Management of a multi-VSYS firewall from Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Management of a multi-VSYS firewall from Panorama

Hello friends,

 

I have been tasked to deploy a multi-VSYS PA and to manage it from Panorama, honestly this is the first time that I do this so I'm reaching out to you in order to guide me in the most siple way to achieve this. The way I'm planning this is:

 

1. Enable multi-VSYS funcionality (I guess that by default VSYS1 should be created automatically).

2. Setup the HA pair.

3. Setup communication to Panorama, this will be a site to site VPN so I will have to do this in the VSYS1.

 

Now in Panorama:

 

1. Register the Serial Numbers in Managed Devices.

2. Create a new Template.

3. Create a new Stack (including the new one, and another that we use for Standard parameters).

 

I guess that this step above is the most critical one, I'm with the idea that we should be able to manage the 4 VSYS from this single template, but please correct me if I'm wrong.

 

4. Then, in Panorama implement the required config, create the 3 new VSYS, etc. and push the config to the device.

5. Then, per my understanding at this point I should be able to see the Virtual Systems as available devices in the Device Groups section.

 

This step above is also a critical one, as I'm with the idea that I should create a single Device Group for each VSYS and in order to achieve that, I should be able to see the Virtual Systems as available devices in Device Groups section? Please correct me if I'm wrong.

 

Any feedback will be appreciated.

 

Kind Regards,

 

 

1 REPLY 1

L4 Transporter

@AlexandroDelAngel All of your assumptions seem correct...

  • 7724 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!