<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/526250#M1303</link>
    <description>&lt;P&gt;This seems like a bug that causes crashes or/and memory leaks and till it is fixed maybe you can run a script using tools like Ansible or XSOAR to periodically restart the process or the managment plane:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/panorama" target="_blank" rel="noopener nofollow noreferrer"&gt;https://xsoar.pan.dev/docs/reference/integrations/panorama&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Jan 2023 08:58:54 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2023-01-08T08:58:54Z</dc:date>
    <item>
      <title>The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/525080#M1293</link>
      <description>&lt;P&gt;Panorama is used for management and log collection. The IP address of Panorama has not changed. There is a firewall outside Panorama, which maps the 3978 port of the firewall's exit IP to Panorama. The managed firewall was originally configured with the private network IP of panorama. Now it is changed to the mapped public network IP. After the change, the original private network IP is still reachable. The management traffic of the firewall will pass through its own data layer. It can be seen from the firewall session that there is still a session to the original private IP address. Is this normal? Is there an official statement?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 08:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/525080#M1293</guid>
      <dc:creator>Wilbur</dc:creator>
      <dc:date>2022-12-26T08:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/525355#M1297</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple of things here to check, one would be the configurations that include the original IP of the Panorama, such as log collector groups and so on, as the traffic for the Panorama communication is running through the data plane of the firewall I would look at the session browser to see if these are just old sessions that are still active, if they are you could try clearing them, you can do this from the session browser by clicking the X at the end of the session entry, you could also try restarting the management server of the firewall using the "&lt;SPAN&gt;debug software&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;restart&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;process&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;management&lt;/EM&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;EM&gt;server&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;From the command line, you will lose the management connectivity to the firewall momentarily as it restarts but it should not affect data plane traffic in any way.&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 11:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/525355#M1297</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2022-12-28T11:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/526250#M1303</link>
      <description>&lt;P&gt;This seems like a bug that causes crashes or/and memory leaks and till it is fixed maybe you can run a script using tools like Ansible or XSOAR to periodically restart the process or the managment plane:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/panorama" target="_blank" rel="noopener nofollow noreferrer"&gt;https://xsoar.pan.dev/docs/reference/integrations/panorama&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 08:58:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/526250#M1303</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-08T08:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/527199#M1319</link>
      <description>&lt;P&gt;Automating those tasks is really elegant solution, XSOAR would make it really easy to, I wonder is there a playbook already for this? I will check when I have chance.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 10:50:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/527199#M1319</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2023-01-16T10:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/557449#M1841</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I configured the public IP to Panorama's management interface, this problem was solved. Thank you for your support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Wilbur&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 02:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/the-panorama-ip-has-been-changed-on-the-firewall-but-the/m-p/557449#M1841</guid>
      <dc:creator>Wilbur</dc:creator>
      <dc:date>2023-09-12T02:35:55Z</dc:date>
    </item>
  </channel>
</rss>

