<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managing single pair of VM firewall with and without Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203406#M59926</link>
    <description>&lt;P&gt;On the back of this, would it be possible to have panorama just push updates to the VM's while we can use the API's directly to the VM-300 to provision policies?&lt;/P&gt;</description>
    <pubDate>Sat, 03 Mar 2018 11:50:06 GMT</pubDate>
    <dc:creator>dave.fernandes</dc:creator>
    <dc:date>2018-03-03T11:50:06Z</dc:date>
    <item>
      <title>Managing single pair of VM firewall with and without Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203399#M59925</link>
      <description>&lt;P&gt;Hi Palo Alto Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to ask what are the pro's and cons of not using a Panorama for managing a single pair of VM-300 firewalls. From reading documentations etc, the main benefit of Panorama would only be if this was a distrbuted deployment managing 10's or 100's of firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If in this case it was only 2 VM's to be managed a Panorama would not serve any benefits from what I gather. But wanted to open up to the community to see if I will lose out on any features by not using the Panorama. We would like to use the API and code directly the VM-300 for provisioning policies etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any advice on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 11:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203399#M59925</guid>
      <dc:creator>dave.fernandes</dc:creator>
      <dc:date>2018-03-03T11:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Managing single pair of VM firewall with and without Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203406#M59926</link>
      <description>&lt;P&gt;On the back of this, would it be possible to have panorama just push updates to the VM's while we can use the API's directly to the VM-300 to provision policies?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 11:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203406#M59926</guid>
      <dc:creator>dave.fernandes</dc:creator>
      <dc:date>2018-03-03T11:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Managing single pair of VM firewall with and without Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203411#M59928</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24704"&gt;@dave.fernandes&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So one thing that you actually miss out on completely, although I've been campaigning for the requirement to be lifted, is the ability to utilize the logging service. The way that its constructed this service isn't functional without Panorama for the time being.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you're right in the assumption that utilizing Panorama for two firewalls would likely be overkill; but keep in mind that utilizing Panorama&amp;nbsp;&lt;EM&gt;at all&lt;/EM&gt; is something that is going to depend on the enviroment and such. I've managed an enviroment where we had upwards of 75 remote offices without utilizing Panorama as I could mimic the features I actually&amp;nbsp;&lt;EM&gt;needed&lt;/EM&gt; with the API. Not something that I would really recommend most people do, but it worked well for what I needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the other features available in Panorama that I actually care anything about I've simply duplicated with the API or setup an expect script and stored the output. Panorama for me is mostly a conviencance thing; you can duplicate almost all of it's features but is the time you spend doing so actually worth it over simply purchasing Panorama?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 21:47:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203411#M59928</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-03T21:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Managing single pair of VM firewall with and without Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203422#M59934</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;thanks for your information. What we had in mind was to have an overarching Panorama just for centrally monitoring all the VM-300 pairs and to provision content updates etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But majority of the policy provisioning would be done by the users locally on the VM-300.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this scenario, hopefully we get a single pane of glass of seeing what traffic is passing through the VM-300 while allowing users to manage their own policies locally.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Mar 2018 11:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/managing-single-pair-of-vm-firewall-with-and-without-panorama/m-p/203422#M59934</guid>
      <dc:creator>dave.fernandes</dc:creator>
      <dc:date>2018-03-04T11:01:12Z</dc:date>
    </item>
  </channel>
</rss>

