud ngfw and have the appropriate azure plugin version 5.1.0?&lt;/P&gt;
&lt;P&gt;The prereq's are listed here: &lt;A href="https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/cngfw-panorama-integration-azure-prerequisites" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/cngfw-panorama-integration-azure-prerequisites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to create a "Cloud Device Group" within the Azure Plugin under "Cloud NGFW" and that group will require keys from your CSP and panorama ip's that are reachable by your Palo Azure Cloud NGFW, you can find that process here &lt;A href="https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/link-cngfw-to-panorama" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/link-cngfw-to-panorama.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;once all that's done use the generate a registration key from the "Cloud Device Group"&amp;nbsp; under "Cloud NGFW" in the azure plugin&lt;/P&gt;
&lt;P&gt;and use that key during the provisioning of the service in azure. I have not done this post deployment so I'm not sure of the process of post panorama integration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on how you connect to your managed firewalls be sure to allow the external source nat if public or internal ip block as the address are dynamic i believe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If all works well then you should see the cngfw's connected under the cloud device group in panorama -&amp;gt; "managed devices" -&amp;gt; summary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 15:49:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563135#M18</guid>
      <dc:creator>TilRando</dc:creator>
      <dc:date>2023-10-25T15:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563206#M19</link>
      <description>&lt;P&gt;Yes, I have followed the instructions and have the recommended version of the plugin. The Cloud NGFW instance was provisioned with a registration key from Panorama and there were no issues during any part of the process. We even went through this process twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I don't see any connected devices, I have nothing to select to when trying to push config to devices (Panorama will manage only this cloud NGFW for start). And under Cloud NGFW in Azure plugin I have nothing under "Associated Cloud NGFW Resources"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="santonic_0-1698300543847.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54685iC25CB7B242E89A56/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="santonic_0-1698300543847.png" alt="santonic_0-1698300543847.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 06:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/563206#M19</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-10-26T06:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564074#M22</link>
      <description>&lt;P&gt;In the end it turned out it was just a connectivity issue; I got confirmation from customer that VNET with Panorama wasn't connected to the HUB where Cloud NGFW was deployed. Later they connected it and everything seems to work now.&lt;/P&gt;
&lt;P&gt;However I now see 2 connected devices (VMs). Is it normal that a single deployment of Cloud NGFW shows as 2 VMs? The other explanation might be that we re-deployed&amp;nbsp;Cloud NGFW again under same name and with same DG and template names. But the old deployment is now removed from Azure and I still see both VMs as connected.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 11:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564074#M22</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-11-02T11:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564107#M23</link>
      <description>&lt;P&gt;Glad you got it sorted and it was something as simple as connectivity. I had four on intialisation of the service but one disconnected as i think the service spins three up by default but as i understand it if any disconnect they will be removed after three days. I had a connectivity issue as well and i beleive that's why i had an addtional firewall over the standard three.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:05:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564107#M23</guid>
      <dc:creator>TilRando</dc:creator>
      <dc:date>2023-11-02T16:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564271#M24</link>
      <description>&lt;P&gt;Ty for the info.&lt;/P&gt;
&lt;P&gt;Well I only have 2, not 3. But both connected so I guess everything is in order. And I guess more will spin up as needed based on throughput needed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 07:45:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/564271#M24</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2023-11-03T07:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/578142#M26</link>
      <description>&lt;P&gt;Hi, This is useful for me as well. However I have one problem. Recently one of the VM instance went down. After logging a call with PA TAC , the TAC engineers rebooted the instance on the Azure side and now I am able to see the instance as connected. However I am unable to add the VM instance in to the Device group. If I am trying to push any policy, it is showing only the two instances under the selected device group. Any help to add the one instance in to the existing DG?. If I push the configuration only to the two VM Instances what will be happen?. this will impact the traffic flow?.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Madhankumar.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 06:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/578142#M26</guid>
      <dc:creator>MADHANKUMARRANGASAMY</dc:creator>
      <dc:date>2024-02-23T06:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama management for Cloud NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/578325#M28</link>
      <description>&lt;P&gt;I think this is PA (or TAC) responsibility. In this scenario you are just consuming their &lt;SPAN&gt;Cloud NGFW&amp;nbsp;&lt;/SPAN&gt;service. All the work under the hood should be handled by PA. Especially as this is managed via Panorama plugin and not as usual VM instance.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 11:27:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-discussions/panorama-management-for-cloud-ngfw/m-p/578325#M28</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2024-02-26T11:27:33Z</dc:date>
    </item>
  </channel>
</rss>

