Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5046 Views
  • 0 replies
  • 0 Likes

Prisma Access 3.2 Known Issue CYR-28288

One of our customers was affected by the Prisma Access 3.2 Known Issue CYR-28288 CYR-28288 --> When performing commits or upgrades, a Prisma Access deployment requires internet connectivity; without internet connectivity, certificate validation will fail and commits are not possible. https://docs.paloaltonetworks.com/prisma/prisma-access...

Firewall has the IPSec tunnel but Panorama don't. How to fix?

Hi Guys, We have one of the IPSec tunnel missing on Panorama but it is configured on individual Firewalls (HA pair). The tunnel is up and running. We don't want any downtime on VPN tunnel. Can I simply add missing IPSec tunnel to Panorama and do just " Commit to Panorama"? Or is there something else needs to be done?

MINKU2 by L0 Member
  • 2310 Views
  • 1 replies
  • 0 Likes

XML API not working

I am facing an issue with the Palo Alto API where I am unable to exclude 'policy-and-objects' and 'shared-object' in partial changes. When I try to use the following XML structure in my API request: https://firewall/api?type=op&cmd=<show><config><list><changes><partial><policy-and-objects>excluded</po...

Schedule Firmware Update via Panorama or Schedule NGFW Reboot via Panorama

Title says it all. Need to patch 16 NGFWs in geographically disparate locations. I see that I can schedule config changes and exports I see that I can push firmware in 3 ways: download, download+install, download+install+reboot. I do not see any way to schedule this.I also don't see that I can schedule a reboot alone were I to perform firmwa...

Resolved! How to use "name-of-threatid" for threat types like "spyware"

Hello, I want to filter Panorama Monitoring results based on the field "name-of-threatid" for threat types like "Spyware". But when I click on of the results, I get a filter like this: "... and ( name-of-threatid eq 'Grayware:ZZZZZ.com' )" but when I want to apply this filter I get this error: It seems this field only accepts numbers. Do you ha...

Arman_Zaheri_0-1705929625551.png

How to set the rule order using CLI on Panorama

Hi, when configuring rules using CLI on Panorama, I used the following syntax, however, if I have multiple rules, how do I configure the order of different rules? set device-group DGName pre-rulebase security rules RuleName to xxxxxx set device-group DGName pre-rulebase security rules RuleName from xxxxxx

nowayout by L1 Bithead
  • 2658 Views
  • 1 replies
  • 0 Likes

Need help in setting up a basic lab

I am a complete beginner new to Palo Alto. I have a lab setup with Palo Alto management IP 192.168.1.51 and a windows server 2022 machine with IP 192.168.1.57. I want to create a rule on Palo Alto firewall to stop the internet access to the server. The default gateway for the internet is 192.168.1.1 Tell me how to do that because when I tried ...

How to delete tags in Panorama from CLI ?

Hi all I have an issue and i need your help. I need to delete tags like "FQDN" from Panorama from the CLI. When i issue this command below i have an error message: command : delete shared tag FQDN Response : Object doesn't exis What did i miss?

Why do all my Panorama security rules have the same "Modified" date and time?

In the NGFW, under Policies > Security, there is a "Modified" field.It usually shows the date and time the Security Rule was modified.I don't see any modifications to the group objects in the security rule that would allow duplicate use.However, the same date and time "Modified" appears in the unmodified panoramic security rule. Any idea why ...

스크린샷 2024-03-22 03.36.20.png

Seconday Passive ES Health Red master_not_discovered_exception

I have two Panorama servers 11.0.1-h2 in HA. Both are in Panorama mode and have 3x Disks (2TB each). Logs are really slow to view on the Active-Primary and never load on the Secondary. When diagnosing I came across this error on the secondary: admin@Panorama2(secondary-passive)> show log-collector-es-cluster health { "error" : { "root_...

Unable to commit Panorama stack template

Hi All, When pushing Panorama stack template configuration to devices i encounter error message as per below. Verified no Masterkey was in use. Please advise. Operation Commit All Status Completed Result Failed Details Validation Error: deviceconfig -> system -> snmp-setting -> access-setting -> version ->v3 ->user -&gt...

Resolved! Panorama Management OS Compatibility

Hey all, I saw many discussions about managing Palo Alto FW with lower version than Panorama. But I wonder if my PA450 FW is at 10.1.12 and my Panorama is at 10.1.10 ,would Panorama will have any issue to manage the FW?

Can't RDP from Mac to Windows Jump Server

Dear Community Members, I'm facing a strange issue. I use 2 machines related to my work. One is a Windows Laptop and another one is a Macbook. We have a server, which acts as a Jump Box. We use Global Protect VPN for connecting to that JumpServer. Now the issues is that, i can access this server after connecting to GP from my Windows Lap...

  • 726 Posts
  • 47 Subscriptions
Top Liked Authors
Labels