- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-28-2024 10:01 AM
Looking for advice on best practice regarding dynamic updates (AV, IPS, WF) when managing firewalls from a Panorama. Currently we are download and pushing these dynamic updates from Panorama to about 15 firewalls but will be managing more firewalls from Panorama in the future. We have discovered some of these dynamic update jobs becoming hung and the push to the firewall never completes.
Possible we should consider configuring each firewall to download from the cloud instead of our on prem Panorama?
08-19-2024 08:05 PM
Hello @clewis1
personally, I think especially for larger amount of Firewalls it is better to have each Firewall retrieve dynamic updates directly instead of deploying it through Panorama. I would limit the Panorama deployed updates only to Firewalls that do not have internet access to retrieve updates directly.
Regarding the error you shared in screen shot this looks like a bug documented in this KB: Commit error on Panorama "Too many (30) deploy jobs pending". If you upgrade to version where this defect is addressed, you will likely be able to continue to use Panorama deployed updates.
Kind Regards
Pavel
08-20-2024 04:20 AM
Thank you for the reply. I was able to resolve the issue a while back. I don't recall the exact solution, but I didn't upgrade PAN OS on either of the Panorama or Firewalls.
If I recall correctly, I was able resolve by updating the schedule and ensuring I had all the firewalls added. I no longer see the errors and all the firewalls are receiving the updates correctly.
I do agree with your idea of having the firewalls get their updates directly from the internet if they have a path out. I will be exploring it as an option once internet is available at each of our sites.
08-31-2024 04:19 AM
Hi @clewis1
I agree with @PavelK where you have a small amount of firewalls or you have firewalls that have no internet access I would utilize the push from Panorama, but you can quickly end up in a situation where the Panorama is constantly queuing commits made by admins for rules/config changes due to high frequency update schedules like Wildfire for example.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!