<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/437090#M413</link>
    <description>&lt;P&gt;Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hey guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it's a valid solution but I need your advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama - M500&lt;/P&gt;
&lt;P&gt;FW - PA3220&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario 1: Panorama (MGT Interface)&amp;nbsp; &amp;lt;---------- (MGT Subnet) ----------&amp;gt; (MGT Interface) Firewall&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; can push the config from Panorama to FW&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; everything works, no issues.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario 2: Panorama (Eth1/1 )&amp;nbsp; &amp;lt;---------- (Routed network) ----------&amp;gt; (Loop0) Firewall&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cannot push the config from Panorama to FW,&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; even though they can ping to each other.&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; can't see the firewall in Managed Device either.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Panorama eth 1/1 -settings&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ping,&lt;/LI&gt;
&lt;LI&gt;SSH,&lt;/LI&gt;
&lt;LI&gt;Device Deployment,&lt;/LI&gt;
&lt;LI&gt;Device Management and Device Log Collection,&lt;/LI&gt;
&lt;LI&gt;Device Deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Could someone advise what's missing in my config or this is not possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Followed this post, looks like similar config worked for someone but not sure whether MGT interface was used or something else.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/panorama-device-management-via-loopback/m-p/341717#M85711" target="_blank"&gt;Solved: LIVEcommunity - Re: Panorama device management via loopback - LIVEcommunity - 341279 &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 06:42:47 GMT</pubDate>
    <dc:creator>sanjaypatel08</dc:creator>
    <dc:date>2021-09-28T06:42:47Z</dc:date>
    <item>
      <title>Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/437090#M413</link>
      <description>&lt;P&gt;Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hey guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it's a valid solution but I need your advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama - M500&lt;/P&gt;
&lt;P&gt;FW - PA3220&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario 1: Panorama (MGT Interface)&amp;nbsp; &amp;lt;---------- (MGT Subnet) ----------&amp;gt; (MGT Interface) Firewall&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; can push the config from Panorama to FW&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; everything works, no issues.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario 2: Panorama (Eth1/1 )&amp;nbsp; &amp;lt;---------- (Routed network) ----------&amp;gt; (Loop0) Firewall&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cannot push the config from Panorama to FW,&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; even though they can ping to each other.&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; can't see the firewall in Managed Device either.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Panorama eth 1/1 -settings&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ping,&lt;/LI&gt;
&lt;LI&gt;SSH,&lt;/LI&gt;
&lt;LI&gt;Device Deployment,&lt;/LI&gt;
&lt;LI&gt;Device Management and Device Log Collection,&lt;/LI&gt;
&lt;LI&gt;Device Deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Could someone advise what's missing in my config or this is not possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Followed this post, looks like similar config worked for someone but not sure whether MGT interface was used or something else.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/panorama-device-management-via-loopback/m-p/341717#M85711" target="_blank"&gt;Solved: LIVEcommunity - Re: Panorama device management via loopback - LIVEcommunity - 341279 &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 06:42:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/437090#M413</guid>
      <dc:creator>sanjaypatel08</dc:creator>
      <dc:date>2021-09-28T06:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/437223#M414</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179500"&gt;@sanjaypatel08&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a few Firewalls that are managed by Panorama and not using management interface. This scenario is possible, you will only have to adjust Service Route Configuration to use Loopback interface instead of management interface. I can confirm that in Panorama the Firewall's IP address will be still displayed with management interface IP address even though it is not connected at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Panorama side, I do not think you can completely eliminate Management interface. Based on documentation it states that: "When assigning Panorama services to various interfaces, keep in mind that only the MGT interface allows administrative access to Panorama for configuration and monitoring tasks."&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/m-series-appliance-interfaces.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/m-series-appliance-interfaces.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For all other functions such as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device Management and Device Log Collection&lt;BR /&gt;Collector Group Communication&lt;BR /&gt;Device Deployment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use different interface than management. This should be functional in your case with Eth 1/1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you make sure that you completed this step:&amp;nbsp;Changes made to interfaces other than management (MGT) require a Collector Group commit to be effective. Below is a sample:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1632866582077.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36674iD12884D3D84AAED3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1632866582077.png" alt="PavelK_0-1632866582077.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Since you mentioned that you can't see Firewall in Panorama under Device Management, this is fundamental issue and without seeing Firewall connected in&amp;nbsp;Device Management, you will not be able to perform further tasks with pushing of configuration. Could you verify that on Firewall side you are pointing to the correct Panorama's IP address, Service Routes are in place and S/N registered in Panorama is corresponding?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 22:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/437223#M414</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-28T22:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/438987#M415</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; for your help, I followed the steps and it did work for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had to make two changes:&lt;/P&gt;
&lt;P&gt;1. The service route update from firewall&lt;/P&gt;
&lt;P&gt;2. After seeing the traffic from firewall to Panorama eth1/1 interface, firewall was dropping it so I had to create another rule allow that flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it worked well, with no issues &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you again!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sanjay&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 21:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-eth1-1-to-firewall-loop0-or-vlan-interface/m-p/438987#M415</guid>
      <dc:creator>sanjaypatel08</dc:creator>
      <dc:date>2021-10-05T21:38:13Z</dc:date>
    </item>
  </channel>
</rss>

