forward logs to panorama without managing or on-boarding firewalls in panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

forward logs to panorama without managing or on-boarding firewalls in panorama

L0 Member

I am looking for the best solution on forwarding taffic and audit logs to a Panorama without registering the firewalls in panorama. The goal is that Panorama should not manage those firewalls as they are in lab environment but would collect logs only. Please let me know if you have done something similar.

1 accepted solution

Accepted Solutions

L7 Applicator

I had used Panorama this way initially on a deploy.  Adding the firewalls with centralized logs and keeping all configuration local without using groups or templates.

 

Panorama also gives you the interface to access the local GUI directly from Panorama so you don't have to leave to make the local changes either.

 

We then migrated slowly a firewall at a time to using groups and templates.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

You don't have to manage firewall from Panorama.

Add firewall to Panorama and configure log profile to send logs to Panorama but you can keep on adding rules and configuration changes directly on the firewall.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L7 Applicator

I had used Panorama this way initially on a deploy.  Adding the firewalls with centralized logs and keeping all configuration local without using groups or templates.

 

Panorama also gives you the interface to access the local GUI directly from Panorama so you don't have to leave to make the local changes either.

 

We then migrated slowly a firewall at a time to using groups and templates.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1 accepted solution
  • 1689 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!