<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use Panorama to deploy standardized remote sites? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36431#M26782</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking for a way to use Panorama to deploy about 100 remote sites.&lt;/P&gt;&lt;P&gt;Let's say that we have the following scenario:&lt;/P&gt;&lt;P&gt;Site 01 has local subnet 192.168.101.0/24&lt;/P&gt;&lt;P&gt;Site 02 has local subnet 192.168.102.0/24&lt;/P&gt;&lt;P&gt;Etc through site 99 has local subnet 192.168.199.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On each site, .1 is the firewall, .3 through .5 are onsite resources, .6-10 are switches, .11-19 are printers, and .20 through .200 are for DHCP Clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security policies are different, of course, for allowing network access to switches than to printers and endusers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way (other than scripting, which is where I'm at now) to use Panorama to set up each of these remote sites, including DHCP scopes for each site?&lt;/P&gt;&lt;P&gt;Or is there a more "Palo Alto Networks" way of doing this than my scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current scenario looks like this:&lt;/P&gt;&lt;P&gt;Script to set up a template specific to the site, with settings for DHCP Scope, Management interface, ethernet interfaces, etc.&lt;/P&gt;&lt;P&gt;Script to set up a device group specific to the site, with settings for local address objects, address groups, etc.&lt;/P&gt;&lt;P&gt;Use the parent device group to have the common security and nat policies that refer to the addresses defined in the site specific device group&lt;/P&gt;&lt;P&gt;Use the Template stack to set common network / device settings, though that doesn't seem relevant to the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Aug 2015 00:05:04 GMT</pubDate>
    <dc:creator>justinbrown</dc:creator>
    <dc:date>2015-08-04T00:05:04Z</dc:date>
    <item>
      <title>How to use Panorama to deploy standardized remote sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36431#M26782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking for a way to use Panorama to deploy about 100 remote sites.&lt;/P&gt;&lt;P&gt;Let's say that we have the following scenario:&lt;/P&gt;&lt;P&gt;Site 01 has local subnet 192.168.101.0/24&lt;/P&gt;&lt;P&gt;Site 02 has local subnet 192.168.102.0/24&lt;/P&gt;&lt;P&gt;Etc through site 99 has local subnet 192.168.199.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On each site, .1 is the firewall, .3 through .5 are onsite resources, .6-10 are switches, .11-19 are printers, and .20 through .200 are for DHCP Clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security policies are different, of course, for allowing network access to switches than to printers and endusers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way (other than scripting, which is where I'm at now) to use Panorama to set up each of these remote sites, including DHCP scopes for each site?&lt;/P&gt;&lt;P&gt;Or is there a more "Palo Alto Networks" way of doing this than my scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current scenario looks like this:&lt;/P&gt;&lt;P&gt;Script to set up a template specific to the site, with settings for DHCP Scope, Management interface, ethernet interfaces, etc.&lt;/P&gt;&lt;P&gt;Script to set up a device group specific to the site, with settings for local address objects, address groups, etc.&lt;/P&gt;&lt;P&gt;Use the parent device group to have the common security and nat policies that refer to the addresses defined in the site specific device group&lt;/P&gt;&lt;P&gt;Use the Template stack to set common network / device settings, though that doesn't seem relevant to the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2015 00:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36431#M26782</guid>
      <dc:creator>justinbrown</dc:creator>
      <dc:date>2015-08-04T00:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Panorama to deploy standardized remote sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36432#M26783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like you have the concepts down.&amp;nbsp; Panorama is primarily about setting up the common settings that can be pushed to multiple devices via the groups.&amp;nbsp; The general assumption is that specific site only settings are on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With version 7 and the template stack you could use a specific template as you suggest for each site.&amp;nbsp; But I think that is going to make your Panorama interface very busy with a very long pull menu on 100 sites.&amp;nbsp; Personally, I would stick with keeping the specific settings local and just changing the context to local in Panorama for maintenance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are also correct that scripting will be your best bet to pre-load the configuration itself either on the device or via your Panorama specific device template.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2015 10:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36432#M26783</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-08-04T10:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Panorama to deploy standardized remote sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36433#M26784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Thank you for helping me validate my plan.&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Is there any way to run the script through Panorama (I couldn't find the command-line equivalent of switching to a local context)?&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Assuming there isn't, and that I don't go with device specific Templates (I'll probably populate 30-40 to see how well filters mitigate the interface issues of having lots of templates), my updated plan ends with:&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Bring up the new device, &lt;SPAN style="font-size: 10pt;"&gt;Import a config with the relevant bits, and use the load partial config from that file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;The load partial is to avoid problems with Putty buffer overruns in the scripting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333330154419px;"&gt;Assuming no one jumps in with a better plan, I'll give you the kudos for an answer in a couple days.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2015 19:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36433#M26784</guid>
      <dc:creator>justinbrown</dc:creator>
      <dc:date>2015-08-04T19:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Panorama to deploy standardized remote sites?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36434#M26785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct that you cannot run CLI for the devices from Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the load partial scripting, I've generally imported the xml config file into the device or panorama as a file on the setup &amp;gt; operations menu.&amp;nbsp; then you can reference the file name in your load partial commands so you don't have the buffer issue.&amp;nbsp; The technique is outlined in the Panorama import documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5332"&gt;Panorama Device Migration&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Aug 2015 22:14:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-use-panorama-to-deploy-standardized-remote-sites/m-p/36434#M26785</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-08-04T22:14:47Z</dc:date>
    </item>
  </channel>
</rss>

