<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pushing dynamic updates from Panorama to firewalls or download direct to firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/596468#M118660</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41709"&gt;@clewis1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;where you have a small amount of firewalls or you have firewalls that have no internet access I would utilize the push from Panorama, but you can quickly end up in a situation where the Panorama is constantly queuing commits made by admins for rules/config changes due to high frequency update schedules like Wildfire for example.&lt;/P&gt;</description>
    <pubDate>Sat, 31 Aug 2024 11:19:55 GMT</pubDate>
    <dc:creator>laurence64</dc:creator>
    <dc:date>2024-08-31T11:19:55Z</dc:date>
    <item>
      <title>Pushing dynamic updates from Panorama to firewalls or download direct to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/590725#M117659</link>
      <description>&lt;P&gt;Looking for advice on best practice regarding dynamic updates (AV, IPS, WF) when managing firewalls from a Panorama. Currently we are download and pushing these dynamic updates from Panorama to about 15 firewalls but will be managing more firewalls from Panorama in the future. We have discovered some of these dynamic update jobs becoming hung and the push to the firewall never completes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Possible we should consider configuring each firewall to download from the cloud instead of our on prem Panorama?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 17:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/590725#M117659</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2024-06-28T17:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing dynamic updates from Panorama to firewalls or download direct to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/590940#M117706</link>
      <description>&lt;P&gt;Here is a screenshot of the failed attempts which were pushed from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clewis1_0-1719931638710.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60632i9BDED44FCAFC9CCF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clewis1_0-1719931638710.png" alt="clewis1_0-1719931638710.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 14:49:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/590940#M117706</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2024-07-02T14:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing dynamic updates from Panorama to firewalls or download direct to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/595302#M118469</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41709"&gt;@clewis1&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;personally, I think especially for larger amount of Firewalls it is better to have each Firewall retrieve dynamic updates directly instead of deploying it through Panorama. I would limit the Panorama deployed updates only to Firewalls that do not have internet access to retrieve updates directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the error you shared in screen shot this looks like a bug documented in this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XhEKCA0" target="_self"&gt;Commit error on Panorama "Too many (30) deploy jobs pending"&lt;/A&gt;. If you upgrade to version where this defect is addressed, you will likely be able to continue to use Panorama deployed updates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 03:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/595302#M118469</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-08-20T03:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing dynamic updates from Panorama to firewalls or download direct to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/595352#M118483</link>
      <description>&lt;P&gt;Thank you for the reply. I was able to resolve the issue a while back. I don't recall the exact solution, but I didn't upgrade PAN OS on either of the Panorama or Firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I recall correctly, I was able resolve by updating the schedule and ensuring I had all the firewalls added. I no longer see the errors and all the firewalls are receiving the updates correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clewis1_0-1724152619886.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61610iBC67AD3CB9400F64/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clewis1_0-1724152619886.png" alt="clewis1_0-1724152619886.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do agree with your idea of having the firewalls get their updates directly from the internet if they have a path out. I will be exploring it as an option once internet is available at each of our sites.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 11:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/595352#M118483</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2024-08-20T11:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing dynamic updates from Panorama to firewalls or download direct to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/596468#M118660</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41709"&gt;@clewis1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;where you have a small amount of firewalls or you have firewalls that have no internet access I would utilize the push from Panorama, but you can quickly end up in a situation where the Panorama is constantly queuing commits made by admins for rules/config changes due to high frequency update schedules like Wildfire for example.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2024 11:19:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pushing-dynamic-updates-from-panorama-to-firewalls-or-download/m-p/596468#M118660</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2024-08-31T11:19:55Z</dc:date>
    </item>
  </channel>
</rss>

