Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4878 Views
  • 0 replies
  • 0 Likes

Can you monitor default routes with BGP Conditional advertisement

Good Day I would like to configure BGP conditional advertisement to advertise a public network when the primary default route is not present. I have heard conflicting reports as to whether or not you can monitor the default routes using conditional advertisement. We are using Panorama 10.2.5 thanks in advance Regards

Amanda_L by L0 Member
  • 1099 Views
  • 0 replies
  • 0 Likes

URL Category Shareware/Freeware

Hello, I'm not sure this is were to ask this but my question is this: One of the Palo's on my network labled the "chromewebstore" in the URL category as shareware/freeware and was blocking the site. After 4 hours, it stopped blocking it and changed the category. Is there a reason for this or where would i look to find out possibly why. Tha...

Resolved! Push to Devices failed

Hello,We're using Panorama for the first time and I have a config that I want to push to a PA440. The device state is connected in Panorama and device certificate is valid. In "Shared Policy Commit State" I have a "commit failed" saying:. Validation Error:. rulebase -> pbf -> rules -> default-via-tunnel -> from -> zone 'trust-l3...

Resolved! Frequently changing IP for a FQDN

FQDN : "dc.applicationinsights.azure.com" The IP of the above Azure FQDN changes rapidly, sometimes even within a second. I was requesting my Palo Alto Firewall team to add this FQDN to the allowed policies so that my deployed application can communicate with the Azure AppInsights and send the logs. The observation is that even after adding the...

Aggregate memory utilization in Panorama

Hi, we have Panorama M-200, Our Snmp monitoring system recently began to alert us about the 85% high aggregate memory utilization in Panorama. now the question is , who the memory utilization is calculated in Panorama the show system resource command show the follow details. fw> show system resources top - 12:17:48 up 272 days, 21:30, ...

Scheduled backup export

Hi there, I have a scheduled backup job running every night, which exports my Panorama config to a backup server, it is running for over a year now without any problem. Yesterday I went over the config, changed the time and permitted the config. This morning I saw that the backup failed due to missing ECDSA SSH key. Failed exporting config...

Netzer by L3 Networker
  • 26654 Views
  • 40 replies
  • 1 Likes

Resolved! Panorama Commit issue 10.1.4-H4 after upgrade from 10.1.3

Hi guys, I have a Panorama- 10.1.4-H4 (upgraded from 10.1.3) on AWS and two other firewalls both at 10.0.9 on AWS. After upgrading, Panorama, I cannot just commit. Throws an error saying plugins unexpected here (for schema verification failed-reverted the config and when trying to commit after that gives the plugin error) I see below differe...

paragkarki143_0-1650938630275.png
paragkarki143_1-1650938630280.png
paragkarki143_2-1650938630293.png
paragkarki143_3-1650938630268.png
Pras by L4 Transporter
  • 9222 Views
  • 11 replies
  • 0 Likes

Panorama after rebooting didn't come up

Hi, After rebooting panorama, it didn't come up , also we are not able to commit after making changes, the committ status will stuck at 99%. Also we need to add more controls to Panorama. We need to do it immediately , Can we get one engineer to call immediately , support portal is down and this has to be case. Please share us Zoom link

IPSEC AND INTERNET TRAFFICE DISTRUTION

Dear Team, IPSEC AND INTERNET TRAFFICE DISTRUTION We have added 1 more ISP at our side and the same has been configured on the firewall, means now we have 2 ISP configured, we shall consider the OLD ISP as 1st ISP and NEW ISP as 2nd ISP. Presently we have configured GLOBAL PROTECT,IPSEC TRAFFIC and INTERENET BROWSING on 1st ISP. now our new re...

IS-Admin by L0 Member
  • 874 Views
  • 1 replies
  • 0 Likes

Palo Alto Panorama XML/REST API Permissions 10.2 vs previous versions

recently upgraded to 10.2, previously API permissions for the rest API and the XML api have been grouped together. But since upgrading to 10.2, we see these permissions are separated: I only want the permissions applied that were previously required for Logging when the XML/REST API permissions were grouped together. Since upgrading all ...

MicrosoftTeams-image (39) (1)[8].png
MicrosoftTeams-image (40) (1)[9].jpeg
MicrosoftTeams-image (41) (1)[47].png

Options for viewing Firewalls with Overrides in place

I recently ran across Panorama managed firewalls that have overrides in place for HA configurations. This must have occurred during deployment and were never removed before they went into production. Is there any way to view local firewall overrides from Panorama? Just trying to find a more efficient method than manually checking each firewal...

Query firewall configuration from Panorama using the REST API

Is there a way to proxy API query over Panorama to a managed firewall using the REST API? This is possible in the XML API using something similar, however I am now building an application using the REST and it will not be ideal, if mixed with the XML API: "https://<panorama>/api/?type=op&cmd=<request><system><softwar...

batd2 by L4 Transporter
  • 1151 Views
  • 0 replies
  • 0 Likes

Validation error while pushing config in panorama

Previously, we had perform upgrade activity on the PA-5220 from version 9.1.14-h1 to version 10.1.11. After few days we try to make some changes and push from panorama. Then we encounter this error(kindly refer the attached image): deviceconfig->system->update-schedule->wildfire->recurring->sync-to-peer unexpected here devicecon...

After removal firewall from Panorama it cannot register anymore to other Panorama instances

I had a small POC with SD-WAN on PA-410 units and Panorama in management mode. Once it was done, configuration was deleted, and it acted just as a regular firewall, so I have decided later to remove it at all from Panorama. Just as a regular step removed IP, disabled policy and objects and device and network templates. Now as I need to test some...

MarcinJ by L1 Bithead
  • 2475 Views
  • 2 replies
  • 0 Likes

Resolved! Late update URL Filtering on Panorama GUI

Any solution of URL Filtering version on GUI not updating to last update. On Panorama GUI, URL Filtering version about 30-60 minutes late. Im using Panorama 10.1.6 and the Palo Alto is 10.1.6-h6 Thank you  Regards, Rival

panorama url filtering not update.png
rivalk by L0 Member
  • 1940 Views
  • 1 replies
  • 0 Likes
  • 847 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors