Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5016 Views
  • 0 replies
  • 0 Likes

MIgrate drives from a retiring M200 and install them in a M600 appliance as expansion

I would like to take the 8 gig drives from a retiring M200 appliance, format, and install them in a M600 appliance in the expansion bays for additional storage. Is there a procedure available to 1. Format the drives on the M200, 2. Install in the M600, and 3. Add them to the existing storage as expanded space.

IPSEC VPN

I am working in a lab with VMware virtual machine and when I do VPN it throws the following error: ike phase 1 negotiation fails as initiator, main mode failed SA: 192.168.1.1[500]-203.0.113.40[500]Due to time. My firewall B is on another machine with another VM. Can you help me please?

When a firewall configuration migrated to the panorama, objects tab configuration imported as a shared object and got impact with other firewalls.

Hi team, While integrating a firewall into the panorama, I imported as a Device >Setup >Operations >Import device configuration as Panorama. The firewall configuration in the objects tab was imported as a shared object and impacted the other firewall configurations. I followed the admin guide for Firewall migration to the panorama. It i...

Screenshot 2023-05-03 173745.png
Screenshot 2023-05-03 173018.png
Screenshot 2023-05-03 173533.png
Screenshot 2023-05-04 201821.png

Panorama read only tunnel interfaces?

Hi I have a Panorama appliance and i am configuring our firewalls for global protect VPN, but i noticed once i pushed out the config for the gateway, it fails as the because it says the tunnel interface doesnt have a virtual router! I checked my config on the panorama and i have pushed out a default router, zones and interfaces to both firewall...

Resolved! Update software for a new Palo Alto 5260 FW through Panorama

Hi,I am fairly new to the game, and in need of some help. I have gotten a brand new PA-5260 fw. The plan for this is to have it in backup in case anything would happen to one of the others fw.My task is to only update the software on the new PA-5260 from 9.1.4 > 10.1.6-h6, which is the version the other fw are running on now. On the new PA-52...

Resolved! load config partial / bad encryption or wrong masterkey

We're replacing an HA pair for a customer with new hardware and building new templates as the current devices have local overrides for almost the entire device & network config (looks like the result of an improper transition to Panorama). The idea is we export the current device config and merge it into the new template. Both Panorama and t...

mb_equate by L3 Networker
  • 7799 Views
  • 3 replies
  • 0 Likes

localhost 31377 erno 111 connection refused

I made a configuration change on panorama. commit to panorama fail I checked the plug-in and only the sd_wan 2.02 plug-in was installed No other plug-ins are installed. My revert to running panorama configuration failed to solve the problem.

Panorama Log collector

Hello, I would like to know on a single log collector can you set up several profiles that send the logs to different servers depending on the source of the logs? We have several Firewall clusters on the panorama and we want to be able to send the logs to different ports depending on the clusters. Thanks in advance for your help.

Mamoudou by L2 Linker
  • 1756 Views
  • 1 replies
  • 0 Likes

Resolved! Can't edit or move Services objects to the Shared location in Panorama

I am testing out a firewall migration to Panorama with our lab firewall and found that, with the Services objects that I imported from the firewall, I am not able to edit them. I see that their location is "Predefined", and I can't change that location either. I know you are typically able to select an object and then select "Move" to move them ...

MDroyKT by L2 Linker
  • 3557 Views
  • 2 replies
  • 0 Likes

Unable to Add URL-Based External Dynamic List as Destination in Policy-Based Forwarding Rule on Panorama

I am attempting to use an External Dynamic List (EDL) with a URL-based list as the destination in a Policy-Based Forwarding (PBF) rule on Panorama. However, when I try to add the EDL as the destination in the PBF rule, I am not able to see the URL-based list EDL in the destination list. I have checked that the EDL is configured correctly, assign...

Stellar by L0 Member
  • 2936 Views
  • 3 replies
  • 0 Likes

error: certfile should be a valid filesystem path

Hi Team, I am trying to automate palo alto version 10.2.3-h2. Initially I tried to use Ansible: palo_security_rule module to push a security rule to palo alto, but I got error "hip_profiles unexpected here". The workaround for this error as looked up in google was to load current config in palo alto, which was not accepted as a feasible solution...

clean up unused objects within Panorama using expedition?

hello all, PA newb here. I recently transitioned to a firewall admin job and am learning my way around Palo Alto for the first time. one issue I've been tasked with exploring is an issue where one of our firewalls has fallen out of sync because it is a VM and has limited object storage capabilities. it is the only VM in our production network. W...

Configure existing Production Panorama template used for Policies/Objects, but not Interfaces/Zones for SD WAN

When we started using the Panorama many years ago, we did so using the templates as an after thought of manually configuring each firewall. We are a small company so it wasn't difficult, but now we want to entertain SD WAN and my understanding is it is best to do this from the Panorama and not individually from each firewall. Since the Interf...

ronan by L0 Member
  • 2158 Views
  • 1 replies
  • 1 Likes
  • 724 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels