Anyone with exp in Firewall PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Anyone with exp in Firewall PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?

L4 Transporter

Anyone with exp in PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?

 

Hi Live PAN-community, how's it going ?

 

Does anyone have operational functional experience of pan-os sdwan ( firewall sdwan without panorama and without cloudgenix appliances ) deployments operating and running sites with two ISPs for IPSEC S2S VPN connections.

 

Today we have operating only pan-os sdwan for internet outbound, with 2 unified links, operating well, however with limitations but it works and good well.

 

Now thinking of moving to VPN S2S using pan-os sdwan scheme, anyone has experience of deployment in their environments ? if it operates correctly ? Points, tips, points to focus on, recommendations, headaches, etc. If you have had any unexpected problems, what has been your feedback, your experience operating between HQ to VPN S2S branches of at least 5, 10 or more pan-os sites between your PANW firewalls of branches against the HQ.

 

Please only people with sdwan exp, from their pan-os licensed firewalls who have real experience without using Panorama, where the deployment is not the best, but it is valid, functional, operable with the important limitations, of course, but functional.

 

Thank you for your kindness, kindness, your time and collaboration

 

Best Regards

High Sticker
2 REPLIES 2

L1 Bithead

I'm also curious. The docs don't list it anywhere as a pre-requisite but Panorama is referenced multiple times for managing the VPN clusters in the admin guide and really nothing on the firewalls themselves.

This page for Auto VPN / mesh states:

Enable SD-WAN with Auto VPN

 

Where Can I Use This?

NGFW

 

What Do I Need?

SD-WAN license

 

Then literally the first line says: Auto VPN enables you to create SD-WAN cluster to connect multiple LANs using the Panorama management server.

Loves routing, hates switching

Cyber Elite
Cyber Elite

Hi @DenovoChris and @Metgatz ,

 

Panorama is required for PAN-OS SD-WAN.  https://docs.paloaltonetworks.com/sd-wan/activation-and-onboarding/system-requirements-for-sd-wan

 

You could also use SCM.  https://docs.paloaltonetworks.com/strata-cloud-manager/getting-started/manage-configuration-ngfw-and...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 439 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!