Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4906 Views
  • 0 replies
  • 0 Likes

Resolved! Adding log forwarding profiles and profile match lists and actions with pan-os-python API

Anyone have any examples of adding log forwarding profiles with match lists and actions using the pan-os-python API? Here's a sample that has me stuck: from panos.panorama import Panorama, DeviceGroupfrom panos.objects import LogForwardingProfile,LogForwardingProfileMatchList,LogForwardingProfileMatchListActionpano = Panorama(hostname='xxx',...

GM001 by L1 Bithead
  • 2054 Views
  • 1 replies
  • 0 Likes

Resolved! Add or remove application in a security rule

Hello.......curl -k -X GET "https://10.10.10.10/api/?key=LUFRPT16R......................Mg==&type=config&action=set&xpath=/config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='GP']/pre-rulebase/security/rules/entry[@name='Policy-1']&element=<source><member>any</member></source><...

ssovee by L2 Linker
  • 4972 Views
  • 6 replies
  • 0 Likes

Panorama API Rule HitCount S/N

Hi Folks, I need to run this api call against Panorama, to query security policies hit-count from a device-group. As we Have HA enabled, it is displaying the same security rule twice as a results for the Active and Passive Firewall. I tried to add to the call <device-vsys>/devices/entry[@name='SN-ACTIVE-FW']</device-vsys>, but it...

SaaS report hangs

My Panorama has often struggled with report generation. For a report covering more than a week, the report will simply fail. However, since updating to 10.2, the predefined SaaS reports will not complete. They just sit at 0% until cancelled. Panorama resources (cpu, memory, disk space) are fine. Is there anything i should check?

Can you monitor default routes with BGP Conditional advertisement

Good Day I would like to configure BGP conditional advertisement to advertise a public network when the primary default route is not present. I have heard conflicting reports as to whether or not you can monitor the default routes using conditional advertisement. We are using Panorama 10.2.5 thanks in advance Regards

Amanda_L by L0 Member
  • 1143 Views
  • 0 replies
  • 0 Likes

URL Category Shareware/Freeware

Hello, I'm not sure this is were to ask this but my question is this: One of the Palo's on my network labled the "chromewebstore" in the URL category as shareware/freeware and was blocking the site. After 4 hours, it stopped blocking it and changed the category. Is there a reason for this or where would i look to find out possibly why. Tha...

Resolved! Push to Devices failed

Hello,We're using Panorama for the first time and I have a config that I want to push to a PA440. The device state is connected in Panorama and device certificate is valid. In "Shared Policy Commit State" I have a "commit failed" saying:. Validation Error:. rulebase -> pbf -> rules -> default-via-tunnel -> from -> zone 'trust-l3...

Resolved! Frequently changing IP for a FQDN

FQDN : "dc.applicationinsights.azure.com" The IP of the above Azure FQDN changes rapidly, sometimes even within a second. I was requesting my Palo Alto Firewall team to add this FQDN to the allowed policies so that my deployed application can communicate with the Azure AppInsights and send the logs. The observation is that even after adding the...

Aggregate memory utilization in Panorama

Hi, we have Panorama M-200, Our Snmp monitoring system recently began to alert us about the 85% high aggregate memory utilization in Panorama. now the question is , who the memory utilization is calculated in Panorama the show system resource command show the follow details. fw> show system resources top - 12:17:48 up 272 days, 21:30, ...

Scheduled backup export

Hi there, I have a scheduled backup job running every night, which exports my Panorama config to a backup server, it is running for over a year now without any problem. Yesterday I went over the config, changed the time and permitted the config. This morning I saw that the backup failed due to missing ECDSA SSH key. Failed exporting config...

Netzer by L3 Networker
  • 27259 Views
  • 40 replies
  • 1 Likes

Resolved! Panorama Commit issue 10.1.4-H4 after upgrade from 10.1.3

Hi guys, I have a Panorama- 10.1.4-H4 (upgraded from 10.1.3) on AWS and two other firewalls both at 10.0.9 on AWS. After upgrading, Panorama, I cannot just commit. Throws an error saying plugins unexpected here (for schema verification failed-reverted the config and when trying to commit after that gives the plugin error) I see below differe...

paragkarki143_0-1650938630275.png
paragkarki143_1-1650938630280.png
paragkarki143_2-1650938630293.png
paragkarki143_3-1650938630268.png
Pras by L4 Transporter
  • 9387 Views
  • 11 replies
  • 0 Likes

Panorama after rebooting didn't come up

Hi, After rebooting panorama, it didn't come up , also we are not able to commit after making changes, the committ status will stuck at 99%. Also we need to add more controls to Panorama. We need to do it immediately , Can we get one engineer to call immediately , support portal is down and this has to be case. Please share us Zoom link

IPSEC AND INTERNET TRAFFICE DISTRUTION

Dear Team, IPSEC AND INTERNET TRAFFICE DISTRUTION We have added 1 more ISP at our side and the same has been configured on the firewall, means now we have 2 ISP configured, we shall consider the OLD ISP as 1st ISP and NEW ISP as 2nd ISP. Presently we have configured GLOBAL PROTECT,IPSEC TRAFFIC and INTERENET BROWSING on 1st ISP. now our new re...

IS-Admin by L0 Member
  • 893 Views
  • 1 replies
  • 0 Likes
  • 853 Posts
  • 47 Subscriptions
Top Liked Authors