<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Best Guides for New Firewall Deployment in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-best-guides-for-new-firewall-deployment/ta-p/515059</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;I data-stringify-type="italic"&gt;This article is based on a discussion,&amp;nbsp;&lt;SPAN&gt;&lt;A title="Best guides for new Firewall Deployment" href="https://live.paloaltonetworks.com/t5/tkb/workflowpage/tkb-id/members_discuss/article-id/106796" target="_blank" rel="noopener"&gt;Best guides for new Firewall Deployment&lt;/A&gt;,&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;posted by&lt;SPAN&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;.&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;Read on to see the discussion and guidance from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;.&lt;/I&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I am deploying a new firewall for a PoC; however, I am having some issues. I have deployed and activated the server on Azure, I am using VM-Series. On the Azure side, there being no restrictions, the server is not able to connect to the internet for updates.&amp;nbsp;&lt;BR /&gt;I must be missing something basic in understanding/setup so any pointers would be great.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If you are looking for a place to start when configuring your new firewall, check out this post to get started:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_self"&gt;Secure Day-One Configuration Not for the Faint of Heart&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Solution:&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like a routing/policy issues with the original PAN you deployed. I wouldn't recommend having the management interface internet facing unless you lock it down to source IP's. However you can change the services, so they use a different interface to reaching out and grabbing updates, etc.&lt;/P&gt;
&lt;P&gt;If you're adventurous — &lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_self"&gt;https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501&lt;/A&gt;&amp;nbsp;— it blocks almost everything so be careful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 16 Sep 2022 13:13:08 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2022-09-16T13:13:08Z</dc:date>
    <item>
      <title>Nominated Discussion: Best Guides for New Firewall Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-best-guides-for-new-firewall-deployment/ta-p/515059</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;I data-stringify-type="italic"&gt;This article is based on a discussion,&amp;nbsp;&lt;SPAN&gt;&lt;A title="Best guides for new Firewall Deployment" href="https://live.paloaltonetworks.com/t5/tkb/workflowpage/tkb-id/members_discuss/article-id/106796" target="_blank" rel="noopener"&gt;Best guides for new Firewall Deployment&lt;/A&gt;,&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;posted by&lt;SPAN&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;.&lt;/SPAN&gt;&lt;/I&gt;&lt;I data-stringify-type="italic"&gt;&amp;nbsp;Read on to see the discussion and guidance from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;.&lt;/I&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I am deploying a new firewall for a PoC; however, I am having some issues. I have deployed and activated the server on Azure, I am using VM-Series. On the Azure side, there being no restrictions, the server is not able to connect to the internet for updates.&amp;nbsp;&lt;BR /&gt;I must be missing something basic in understanding/setup so any pointers would be great.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If you are looking for a place to start when configuring your new firewall, check out this post to get started:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_self"&gt;Secure Day-One Configuration Not for the Faint of Heart&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Solution:&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sounds like a routing/policy issues with the original PAN you deployed. I wouldn't recommend having the management interface internet facing unless you lock it down to source IP's. However you can change the services, so they use a different interface to reaching out and grabbing updates, etc.&lt;/P&gt;
&lt;P&gt;If you're adventurous — &lt;A href="https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501" target="_self"&gt;https://live.paloaltonetworks.com/t5/general-articles/secure-day-one-configuration-not-for-the-faint-of-heart/ta-p/435501&lt;/A&gt;&amp;nbsp;— it blocks almost everything so be careful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 16 Sep 2022 13:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-best-guides-for-new-firewall-deployment/ta-p/515059</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-09-16T13:13:08Z</dc:date>
    </item>
  </channel>
</rss>

