Starting with Palo Alto Networks - What I wish I had known...

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Starting with Palo Alto Networks - What I wish I had known...

L4 Transporter

Beginnings are not always perfect.  Whether you started your Palo Alto Networks journey years ago or just recently, tell us what you learned early on that you wish you had known before. 


If there was one thing, or maybe more, Live Community users would love to hear about it.  Share your stories, your tips to help other users along the way.


Read a tip you like, make sure to like it or let them know by commenting!  


The most popular and helpful stories will get you a cool new Live Community t-shirt!


live t-shirt.jpg


Looking forward to reading all the great stories!




Cyber Elite
Cyber Elite

The benefit of using the forums unless I actually need emergency support through TAC. A lot of the frontline support folks love to simply get your configuration and 'verify it for issues' when there really isn't a need for it; heck simply opening up a ticket for the weird URLs I was seeing on my botnet report the first line support was adimit that the predefined report was in some way misconfigured on my end. 

In the past I've worked through issues soley by myself because I loathed contacting support and having to do the same troubleshooting steps I had already done multiple times, or hearing how I should try to restart in the middle of the day to fix the issue. In the forums it's by far more likely that you'll either get told the solution or be told to restart a specific process, instead of restarting the whole data/management plane. 

L1 Bithead

I've been administrating a Palo Alto Firewall for 3 years now and think it's a really good tool, it friendly and faily easy to configure and manage. It has helped to improve our traffic controll and solve connection issues. I do encourage other administrators to use it!

L0 Member

i've been working with Cisco ASA before start using Palo Alto more than 4 years ago. since the first beginning i've appreciated the very friendly web interface and the huge amount of feature which are very helpful to manage our network and security.

especially indicated for corporate and sysadmins focused on the websecurity, you have a lot of automated and manual tools to prevent, detect properly attempts of breaches and vulnerabilities.

growing and growing version after version, i can't wait to see and test the 8 version.

L0 Member

If I knew then what I know now.....


1. Use Panorama for (almost) everything. Building all objects, profiles, zones, and policies in Panorama has numerous manageability/scalability benefits. Other than network interfaces, virtual routers, and IPSec tunnels, build everything else in Panorama and push it to the firewalls.

2. Use nested device groups in Panorama to create a hierarchy for shared security policies. This allows a single rule, created once, to be applied to multiple firewalls. 

3. Template grouping should be based on device model do to zone limitations. Device grouping should be based on function or purpose.

4. Using tags, and corresponding colors, in your security rules helps with visual grouping the rules, and can also help with searching and filtering.

L2 Linker

I'm about 2-months in, and I'm still looking for what I need to know.


What I most want is the "How to think Palo Alto" guide - the biggest picture of how the parts fit together, and the minute details of what little "other-guy" process or method doesn't work here.


I'll publish it myself once I think I have it 😉

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!