<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewalls accessing Panorama: best practice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/70489#M40525</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking for a best practice when deploying Panorama accross multiple sites that do not really have any interconnections (and have quite a few overlapping subnets).&lt;/P&gt;
&lt;P&gt;From what I understand, the firewalls themselves initiate the connection towards the Panorama instance (VM appliance in this case). The VM instance has &lt;STRONG&gt;one&lt;/STRONG&gt; ethernet link.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question would be, which of these options would be considered the safest/most reliable way?&lt;/P&gt;
&lt;P&gt;- Destination NAT the Panorama instance on a public routeable IP, ensure the management interface from each firewall has a path to it over port 3978 (possibly with a 0.5m patch cord from the management port to an internal port &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;- Create a site to site VPN to the location where the Panorama resides: from each firewall, specifically for Panorama&lt;/P&gt;
&lt;P&gt;- Some other solution I haven't thought of yet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To give you an idea, we're talking roughly 35&amp;nbsp;devices (mainly 3020's and a few 5050-5060's), all configured in HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, do the Panorama timers (Receive/send Timeout for Connection to Device, Retry Count for SSL Send to Device,...) &lt;STRONG&gt;need&lt;/STRONG&gt; to match between firewalls&amp;amp;panorama?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2016 12:31:31 GMT</pubDate>
    <dc:creator>Arne-VDH</dc:creator>
    <dc:date>2016-01-07T12:31:31Z</dc:date>
    <item>
      <title>Firewalls accessing Panorama: best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/70489#M40525</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking for a best practice when deploying Panorama accross multiple sites that do not really have any interconnections (and have quite a few overlapping subnets).&lt;/P&gt;
&lt;P&gt;From what I understand, the firewalls themselves initiate the connection towards the Panorama instance (VM appliance in this case). The VM instance has &lt;STRONG&gt;one&lt;/STRONG&gt; ethernet link.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question would be, which of these options would be considered the safest/most reliable way?&lt;/P&gt;
&lt;P&gt;- Destination NAT the Panorama instance on a public routeable IP, ensure the management interface from each firewall has a path to it over port 3978 (possibly with a 0.5m patch cord from the management port to an internal port &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;- Create a site to site VPN to the location where the Panorama resides: from each firewall, specifically for Panorama&lt;/P&gt;
&lt;P&gt;- Some other solution I haven't thought of yet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To give you an idea, we're talking roughly 35&amp;nbsp;devices (mainly 3020's and a few 5050-5060's), all configured in HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, do the Panorama timers (Receive/send Timeout for Connection to Device, Retry Count for SSL Send to Device,...) &lt;STRONG&gt;need&lt;/STRONG&gt; to match between firewalls&amp;amp;panorama?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 12:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/70489#M40525</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2016-01-07T12:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firewalls accessing Panorama: best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/70880#M40606</link>
      <description>&lt;P&gt;A service route can be used to change the interface used to connect to panorama to any of your dataplane interfaces instead of the management interface:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2028i760EAA2E3B729772/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2016-01-14_12-19-14.png" title="2016-01-14_12-19-14.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if possible I'd recommend using a site to site VPN to allow for more robust encryption (ipsec + ssl) if your connections are going to pass over an insecure/untrusted network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;not sure if the timers &lt;EM&gt;need&lt;/EM&gt; to be identical but it would certainly be recommended to prevent any cascading timer issues&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 11:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/70880#M40606</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-14T11:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firewalls accessing Panorama: best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/71336#M40753</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply, I hadn't found that button yet. I'll figure the rest from here, thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 10:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-accessing-panorama-best-practice/m-p/71336#M40753</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2016-01-21T10:41:15Z</dc:date>
    </item>
  </channel>
</rss>

