<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Assistance with Design of Palo Alto Firewalls &amp;amp; Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/assistance-with-design-of-palo-alto-firewalls-amp-panorama/m-p/582186#M2250</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;DIV id="tinyMceEditornaeemshahzad_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;I have attached network topology based on Fortigate firewalls which needs to be migrated to Palo Alto on all 3 sites, Plus I Want to use PANOS SDWAN with Panorama as well, Brief description of network is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- HO site will have 2 x PA 1410 in A/P HA&lt;/P&gt;
&lt;P&gt;- Virtual Panorama will be deployed in HO site&lt;/P&gt;
&lt;P&gt;- Branch A don't have a static Public IP , hence It makes a dialup IPSEC VPN connection to HO&lt;/P&gt;
&lt;P&gt;- Branch B has a static Public IP and makes IPSEC VPN connection to HO site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have below concerns when considering PANOS SDWAN with Panorama,&lt;/P&gt;
&lt;P&gt;- Can I replace site-site IPSEC VPN with PANOS SDWAN Dynamic VPN setup ?&amp;nbsp; for this I suppose Panorama should be on a central location &amp;amp; not dependent on Site to Site VPN to connect &amp;amp; manage remote branch firewalls.&lt;/P&gt;
&lt;P&gt;- Shall I perform DNAT on HO Firewall to expose Panorama to public IP &amp;amp; connect to Branch Firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Mar 2024 08:12:52 GMT</pubDate>
    <dc:creator>N.Carabia</dc:creator>
    <dc:date>2024-03-31T08:12:52Z</dc:date>
    <item>
      <title>Assistance with Design of Palo Alto Firewalls &amp; Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/assistance-with-design-of-palo-alto-firewalls-amp-panorama/m-p/582186#M2250</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;DIV id="tinyMceEditornaeemshahzad_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;I have attached network topology based on Fortigate firewalls which needs to be migrated to Palo Alto on all 3 sites, Plus I Want to use PANOS SDWAN with Panorama as well, Brief description of network is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- HO site will have 2 x PA 1410 in A/P HA&lt;/P&gt;
&lt;P&gt;- Virtual Panorama will be deployed in HO site&lt;/P&gt;
&lt;P&gt;- Branch A don't have a static Public IP , hence It makes a dialup IPSEC VPN connection to HO&lt;/P&gt;
&lt;P&gt;- Branch B has a static Public IP and makes IPSEC VPN connection to HO site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have below concerns when considering PANOS SDWAN with Panorama,&lt;/P&gt;
&lt;P&gt;- Can I replace site-site IPSEC VPN with PANOS SDWAN Dynamic VPN setup ?&amp;nbsp; for this I suppose Panorama should be on a central location &amp;amp; not dependent on Site to Site VPN to connect &amp;amp; manage remote branch firewalls.&lt;/P&gt;
&lt;P&gt;- Shall I perform DNAT on HO Firewall to expose Panorama to public IP &amp;amp; connect to Branch Firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 08:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/assistance-with-design-of-palo-alto-firewalls-amp-panorama/m-p/582186#M2250</guid>
      <dc:creator>N.Carabia</dc:creator>
      <dc:date>2024-03-31T08:12:52Z</dc:date>
    </item>
  </channel>
</rss>

