<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW in Palo IP changed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/417008#M93493</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the new management IPs of the firewalls, is it possible to reach the panorama? Is the new network configuration correctly configured and these firewalls are able to communicate to the default gateway and other networks? Is an ACL on panorama configured that restrics access to only specific IPs or is a firewall in front of the panorama that prevents the communication from the new IPs?&lt;/P&gt;&lt;P&gt;The communication is always coming from the firewall to panorama so you need to make sure that this way of communication is possible.&lt;/P&gt;</description>
    <pubDate>Sat, 03 Jul 2021 19:08:11 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2021-07-03T19:08:11Z</dc:date>
    <item>
      <title>FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/416503#M93432</link>
      <description>&lt;P&gt;Hello -&lt;/P&gt;&lt;P&gt;I have an HA pair of palo's that were added to Panorama. The management IP for each of those palo's has changed and are now showing in a disconnected state. How can I correct this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 13:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/416503#M93432</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2021-07-01T13:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/417008#M93493</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the new management IPs of the firewalls, is it possible to reach the panorama? Is the new network configuration correctly configured and these firewalls are able to communicate to the default gateway and other networks? Is an ACL on panorama configured that restrics access to only specific IPs or is a firewall in front of the panorama that prevents the communication from the new IPs?&lt;/P&gt;&lt;P&gt;The communication is always coming from the firewall to panorama so you need to make sure that this way of communication is possible.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 19:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/417008#M93493</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-03T19:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/417041#M93504</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Two points to remember when troubleshooting panorama connectivity:&lt;/P&gt;&lt;P&gt;- Aways the FW is the initiator of the connection. Which means FW is always the source of the traffic and panorama is just waiting for someone to call it&lt;/P&gt;&lt;P&gt;- Panorama is tracking firewalls by serial numbers, not by management IP. Which means panorama will accept any connection request as long as the FW serial number is added to panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So by default Panorama will accept/establish TCP connection with any source IP, but can reject the connection if the provided FW S/N is not in the list of managed devices. You can control this by configuring "Permitted IPs" under the panorama management interface. That way Panorama will respond only IP from the allow list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If everying is setup properly if FW is connected to Panorama, but its mgmt ip is change. The new IP will be detect and changed automatically. So it looks more like the new mgmt ip is not reaching the Panorama:&lt;/P&gt;&lt;P&gt;- Try to ping panorama from fw using mgmt interface&lt;/P&gt;&lt;P&gt;- Check if you have configured permitted ip panorama interface&lt;/P&gt;&lt;P&gt;- Last resort make a packet capture on panorama and FW interface and confirm that you have bi-directional traffic&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:39:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/417041#M93504</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-07-04T07:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418581#M93686</link>
      <description>&lt;P&gt;Great info to have!&amp;nbsp; I read your post and figured it out.&amp;nbsp; I set the object for the Firewalls within Pano to IP (so pano saw the old IP and not the new).&amp;nbsp; I changed it to FQDN and whiz-bang, it connected.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 16:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418581#M93686</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2021-07-12T16:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418588#M93687</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt;&amp;nbsp;Can you please tell me where did you use that object? Would be great if you share a screenshot(after masking any sensitive details)&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 17:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418588#M93687</guid>
      <dc:creator>a-techie</dc:creator>
      <dc:date>2021-07-12T17:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: FW in Palo IP changed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418606#M93690</link>
      <description>&lt;P&gt;Pretty simple really, we have Addresses and Address Groups under the Objects tab in Panorama.&amp;nbsp; You create the Address object and then add it to a Address Groups object.&amp;nbsp; We then apply that Address Group to the Rules needed for them to talk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I, stupidly, did was when I created the Address for the managed firewall I used Type IP Netmask&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 799px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34983iA2E49A07BF03F627/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I should have done and did correct was use Type FQDN&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 802px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34984iCFD3864F3D6496D7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This way if the IP changes, I don't have to do anything. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 18:25:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fw-in-palo-ip-changed/m-p/418606#M93690</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2021-07-12T18:25:48Z</dc:date>
    </item>
  </channel>
</rss>

