Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5070 Views
  • 0 replies
  • 0 Likes

ZTP configuration at remote sites

We have some new PA-440's are are trying to work through the ZTP process. We have ZTP configured, and the devices are registered. We now see them as connected to our Panorama server, but we are unsure of the next step. We can't seem to make some changes to do the devices as they are still in ZTP mode, but the documentation to turn ZTP off...

RHuss1 by L1 Bithead
  • 2609 Views
  • 1 replies
  • 0 Likes

Resolved! Adding log forwarding profiles and profile match lists and actions with pan-os-python API

Anyone have any examples of adding log forwarding profiles with match lists and actions using the pan-os-python API? Here's a sample that has me stuck: from panos.panorama import Panorama, DeviceGroupfrom panos.objects import LogForwardingProfile,LogForwardingProfileMatchList,LogForwardingProfileMatchListActionpano = Panorama(hostname='xxx',...

GM001 by L1 Bithead
  • 2191 Views
  • 1 replies
  • 0 Likes

Resolved! Add or remove application in a security rule

Hello.......curl -k -X GET "https://10.10.10.10/api/?key=LUFRPT16R......................Mg==&type=config&action=set&xpath=/config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='GP']/pre-rulebase/security/rules/entry[@name='Policy-1']&element=<source><member>any</member></source><...

ssovee by L2 Linker
  • 5444 Views
  • 6 replies
  • 0 Likes

Resolved! Push to Devices failed

Hello,We're using Panorama for the first time and I have a config that I want to push to a PA440. The device state is connected in Panorama and device certificate is valid. In "Shared Policy Commit State" I have a "commit failed" saying:. Validation Error:. rulebase -> pbf -> rules -> default-via-tunnel -> from -> zone 'trust-l3...

Resolved! Frequently changing IP for a FQDN

FQDN : "dc.applicationinsights.azure.com" The IP of the above Azure FQDN changes rapidly, sometimes even within a second. I was requesting my Palo Alto Firewall team to add this FQDN to the allowed policies so that my deployed application can communicate with the Azure AppInsights and send the logs. The observation is that even after adding the...

Aggregate memory utilization in Panorama

Hi, we have Panorama M-200, Our Snmp monitoring system recently began to alert us about the 85% high aggregate memory utilization in Panorama. now the question is , who the memory utilization is calculated in Panorama the show system resource command show the follow details. fw> show system resources top - 12:17:48 up 272 days, 21:30, ...

Scheduled backup export

Hi there, I have a scheduled backup job running every night, which exports my Panorama config to a backup server, it is running for over a year now without any problem. Yesterday I went over the config, changed the time and permitted the config. This morning I saw that the backup failed due to missing ECDSA SSH key. Failed exporting config...

Netzer by L3 Networker
  • 28549 Views
  • 40 replies
  • 1 Likes

Resolved! Panorama Commit issue 10.1.4-H4 after upgrade from 10.1.3

Hi guys, I have a Panorama- 10.1.4-H4 (upgraded from 10.1.3) on AWS and two other firewalls both at 10.0.9 on AWS. After upgrading, Panorama, I cannot just commit. Throws an error saying plugins unexpected here (for schema verification failed-reverted the config and when trying to commit after that gives the plugin error) I see below differe...

paragkarki143_0-1650938630275.png
paragkarki143_1-1650938630280.png
paragkarki143_2-1650938630293.png
paragkarki143_3-1650938630268.png
Pras by L4 Transporter
  • 9850 Views
  • 11 replies
  • 0 Likes

Panorama after rebooting didn't come up

Hi, After rebooting panorama, it didn't come up , also we are not able to commit after making changes, the committ status will stuck at 99%. Also we need to add more controls to Panorama. We need to do it immediately , Can we get one engineer to call immediately , support portal is down and this has to be case. Please share us Zoom link

IPSEC AND INTERNET TRAFFICE DISTRUTION

Dear Team, IPSEC AND INTERNET TRAFFICE DISTRUTION We have added 1 more ISP at our side and the same has been configured on the firewall, means now we have 2 ISP configured, we shall consider the OLD ISP as 1st ISP and NEW ISP as 2nd ISP. Presently we have configured GLOBAL PROTECT,IPSEC TRAFFIC and INTERENET BROWSING on 1st ISP. now our new re...

IS-Admin by L0 Member
  • 946 Views
  • 1 replies
  • 0 Likes

Palo Alto Panorama XML/REST API Permissions 10.2 vs previous versions

recently upgraded to 10.2, previously API permissions for the rest API and the XML api have been grouped together. But since upgrading to 10.2, we see these permissions are separated: I only want the permissions applied that were previously required for Logging when the XML/REST API permissions were grouped together. Since upgrading all ...

MicrosoftTeams-image (39) (1)[8].png
MicrosoftTeams-image (40) (1)[9].jpeg
MicrosoftTeams-image (41) (1)[47].png

Options for viewing Firewalls with Overrides in place

I recently ran across Panorama managed firewalls that have overrides in place for HA configurations. This must have occurred during deployment and were never removed before they went into production. Is there any way to view local firewall overrides from Panorama? Just trying to find a more efficient method than manually checking each firewal...

Validation error while pushing config in panorama

Previously, we had perform upgrade activity on the PA-5220 from version 9.1.14-h1 to version 10.1.11. After few days we try to make some changes and push from panorama. Then we encounter this error(kindly refer the attached image): deviceconfig->system->update-schedule->wildfire->recurring->sync-to-peer unexpected here devicecon...

  • 728 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels