<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama SD-WAN Zone Mapping? No longer needed or no longer available? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-sd-wan-zone-mapping-no-longer-needed-or-no-longer/m-p/1227876#M2858</link>
    <description>&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;I know this has been posted in the past, but I want to check if there are some new answers before reaching out to our SE. There is a "&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes/panorama-plugin-for-sd-wan/sd-wan-plugin-300/known-issues-in-sd-wan-plugin-300" target="_blank"&gt;&lt;SPAN&gt;known issue&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;" where the zone mapping tab was removed from Panorama. The &lt;A title="SD-WAN - Add SD-WAN Branch or Hub Firewall" href="https://docs.paloaltonetworks.com/sd-wan/administration/enable-sd-wan-with-auto-vpn/add-sd-wan-branch-or-hub-firewall" target="_self"&gt;current documentation&lt;/A&gt; still mentions the need to map the pre-defined zones to existing zones when adding the device to SD-WAN or via CSV. The known issue states:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir="ltr"&gt;&lt;SPAN&gt;PLUG-13152&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;The SD-WAN plugin creates predefined zones automatically that does not require any user configuration. Hence, we have removed the following predefined zones tabs from the SD-WAN plugin web interface:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;* Zone Internet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone to Hub&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone to Branch&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone Internal&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;This issue is addressed in SD-WAN plugin 2.2.5 and 3.0.5&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;The documentation states, "If you have pre-existing zones for your Palo Alto Networks&lt;SUP class="ph sup"&gt;®&lt;/SUP&gt;&amp;nbsp;firewalls, you will be mapping them to the predefined zones used in&amp;nbsp;&lt;SPAN class="ph"&gt;SD-WAN&lt;/SPAN&gt;." and later goes into detail on how to map the zones.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;I imagine you then have to replace your existing zones with the pre-defined ones, no? Either that or create rules that allow communication between your existing zones and the pre-defined zones. The "does not require any user configuration" bit makes it sound like it "just works" but that does not seem to be the case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;What is the appropriate solution? Do we need to rename all of the relevant zones?&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Relevant Versions:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Panorama: 11.2.4-h1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;SD-WAN Plugin: sd_wan-3.3.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Firewalls: 11.1.2-h3 (mostly)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 May 2025 15:52:28 GMT</pubDate>
    <dc:creator>VRT-JH</dc:creator>
    <dc:date>2025-05-01T15:52:28Z</dc:date>
    <item>
      <title>Panorama SD-WAN Zone Mapping? No longer needed or no longer available?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-sd-wan-zone-mapping-no-longer-needed-or-no-longer/m-p/1227876#M2858</link>
      <description>&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;I know this has been posted in the past, but I want to check if there are some new answers before reaching out to our SE. There is a "&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes/panorama-plugin-for-sd-wan/sd-wan-plugin-300/known-issues-in-sd-wan-plugin-300" target="_blank"&gt;&lt;SPAN&gt;known issue&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;" where the zone mapping tab was removed from Panorama. The &lt;A title="SD-WAN - Add SD-WAN Branch or Hub Firewall" href="https://docs.paloaltonetworks.com/sd-wan/administration/enable-sd-wan-with-auto-vpn/add-sd-wan-branch-or-hub-firewall" target="_self"&gt;current documentation&lt;/A&gt; still mentions the need to map the pre-defined zones to existing zones when adding the device to SD-WAN or via CSV. The known issue states:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir="ltr"&gt;&lt;SPAN&gt;PLUG-13152&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;The SD-WAN plugin creates predefined zones automatically that does not require any user configuration. Hence, we have removed the following predefined zones tabs from the SD-WAN plugin web interface:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;* Zone Internet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone to Hub&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone to Branch&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* Zone Internal&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;This issue is addressed in SD-WAN plugin 2.2.5 and 3.0.5&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;The documentation states, "If you have pre-existing zones for your Palo Alto Networks&lt;SUP class="ph sup"&gt;®&lt;/SUP&gt;&amp;nbsp;firewalls, you will be mapping them to the predefined zones used in&amp;nbsp;&lt;SPAN class="ph"&gt;SD-WAN&lt;/SPAN&gt;." and later goes into detail on how to map the zones.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;I imagine you then have to replace your existing zones with the pre-defined ones, no? Either that or create rules that allow communication between your existing zones and the pre-defined zones. The "does not require any user configuration" bit makes it sound like it "just works" but that does not seem to be the case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;What is the appropriate solution? Do we need to rename all of the relevant zones?&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Relevant Versions:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Panorama: 11.2.4-h1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;SD-WAN Plugin: sd_wan-3.3.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Firewalls: 11.1.2-h3 (mostly)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 15:52:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-sd-wan-zone-mapping-no-longer-needed-or-no-longer/m-p/1227876#M2858</guid>
      <dc:creator>VRT-JH</dc:creator>
      <dc:date>2025-05-01T15:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama SD-WAN Zone Mapping? No longer needed or no longer available?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-sd-wan-zone-mapping-no-longer-needed-or-no-longer/m-p/1235223#M2949</link>
      <description>&lt;P&gt;I ended up finding out that plugin versions &amp;gt;2.2.4 or &amp;gt;3.0.4 force you to use the pre-defined zones. To make this work, I created policies such as "trust to zone-internal", "zone-internal to trust", "zone-to-branch to trust" and "trust to zone-to-branch". The alternative would be to replace your VPN/trust zones with the pre-defined ones, like changing your "trust" zone to "zone-internal", for example. Kind of annoying, but is what it is.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 16:34:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-sd-wan-zone-mapping-no-longer-needed-or-no-longer/m-p/1235223#M2949</guid>
      <dc:creator>VRT-JH</dc:creator>
      <dc:date>2025-08-01T16:34:08Z</dc:date>
    </item>
  </channel>
</rss>

