<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CNGFW integration with Panorama in Cloud NGFW for AWS Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cngfw-integration-with-panorama/m-p/995870#M454</link>
    <description>&lt;P&gt;&lt;SPAN&gt;To integrate the Cloud NGFW service with Panorama virtual appliance, panorama running&amp;nbsp;software version 10.2, 11.0, or 11.1 and not greater than 11.1 as per the below KB Article.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/cngfw-panorama-integration-azure-prerequisites" target="_blank" rel="nofollow noopener noreferrer"&gt;Panorama Integration Prerequisites&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, I recently deployed VM Series Panorama running on 11.2.4-h1, which being integrated with CNGFW (azure plugin version 5.2.1) and observed 3 VMs got created with same device name &amp;amp; with different serial numbers which are in sync mode (green) in panorama (Manage device &amp;gt; summary) and connected with Panorama. Commit has been successful upon test rule creation. Drawback I see that unable to access CNGFW via GUI &amp;amp; CLI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone please give your inputs or share your experience on my below queries?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Will this integration be stable as I made setup on higher versions than palo advised?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. How can we access to CNGFW? Is GUI &amp;amp; CLI possible instead panorama management?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Will cost or pricing or billing applicable to 3 VMs (but I created single CNGFW in Azure marketplace)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Will NGFW Credits be applied to 3 VMs or 3 Serial numbers if I register with CSP support account?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Dec 2024 12:54:38 GMT</pubDate>
    <dc:creator>l.ellandula</dc:creator>
    <dc:date>2024-12-01T12:54:38Z</dc:date>
    <item>
      <title>CNGFW integration with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cngfw-integration-with-panorama/m-p/995870#M454</link>
      <description>&lt;P&gt;&lt;SPAN&gt;To integrate the Cloud NGFW service with Panorama virtual appliance, panorama running&amp;nbsp;software version 10.2, 11.0, or 11.1 and not greater than 11.1 as per the below KB Article.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-ngfw/azure/cloud-ngfw-for-azure/panorama-policy-management/cngfw-panorama-integration-azure-prerequisites" target="_blank" rel="nofollow noopener noreferrer"&gt;Panorama Integration Prerequisites&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, I recently deployed VM Series Panorama running on 11.2.4-h1, which being integrated with CNGFW (azure plugin version 5.2.1) and observed 3 VMs got created with same device name &amp;amp; with different serial numbers which are in sync mode (green) in panorama (Manage device &amp;gt; summary) and connected with Panorama. Commit has been successful upon test rule creation. Drawback I see that unable to access CNGFW via GUI &amp;amp; CLI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone please give your inputs or share your experience on my below queries?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Will this integration be stable as I made setup on higher versions than palo advised?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. How can we access to CNGFW? Is GUI &amp;amp; CLI possible instead panorama management?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Will cost or pricing or billing applicable to 3 VMs (but I created single CNGFW in Azure marketplace)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Will NGFW Credits be applied to 3 VMs or 3 Serial numbers if I register with CSP support account?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 12:54:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cngfw-integration-with-panorama/m-p/995870#M454</guid>
      <dc:creator>l.ellandula</dc:creator>
      <dc:date>2024-12-01T12:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: CNGFW integration with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cngfw-integration-with-panorama/m-p/1226261#M458</link>
      <description>&lt;P&gt;1. Will this integration be stable as I made setup on higher versions than Palo advised?&lt;BR /&gt;Short answer: It's not guaranteed.&lt;BR /&gt;Explanation: Palo Alto typically certifies certain combinations of Panorama versions, Azure plugin versions, and CNGFW images for stability and support. Running Panorama 11.2.4-h1 with plugin 5.2.1 may not be an officially supported combination, especially with latest CNGFWs, so there may be bugs or unexpected behavior.&lt;BR /&gt;Check the Compatibility Matrix on Palo's support site to verify compatibility. If not aligned, you’re in “best effort” support territory.&lt;BR /&gt;If you're using CSP licensing or Premium Support, they may still assist, but they might ask you to downgrade to a certified version.&lt;/P&gt;
&lt;P&gt;2. How can we access the CNGFW? Is GUI &amp;amp; CLI possible instead of Panorama management?&lt;BR /&gt;Short answer: Yes, but it depends on deployment model.&lt;/P&gt;
&lt;P&gt;Explanation: By default, CNGFWs deployed from Azure Marketplace via templates may not expose their Mgmt interface to the internet or even internal subnets directly for security.&lt;BR /&gt;To enable CLI/GUI access:&lt;BR /&gt;Ensure Mgmt NIC has a public IP (if internet access is required).&lt;BR /&gt;Add proper NSG rules or route tables to allow access (typically TCP 22 for SSH, TCP 443 for GUI).&lt;BR /&gt;Confirm Panorama mode is not enforcing “panorama-only access” in the bootstrap config (check the init-cfg.txt or launch config).&lt;BR /&gt;You can also create a jumpbox VM in the same subnet to access the CNGFW via private IP.&lt;BR /&gt;CLI access (SSH) and GUI (HTTPS) are possible as long as the management interface is reachable.&lt;/P&gt;
&lt;P&gt;3. Will cost or pricing or billing apply to 3 VMs (but I created single CNGFW in Azure marketplace)?&lt;BR /&gt;Short answer: Yes, Azure charges per running VM instance.&lt;/P&gt;
&lt;P&gt;Explanation: If 3 VMs were spun up, Azure will bill you for all 3, even if it was unintentional. This might have happened due to:&lt;BR /&gt;HA or autoscale being enabled in the deployment template.&lt;BR /&gt;Custom bootstrap config spinning up extra instances.&lt;/P&gt;
&lt;P&gt;You can check in Azure:&lt;BR /&gt;Go to Azure Portal &amp;gt; Resource Group where you deployed the CNGFW.&lt;BR /&gt;Look for VMs prefixed with the same deployment name.&lt;BR /&gt;Azure bills per VM-hour + potential extra storage/networking charges.&lt;/P&gt;
&lt;P&gt;4. Will NGFW Credits be applied to 3 VMs or 3 Serial Numbers if I register with CSP support account?&lt;BR /&gt;Short answer: Yes – NGFW credits are applied per firewall instance/serial, not per deployment.&lt;/P&gt;
&lt;P&gt;Explanation: Each serial number represents a separate firewall instance in Palo Alto’s licensing model, so:&lt;BR /&gt;If you see 3 serial numbers, registering them will consume 3x the credits.&lt;BR /&gt;This is true even if they were deployed unintentionally or as part of an autoscale/HA pair.&lt;/P&gt;
&lt;P&gt;You can:&lt;BR /&gt;Open a support case with Palo Alto CSP support to potentially reclaim credits for unintentional instances.&lt;BR /&gt;Decommission unused VMs and remove serials from CSP portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Suggested Actions:&lt;BR /&gt;Verify version compatibility using Palo's Compatibility Matrix.&lt;BR /&gt;Check Azure Resource Group for how/why 3 VMs were deployed.&lt;BR /&gt;Use a jumpbox VM or open NSG temporarily to access CNGFW via CLI/GUI.&lt;BR /&gt;In Panorama, compare config and logs across all 3 serials—see if any are idle or duplicates.&lt;BR /&gt;Reach out to Palo support for help with credit disputes or deployment cleanup.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 20:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/cngfw-integration-with-panorama/m-p/1226261#M458</guid>
      <dc:creator>fcsexpert</dc:creator>
      <dc:date>2025-04-10T20:53:52Z</dc:date>
    </item>
  </channel>
</rss>

