<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virtual Panorama for Log viewing only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172081#M54347</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Yes, this would actually be a pretty simple solution. But theres two little problems (besides the one that there are important information missing in my initial post)&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;This "one" firewall unfortunately is a active/passive HA pair&lt;/LI&gt;&lt;LI&gt;Its not only to view current data. We have to store logs for 180 days. And these logs need to be available&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Thu, 17 Aug 2017 16:13:15 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-17T16:13:15Z</dc:date>
    <item>
      <title>Virtual Panorama for Log viewing only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172056#M54343</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope someone already did something like that to answer my question &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a virtual Panorama on PAN-OS 8 with a local log collector. On this panorama we manage differdnt firewalls and also store the logs of these firewalls. This panorama is in a secure zone where we ONLY allow acces for firewall administrators.&lt;/P&gt;&lt;P&gt;So far so good. Now we have a customer who got a visit from PaloAlto itself, where he was shown PaloAlto products - including Panorama. Result of this visit was, the customer now asks me if he could have access to Panorama to view specially the ACC tab of the logs of ONE firewallcluster. And unfortunately not only current data. We are storing these logs for 180 days. So he'd likes to have access to this data, for reporting reasons.&lt;/P&gt;&lt;P&gt;Our own policy now doed not allow to give the customer this access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my idea now was the following: we build a second panorama only for this one firewall of this customer. This second panorama will not be used for managing this firewall because on the first panorama we forward some specific logs to the second panorama, where the customer can have access to view these logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this even possible with PAN-OS 8 and the local log collectors?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input or better ideas is appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 16:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172056#M54343</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-17T16:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Panorama for Log viewing only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172066#M54344</link>
      <description>&lt;P&gt;If firewall is at client site why don't you just allow direct login into firewall with read only access to spcecific tabs?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 15:24:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172066#M54344</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-17T15:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Panorama for Log viewing only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172081#M54347</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Yes, this would actually be a pretty simple solution. But theres two little problems (besides the one that there are important information missing in my initial post)&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;This "one" firewall unfortunately is a active/passive HA pair&lt;/LI&gt;&lt;LI&gt;Its not only to view current data. We have to store logs for 180 days. And these logs need to be available&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 17 Aug 2017 16:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-panorama-for-log-viewing-only/m-p/172081#M54347</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-17T16:13:15Z</dc:date>
    </item>
  </channel>
</rss>

