<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automation / self-service success stories or information? in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203312#M1607</link>
    <description>&lt;P&gt;Palo Alto Networks has released integrations with two of the main automation tools when it comes to managing NGFWs in the cloud (and on prem):&amp;nbsp; Ansible and Terraform.&amp;nbsp; Both work more or less the same:&amp;nbsp; you have some sort of config file that details the changes you want to make, then you run the config file.&amp;nbsp; Integration with Ansible is more mature and has more features right now, as the Terraform integration was just released a month ago.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ansible:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* &lt;A href="http://panwansible.readthedocs.io/en/latest/" target="_blank"&gt;http://panwansible.readthedocs.io/en/latest/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible&lt;/A&gt; (some good blog posts here)&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/ansible-pan" target="_blank"&gt;https://github.com/PaloAltoNetworks/ansible-pan&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terraform:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://www.terraform.io/docs/providers/panos/index.html" target="_blank"&gt;https://www.terraform.io/docs/providers/panos/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://github.com/terraform-providers/terraform-provider-panos" target="_blank"&gt;https://github.com/terraform-providers/terraform-provider-panos&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 16:39:03 GMT</pubDate>
    <dc:creator>gfreeman</dc:creator>
    <dc:date>2018-03-02T16:39:03Z</dc:date>
    <item>
      <title>Automation / self-service success stories or information?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203262#M1606</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work at a large company that has a hybrid workload split between AWS and our datacenters, with dedicated connectivity between AWS and on-prem resources. We use NGFW's on the datacenter end with a default-deny policy for everything. Our firewall change process includes a weekly change management meeting with a whole bunch of approvals, and change windows twice a week. This simply can't keep up with all of the new applications being deployed in AWS; especially since so many of the rule change requests are more or less identical, like allowing new services in AWS to access port 80 on a specific IP in our datacenter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if anyone has, or knows of, information they can point me to about how others have solved problems like this? I figured that this was the best category for such a question, but I can handle the actual code and API side of it fine. The thing I'm looking for help with are success stories from other companies that have done this, that I can use to help convince leadership and the change management folks that we can automate many typical firewall changes (or even make them self-service) the same way we do that for other infrastructure tasks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any input/advice/links/etc.&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203262#M1606</guid>
      <dc:creator>jantman</dc:creator>
      <dc:date>2018-03-02T13:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Automation / self-service success stories or information?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203312#M1607</link>
      <description>&lt;P&gt;Palo Alto Networks has released integrations with two of the main automation tools when it comes to managing NGFWs in the cloud (and on prem):&amp;nbsp; Ansible and Terraform.&amp;nbsp; Both work more or less the same:&amp;nbsp; you have some sort of config file that details the changes you want to make, then you run the config file.&amp;nbsp; Integration with Ansible is more mature and has more features right now, as the Terraform integration was just released a month ago.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ansible:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* &lt;A href="http://panwansible.readthedocs.io/en/latest/" target="_blank"&gt;http://panwansible.readthedocs.io/en/latest/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible&lt;/A&gt; (some good blog posts here)&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/ansible-pan" target="_blank"&gt;https://github.com/PaloAltoNetworks/ansible-pan&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terraform:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://www.terraform.io/docs/providers/panos/index.html" target="_blank"&gt;https://www.terraform.io/docs/providers/panos/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;*&amp;nbsp;&lt;A href="https://github.com/terraform-providers/terraform-provider-panos" target="_blank"&gt;https://github.com/terraform-providers/terraform-provider-panos&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203312#M1607</guid>
      <dc:creator>gfreeman</dc:creator>
      <dc:date>2018-03-02T16:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Automation / self-service success stories or information?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203317#M1608</link>
      <description>&lt;P&gt;gfreeman,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much, but I'm already aware of both of those. We're fine on the technical side - we're very comfortable with Terraform and somewhat with Ansible, and would be fine using pandevice as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem we're having is convincing people who are tied to our current change control process, and think that waiting 2-4 weeks for a firewall change is not only a good thing, but the only way to function. We're having a lot of people who are involved in the current process make arguments that essentially boil down to fear that "automation" will result in horrible instability or loss of security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main question is whether anyone has either public examples of success stories with automating (or maybe even provinding self-service) rule changes, or else can speak to test processes that they use for vetting changes before automation takes over, and how that's helped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/203317#M1608</guid>
      <dc:creator>jantman</dc:creator>
      <dc:date>2018-03-02T16:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Automation / self-service success stories or information?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/206066#M1624</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've worked with a number of global financial, manufacturing, and retail customers that have built entirely homegrown automation and orchestration&amp;nbsp;frameworks to meet the specific needs of their respective organizations.&amp;nbsp; Each one used API-based workflows to provision, configure, and orchestrate services and infrastructure including compute, storage, networking, and security.&amp;nbsp; In every case they've touted some pretty remarkable benefits such as cost savings, shortened&amp;nbsp;delivery timeframes, and a significant reduction in misconfigurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Bob-&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 19:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automation-self-service-success-stories-or-information/m-p/206066#M1624</guid>
      <dc:creator>rhagen</dc:creator>
      <dc:date>2018-03-16T19:55:24Z</dc:date>
    </item>
  </channel>
</rss>

