<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install &amp;amp; upgrade Firewall new on client side in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260511#M73847</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I built it on a lab pa-200 I have on code 8.0.17 so it'll need at least 8.0.x before you can really apply it. Here are the rough steps and my email is oklier @ andraste . net . Its a work in progress so I appreciate any feedback. I left it as generic as possible so there is still specific config that needs to happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For manual config of MGMT interface via cli:&lt;/P&gt;&lt;P&gt;configure&lt;BR /&gt;set deviceconfig system ip-address &amp;lt;IP address&amp;gt; netmask &amp;lt;subnet mask&amp;gt; default-gateway &amp;lt;gateway&amp;gt;&lt;BR /&gt;set deviceconfig system dns-setting servers primary &amp;lt;IP of internal DNS server if no internal DNS server use 208.67.220.220 &amp;gt;&lt;BR /&gt;set deviceconfig system ntp-servers primary-ntp-server ntp-server-address &amp;lt;IP of NTP server or use us.pool.ntp.org&amp;gt;&lt;BR /&gt;commit&lt;/P&gt;&lt;P&gt;Time and DNS are required for the PAN to obtain its licening and updates!&lt;/P&gt;&lt;P&gt;MGMT interface is configured for DHCP in the template&lt;/P&gt;&lt;P&gt;assign IP to eth 1/1 and NAT&lt;BR /&gt;assing IP to internal eth 1/2&lt;BR /&gt;Verify default outbound route&lt;/P&gt;&lt;P&gt;Update dynamic updates&lt;BR /&gt;Code must be 8.0.0 or higher to take advantage of the template.&lt;/P&gt;&lt;P&gt;Disable the following if not used:&lt;/P&gt;&lt;P&gt;SIEM=1.0.0.0&lt;BR /&gt;email server profile 1.0.0.1&lt;BR /&gt;Netflow 10.0.0.2&lt;/P&gt;&lt;P&gt;Put the MGMT interface into the Management zone and make sure it has the proper IP/SM/GW along with DNS and NTP.&lt;/P&gt;&lt;P&gt;Other:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/8-0/data-center-best-practices/data-center-best-practices-checklist.html" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/8-0/data-center-best-practices/data-center-best-practices-checklist.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;configure&lt;BR /&gt;delete deviceconfig system ssh&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh ciphers mgmt aes256-ctr&lt;BR /&gt;set deviceconfig system ssh ciphers mgmt aes256-gcm&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh regenerate-hostkeys mgmt key-type RSA key-length 3072&lt;BR /&gt;set deviceconfig system ssh session-rekey mgmt interval 3600&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh mac mgmt hmac-sha2-256&lt;BR /&gt;commit&lt;BR /&gt;exit&lt;BR /&gt;set ssh service-restart mgmt&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 14:37:23 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-05-10T14:37:23Z</dc:date>
    <item>
      <title>How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260408#M73813</link>
      <description>&lt;P&gt;We had ordered the firewall and it's been delivered to client Now we want to configure and upgrade without distrubtring the current network what is the best way to do this or we had to bring it our side to configure and send back?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any document or client had to plug in separate network with the internet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 15:34:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260408#M73813</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2019-05-09T15:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260415#M73814</link>
      <description>&lt;P&gt;You have a couple of options if you want to do this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to hook a laptop up to the Management port, and gain access to the device and configure it without it "being on the network".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, You can perform some updates to it while "offline".. please refer to this article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFhCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFhCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or there are some other discussions around here talking about the same thing. here is one I found:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Any-step-to-install-all-kit-when-new-PA-box-is-offline/m-p/48764#M35911" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Any-step-to-install-all-kit-when-new-PA-box-is-offline/m-p/48764#M35911&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 16:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260415#M73814</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-05-09T16:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260433#M73818</link>
      <description>You can start off by connecting the management interface to the customer's laptop or managemeny network and prepping it for deployment&lt;BR /&gt;The default config is a vwire setup between ethernet1/1 and 1/2 wit 1/1 being the external (ISP) interface&lt;BR /&gt;The default security policy allows all outgoing traffic and blocks all inbound connections&lt;BR /&gt;&lt;BR /&gt;This config allows you to simply connect the firewall between the current firewall and the LAN, or directly behind the ISP router without much interruption&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Theres a couple of articles you may want to have the customer go through to get the firewal hooked up so you can manage it remotely &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS2CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS2CAK&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 09 May 2019 16:41:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260433#M73818</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-09T16:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260458#M73829</link>
      <description>&lt;P&gt;1. Do you have Panorama?&lt;/P&gt;&lt;P&gt;2. Is this running in an HA pair?&lt;/P&gt;&lt;P&gt;3. Is there any kind of VPN tunnel giving you access to their network?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 19:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260458#M73829</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-09T19:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260466#M73837</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you are interested, I have a template I created of a base config. Does stuff like set management to dhcp, setup dynamic updates and a few security policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let mek ow if you are interested.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 19:35:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260466#M73837</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-09T19:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260491#M73842</link>
      <description>&lt;P&gt;1. Do you have Panorama?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;No Panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Is this running in an HA pair?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;PA-220 so no HA Pair&lt;/P&gt;&lt;P&gt;3. Is there any kind of VPN tunnel giving you access to their network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Yes VPN tunnel will be created to give support to the client .&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 08:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260491#M73842</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2019-05-10T08:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260492#M73843</link>
      <description>&lt;P&gt;Sure. That would be great help. Can you email me the template ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 08:16:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260492#M73843</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2019-05-10T08:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260511#M73847</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I built it on a lab pa-200 I have on code 8.0.17 so it'll need at least 8.0.x before you can really apply it. Here are the rough steps and my email is oklier @ andraste . net . Its a work in progress so I appreciate any feedback. I left it as generic as possible so there is still specific config that needs to happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For manual config of MGMT interface via cli:&lt;/P&gt;&lt;P&gt;configure&lt;BR /&gt;set deviceconfig system ip-address &amp;lt;IP address&amp;gt; netmask &amp;lt;subnet mask&amp;gt; default-gateway &amp;lt;gateway&amp;gt;&lt;BR /&gt;set deviceconfig system dns-setting servers primary &amp;lt;IP of internal DNS server if no internal DNS server use 208.67.220.220 &amp;gt;&lt;BR /&gt;set deviceconfig system ntp-servers primary-ntp-server ntp-server-address &amp;lt;IP of NTP server or use us.pool.ntp.org&amp;gt;&lt;BR /&gt;commit&lt;/P&gt;&lt;P&gt;Time and DNS are required for the PAN to obtain its licening and updates!&lt;/P&gt;&lt;P&gt;MGMT interface is configured for DHCP in the template&lt;/P&gt;&lt;P&gt;assign IP to eth 1/1 and NAT&lt;BR /&gt;assing IP to internal eth 1/2&lt;BR /&gt;Verify default outbound route&lt;/P&gt;&lt;P&gt;Update dynamic updates&lt;BR /&gt;Code must be 8.0.0 or higher to take advantage of the template.&lt;/P&gt;&lt;P&gt;Disable the following if not used:&lt;/P&gt;&lt;P&gt;SIEM=1.0.0.0&lt;BR /&gt;email server profile 1.0.0.1&lt;BR /&gt;Netflow 10.0.0.2&lt;/P&gt;&lt;P&gt;Put the MGMT interface into the Management zone and make sure it has the proper IP/SM/GW along with DNS and NTP.&lt;/P&gt;&lt;P&gt;Other:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/8-0/data-center-best-practices/data-center-best-practices-checklist.html" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/8-0/data-center-best-practices/data-center-best-practices-checklist.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;configure&lt;BR /&gt;delete deviceconfig system ssh&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh ciphers mgmt aes256-ctr&lt;BR /&gt;set deviceconfig system ssh ciphers mgmt aes256-gcm&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh regenerate-hostkeys mgmt key-type RSA key-length 3072&lt;BR /&gt;set deviceconfig system ssh session-rekey mgmt interval 3600&lt;/P&gt;&lt;P&gt;set deviceconfig system ssh mac mgmt hmac-sha2-256&lt;BR /&gt;commit&lt;BR /&gt;exit&lt;BR /&gt;set ssh service-restart mgmt&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 14:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260511#M73847</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-10T14:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to install &amp; upgrade Firewall new on client side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260565#M73857</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I forgot that you can create your own with IronSkillet:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-with-IronSkillet-Best-Practices-Templates/ba-p/233175" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/Getting-Started-with-IronSkillet-Best-Practices-Templates/ba-p/233175&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would just say that the Team Cymru bogons dont work quite right. I think its a paid subscription?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 20:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-install-amp-upgrade-firewall-new-on-client-side/m-p/260565#M73857</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-10T20:18:52Z</dc:date>
    </item>
  </channel>
</rss>

