<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Panorama Active/Standby deployment - Read only access only to standby Panorama´s Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/560570#M113626</link>
    <description>&lt;P&gt;Hi there, thanks a lot for your answer!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Really appreciate your ideas! And yes, I really want to have them restricted to the standby Panorama server as we have a lot of admin users already, and don´t want all of them accessing the prod panorama as it´s affecting the overall performance of the platform.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 18:06:23 GMT</pubDate>
    <dc:creator>BondonI</dc:creator>
    <dc:date>2023-10-04T18:06:23Z</dc:date>
    <item>
      <title>HA Panorama Active/Standby deployment - Read only access only to standby Panorama´s Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/559920#M113545</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an environment with a lot of people wanting to get live traffic logs and policy rules for troubleshooting purposes, audit, etc., so we are thinking about to get all the read only admins connected only to the Standby web GUI and not to the active one and I´m not finding a way to get this done. We want to prevent this active panorama server connections to avoid resources overload on the active server do to many read only admins pushing traffic logs and policies at the same time, delaying the real administration tasks.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the standby is also getting all traffic logs and policy rules, we would like to give the read only admins access only to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does someone knows if there is a way to accomplish this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 18:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/559920#M113545</guid>
      <dc:creator>BondonI</dc:creator>
      <dc:date>2023-09-28T18:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: HA Panorama Active/Standby deployment - Read only access only to standby Panorama´s Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/560337#M113591</link>
      <description>&lt;P&gt;you could start simply by drafting a user policy for the admins, directing them to only connect to panorama A or B, depending on their role, and adding a banner to the logon page reminding the admin they are logging on to the 'readonly' or the 'admin' panorama and should mind if this is the right one for them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the accounts are all synchronized across both panoramas, so it's not possible to have an account only on one panorama.&lt;/P&gt;
&lt;P&gt;a few 'ideas'&lt;/P&gt;
&lt;P&gt;-you could limit the source addresses allowed to connect to each panorama, or set up a jump host with only one panorama bookmarked in a locked down browser&lt;/P&gt;
&lt;P&gt;-set the accounts to remote authentication via radius or tacacs+ and set a client IP (ip for panorama a or b) restriction policy on the authentication server (i.e. so a given username is only allowed to authenticate from the IP from panorama B)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;before you tackle the technical solutions, consider if there a real need to block these admins or do you simply want a better 'spread'&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 09:16:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/560337#M113591</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-10-03T09:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: HA Panorama Active/Standby deployment - Read only access only to standby Panorama´s Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/560570#M113626</link>
      <description>&lt;P&gt;Hi there, thanks a lot for your answer!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Really appreciate your ideas! And yes, I really want to have them restricted to the standby Panorama server as we have a lot of admin users already, and don´t want all of them accessing the prod panorama as it´s affecting the overall performance of the platform.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 18:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-panorama-active-standby-deployment-read-only-access-only-to/m-p/560570#M113626</guid>
      <dc:creator>BondonI</dc:creator>
      <dc:date>2023-10-04T18:06:23Z</dc:date>
    </item>
  </channel>
</rss>

