Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5067 Views
  • 0 replies
  • 0 Likes

Resolved! Email Alert on PAN/PAFW for new admin account Creation

Hi, I am looking to create email alerts for when ANY user creates a new admin account of anytype on both our Panorama and any of our firewalls managed by panorama. Our PAFW send/forward their logs to our M600 Panorama device. Any have any link or suggestions? Purpose being to know if any admin create local or alternate admin accounts, or s...

Resolved! Panorama - Log collector issues

Hi I just deployed a Panorama VM and I added a disk of 2TB. On Managed Collector, I see my Panorama device (VM) on collector name but the status is disconnected / Out of Sync. Currently, I have no firewall connected on the Panorama server. Is-it this status is normal until I connect a firewall to the Panorama or does I make an error on my conf...

jeromecarrier_0-1695723894121.png

How do I assign SD-wan interface profile to template when all sites have different speeds for fiber and cable.

How do I assign a SD-wan interface profile an interface in a template with 3 firewalls assigned to 3 groups based on site when each site has different speeds for each ISP? Do I have to go against palo alto recommendations and use 3 templates? Site 1 Fiber: 250Mbps/250MbpsSite 1 cable: 600Mbps/35Mbps Site 2 Fiber: 200Mbps/200MbpsSite 2 cable: 250...

Resolved! Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't

Hi,When I try to push a config from Panorama to a PA-440, the commit fails because of these reasons. Which is strange because ethernet1/2 isn't in use (on the PA-440). Also the zones are configured and their type is defined.What am I missing here ? Thank you very much,

The Panorama IP has been changed on the firewall, but the firewall still has a session to the original IP

Panorama is used for management and log collection. The IP address of Panorama has not changed. There is a firewall outside Panorama, which maps the 3978 port of the firewall's exit IP to Panorama. The managed firewall was originally configured with the private network IP of panorama. Now it is changed to the mapped public network IP. After the ...

Wilbur by L1 Bithead
  • 5667 Views
  • 4 replies
  • 0 Likes

Primary palo alto 220 missing on panorama but I can access it via CLI

Needing your help I'm newbie on Palo alto . We have a Panorama on one of our sites this is PA 200 before I'm seeing the primary on panorama but not its not. Although I can access it via SSH and use the CLI but when I run the show running sync-to-panorama command it was not on list. This panoramas are old ones and slow. The mgmt and policies are ...

weezy by L3 Networker
  • 3868 Views
  • 8 replies
  • 0 Likes

Template stack override clear pending change

I mistakenly clicked an override on a template stack and now there are pending changes to be pushed to the firewalls. I tried the revert option in Panorama next to the commit button but it did not show any changes. I tried the Revert to running Panorama configuration and then selected one of the template stacks and clicked OK, when I click on...

HIP Notification + Windows Updates

I have HIP notifications set up when users do not have Microsoft patches greater than or equal 2 severity. I would like to only notify them if it is a Windows Update, specifically security updates. As of now, they are getting the notification for any patch from Microsoft with the severity greater than or equal to 2. I see in the GlobalProtect Ho...

Panorama managed devices lose configuration

On two occasions recently my firewalls stopped functioning correctly following a reboot.The first time affected a single firewall. I restarted the firewall in order to troubleshoot.The second time was after a software update. Both firewalls were rebooted.In both cases when the firewalls came back up they wouldn't process traffic correctly until ...

Template stacks and Vsys1

Hello, I am running into an issue when attempting to create a template stack and vsys1 not being able to be removed. I have a defined vsys that I want to use with all the necessary information already in it and as I start building out my stack I noticed that my preferred vsys is listed under Templates -> <Stack defined> -> virtual ...

Resolved! How are duplicate shared objects identified in Panorama?

I know that when you migrate a firewall into Panorama and you keep the Import device's shared objects into Panorama's shared context box checked, this imports the firewall's objects as shared objects, unless there are duplicates. I'm wondering--how does Panorama identify any duplicates? Is it by the name of the object or other characteristics (s...

MDroyKT by L2 Linker
  • 12042 Views
  • 5 replies
  • 0 Likes

Management server failed to send phase 1 to client sslvpn

Hi All, Commit is getting failed on only Active unit while pushing it from Panorama. Commit Failed from Panorama Error : Management server failed to send phase 1 to client sslvpn Commit is failing only on Active unit while commit is successful on passive unit. Device Details: Panorama : M-500 PAN-OS : 9.1.8 Firewall : PA-5060 PAN-OS : 8.1.18...

Should you track failed login attempts and how ?

How important is it to configure an alerting/incident for failed login attempts to the Palo Alto Panorama or Firewalls. This is for: (1). SAML based authentication (2). Local logins. Should both of them be tracked and do we need to monitor the system logs for any particular "event" for both of them ?

  • 728 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels