<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama deployment in Ansible in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/panorama-deployment-in-ansible/m-p/288576#M2033</link>
    <description>&lt;P&gt;You can disable certificate checking globally for Python by editing&amp;nbsp;/etc/python/cert-verification.cfg and set&amp;nbsp;verify=disable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not very secure, so we should look at enabling this on runtime per playbook.This way we can disable checks, install certs from our favourite CA, and then turn cert-checks on again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2019 14:10:12 GMT</pubDate>
    <dc:creator>OysteinK</dc:creator>
    <dc:date>2019-09-16T14:10:12Z</dc:date>
    <item>
      <title>Panorama deployment in Ansible</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/panorama-deployment-in-ansible/m-p/288069#M2031</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Im working with a customer using PANW/NSX that wants to automate Panorama/firewall deployment with ansible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far I have found a few stumbling blocks:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The ESXi OVA file defines the VM with 4vCPUs and 8GB RAM. This wont work for Panorama mode, only legacy mode&lt;/LI&gt;&lt;LI&gt;The Panorama ESX ova does not have DHCP enabled by default on the MGMT interface, unlike the firewall ova, and the Azure/AWS. images.&lt;/LI&gt;&lt;LI&gt;The various Panos modules for Ansible do not support the "validate_certs: false" option common to most Ansible modules.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For nr 1, I'll fix it by creating a custom .ovf file.&lt;/P&gt;&lt;P&gt;If anyone has any suggestions to solve nr 2 and 3, please reply.&lt;/P&gt;&lt;P&gt;I'll keep posting as I figure out how to go forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 10:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/panorama-deployment-in-ansible/m-p/288069#M2031</guid>
      <dc:creator>OysteinK</dc:creator>
      <dc:date>2019-09-12T10:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama deployment in Ansible</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/panorama-deployment-in-ansible/m-p/288576#M2033</link>
      <description>&lt;P&gt;You can disable certificate checking globally for Python by editing&amp;nbsp;/etc/python/cert-verification.cfg and set&amp;nbsp;verify=disable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not very secure, so we should look at enabling this on runtime per playbook.This way we can disable checks, install certs from our favourite CA, and then turn cert-checks on again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 14:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/panorama-deployment-in-ansible/m-p/288576#M2033</guid>
      <dc:creator>OysteinK</dc:creator>
      <dc:date>2019-09-16T14:10:12Z</dc:date>
    </item>
  </channel>
</rss>

