Connect pan-vm firewalls to on premise Panorama?

Reply
Highlighted
L1 Bithead

Connect pan-vm firewalls to on premise Panorama?

We have virtual Palo firewalls in AWS VPC behind the AWS internet gateway. We are looking to register them to the on-prem panorama.

Tags (3)
Highlighted
L4 Transporter

Hello @tejasmapuskar 

You need to make your panorama available via the Internet, filter access very tight. Now you need to grant the public IPs of your firewalls management interface to have access to panorama.

The firewalls on cloud need to be told to communicate with the public IP of panorama.

Highlighted
L1 Bithead

Hi, 

 

I am going to give it a try. Which ports does panorama need to communicate with the firewalls apart from TCP- 3978 and TCP 28443 ?

Highlighted
Cyber Elite

@tejasmapuskar 

That's the only two ports you should need from the VM series to your Panorama instance. 

Highlighted
L1 Bithead

Can we make use of the 'Public IP Address' option under Management interface of Panorama to allocate a public IP and create a Nat rule to translate the internal private IP to the public?

note- we have firewalls managed on our internal network too. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!