Add Additional Interfaces to Panorama VM in ESXI

Add Additional Interfaces to Panorama VM in ESXI

46817
Created On 09/25/18 20:40 PM - Last Modified 11/14/20 01:28 AM


Environment


  • Any Panorama VM in ESXI environment with PAN-OS version 8.1 and above. 
  • Panorama running in 'system-mode: panorama'.
  • Check the system mode using either of the following methods:
    1. From CLI, issue  '> show system info' command.
    2. From WebUI, check 'General Information' widget on the Dashboard.


Resolution


Add the new interface(s) to the VM in vCenter

  1. Right-click on the VM Panorama guest and select 'Edit Settings'.
edit settings.png
  1. In the settings window add a new network device and select the appropriate port group.
add network.png
  1. Click ok and wait until vCenter reports that reconfiguration of the virtual machine is complete.
  2. Reboot the Panorama device (can be done now, or at the end of the procedure). 

Configure the new interface(s) in Panorama

  1. Panorama needs to be configured as a local Log Collector. To configure a local log collector please refer to Set Up the Panorama Virtual Appliance with Local Log Collector
  2. Configure required settings for ethernet1/1. WebUI: Panorama >> Setup >> Interfaces
Note: Choose an IP address that is not in use. In this example 10.8.56.6 is used.
 
panorama interface.png

3. Click 'OK'

4. Commit to Panorama locally.
WebUI: Commit >> Commit to Panorama

5. Do a Collector Group Push. 
WebUI: Panorama Tab >> Commit >> Push to Devices >> Edit Selections >> Collector Groups tab (Choose the Collector Group of interest from the list) >> OK >> Push

6. Reboot the Panorama device if you didn't in previous steps.



Additional Information


  • The interfaces will show up in Panorama in the order that they were added to the VM in ESXi. For example, the second interface that was added to the VM, will be presented in Panorama as ethernet1/1. Subsequent interfaces will be presented as ethernet 1/2, ethernet 1/3, etc,
  • Choosing "Device Management and Device Log Collection" or "Collector Group Communication" will need a commit to Collector-Group after a local commit.
  • Enabling/Disabling services that are mentioned above will require a Commit to Collector-Group, otherwise the interface IP may not be recognized or the interface may not come up.
  • Enabling additional interfaces (e.g. ethernet1/1, ethernet1/2) in Panorama, will automatically create a local log collector, but not a Collector Group. 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClksCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language