<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change IP MGT Firewall conect to Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/1204477#M122960</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14452"&gt;@Ricky_Mayenburg&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for sharing!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The behavior with SSL on port 3978 you described is documented in this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI94CAE" target="_self"&gt;Why is traffic on port 3978 Identified as SSL application instead of Panorama application?&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 02:49:55 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2025-01-21T02:49:55Z</dc:date>
    <item>
      <title>Change IP MGT Firewall conect to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/483644#M104373</link>
      <description>&lt;P&gt;Hello, good afternoon everyone, thank you very much for your time, help and support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have the following scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1.- Panorama managing 6 firewalls&lt;BR /&gt;2.- Panorama version 9.1.6&lt;BR /&gt;3.- Firewall HA 9.1.6 (5250 - This will be used for configuration migration )&amp;nbsp;&lt;BR /&gt;4.-Other HA 7.1.15 ( 5060 )&lt;BR /&gt;5.- Firewall HA 9.1.13-h3 (5250)&lt;BR /&gt;6.- All the previously named devices are being reported and managed (template and device group) in Panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is what it intends to do, the 5060 firewalls will be taken offline and a HA 5250 will be used instead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The HA 5250 (with its corresponding Template and personalized Device group) is connected to Panorama with its respective MGT IP and also the HA 5060 units with their respective MGT IP (also with their corresponding Template and personalized Device group).&lt;/P&gt;&lt;P&gt;So what is going to be done, what is intended is to clone the profiles (device group and templates) from the 5060 and use it to migrate the configuration to the HA 5250. After this, it is necessary to use the same MGT IPs that have or had the 5060 in the 5250.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I&lt;/EM&gt;&lt;EM&gt;t is there with the details already delivered, after the change of IP and obviously the PA-5060 firewalls, they will be disconnected and eliminated from Panorama, the question is if it will be necessary to remove and re-add the 5250 firewalls after the IP change or will the Panorama recognize the IP change and only focus on the Serial Number-SN and the IP change will be transparent?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much in advance for the support, I remain tense, best regards&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 20:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/483644#M104373</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-04-28T20:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Change IP MGT Firewall conect to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/483655#M104374</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;based on my experience only serial number matters. The IP address change will be transparent. Good luck with your migration!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 21:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/483655#M104374</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-04-28T21:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Change IP MGT Firewall conect to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/484000#M104400</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; correctly pointed out - Panorama is using device serial number to identify managed device, the IP address is irrelevant.&lt;/P&gt;&lt;P&gt;It worth mentioning the following:&lt;/P&gt;&lt;P&gt;- Communication between Panorama and managed device is &lt;STRONG&gt;always &lt;/STRONG&gt;&lt;STRONG&gt;initiated&lt;/STRONG&gt; by the firewall.&lt;/P&gt;&lt;P&gt;- So Panorama will accept any source IP address to connect to it (which can be restricted by allowed address list under panorama managed interface config). Note that it will accept and establish the TCP connection, after that FW will try to "authenticate" providing its serial number, at this point Panorama will decide if it will continue to communicate with the FW or close the session - based on the S/N number that you have added to the Panorama.&lt;/P&gt;&lt;P&gt;- For that reason if firewall changes its IP address (either admin manually change statically assigned IP, or just FW uses DHCP for mgmt), Panorama will still be able to authenticate the firewall and associate it with device-group and template stack. As bonus it will update the information under Managed Devices -&amp;gt; Summary showing the current management ip of the firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it may take few minutes (I would say less than 2mins), for Panorama to list the firewalls as connected after you change the IP addresses.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2022 20:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/484000#M104400</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-04-30T20:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Change IP MGT Firewall conect to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/1204461#M122959</link>
      <description>&lt;P&gt;If panorama doesn't pick up the device after the MGMT ip change, it's worth checking the monitor logs to see if the firewall is able to communicate with Panorama with application SSL on port 3978.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have to add a rule to allow the traffic on this port and then Panorama saw the firewall right away. because I was only allowing SSL on the default port.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 23:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/1204461#M122959</guid>
      <dc:creator>Ricky_Mayenburg</dc:creator>
      <dc:date>2025-01-20T23:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change IP MGT Firewall conect to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/1204477#M122960</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14452"&gt;@Ricky_Mayenburg&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for sharing!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The behavior with SSL on port 3978 you described is documented in this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI94CAE" target="_self"&gt;Why is traffic on port 3978 Identified as SSL application instead of Panorama application?&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 02:49:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/change-ip-mgt-firewall-conect-to-panorama/m-p/1204477#M122960</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2025-01-21T02:49:55Z</dc:date>
    </item>
  </channel>
</rss>

