<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One configuration for multiple sites in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191626#M57692</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79072"&gt;@ddocksta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would take a look at&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;'s excellent&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Getting-Started-Setting-Up-Your-Firewall-video/ta-p/68103" target="_blank"&gt;Getting Started&lt;/A&gt;&amp;nbsp;guide. Once you have more specific questions it gets a little easier to help you along the way, but you shouldn't run into any issues getting this to function correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can look at the actual PAN-OS 8.0 Getting Started documentation as well&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/getting-started" target="_blank"&gt;Admin Guide - Getting Started&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 21:54:37 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-12-13T21:54:37Z</dc:date>
    <item>
      <title>One configuration for multiple sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191584#M57688</link>
      <description>&lt;P&gt;We are trying to deploy the PA 220&amp;nbsp;at multiple sites.&amp;nbsp; The firewall will be facing an outside internet connection protecting a production server.&amp;nbsp; Objective 1 is to create vpn accounts for specified users and machines (using MAC addresses) to control access,&amp;nbsp; &amp;nbsp;Objective 2 is to block ALL other traffic (incoming/outgoing)&amp;nbsp; &amp;nbsp;Objective 3 Create a config that can be download to the firewall which will be updated at our home office.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just recieved my PA 220 to begin testing.&amp;nbsp; Any assistance, advice, references to docs.&amp;nbsp; etc.&amp;nbsp; will be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 18:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191584#M57688</guid>
      <dc:creator>ddocksta</dc:creator>
      <dc:date>2017-12-13T18:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: One configuration for multiple sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191626#M57692</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79072"&gt;@ddocksta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would take a look at&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;'s excellent&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Getting-Started-Setting-Up-Your-Firewall-video/ta-p/68103" target="_blank"&gt;Getting Started&lt;/A&gt;&amp;nbsp;guide. Once you have more specific questions it gets a little easier to help you along the way, but you shouldn't run into any issues getting this to function correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can look at the actual PAN-OS 8.0 Getting Started documentation as well&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/getting-started" target="_blank"&gt;Admin Guide - Getting Started&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 21:54:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191626#M57692</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-13T21:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: One configuration for multiple sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191894#M57730</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This is an interesting scenario. I did this with Cisco equipment back in the day and worked out kind of well. Of course I had to preconfigure the equipment inhouse prior to shipping and we had 3g (yes that old) connections with static IP's for easy prebuilt VPN tunnels. While I think most of the config can be a 'template', there&amp;nbsp;are going to be some custom configs for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. External IP(s), you'll need to know what they are unless you are getting DHCP from the ISP? A layer 3 interface can get its IP by DHCP.&lt;/P&gt;&lt;P&gt;2. Tunnel all traffic back through your data cetners main connections. This way you can NAT the servers there if they need to be access from the public internet.&lt;/P&gt;&lt;P&gt;3. I would create a rule on the 220's that allows the following: VPN conections from your data center IP's only. Also for the purpose of remote configuration, allow admin access to the device from your data center IP's only.&lt;/P&gt;&lt;P&gt;All of this followed by a DENY ALL rule which preceeds the default allow rules that are preconfigured so that your systems are safe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While some of my suggestions seem a bit old fashion, they do prevent a lot of headaches from the configuration and maintenance side of things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 16:53:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-configuration-for-multiple-sites/m-p/191894#M57730</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-12-15T16:53:25Z</dc:date>
    </item>
  </channel>
</rss>

