Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5070 Views
  • 0 replies
  • 0 Likes

Getting Set VSYS message when creating Panorama certificates

I am creating a certificate/CSR for my management TLS login. I created a cert, but when going to export the CSR, or anything else on the bottom bar, I get a hovering message "You need to assign a default VSYS to current template first" I can't find anywhere in Panorama to set the VSYS, all my device templates have VSYS1, Tried many documents, ...

Collect data on and then block file-sharing application IDs.

I'm looking for a method to collect data passing through all location firewalls on what app-id tagged traffic for "file-sharing" is passing through (such as dropbox, onedrive, gdrive, etc.) and consolidate our organize to a single filesharing service. Once I've collected what is the most popular service, I want to put in place a policy to block ...

Resolved! ACC on Panorama show only risk 1

Hi everyone, I have a problem with ACC on Panorama showing only risk 1. Using Panorama-VM and Firewall PA-440 I try to -restart management server on Firewall and Panorama. -upgrade panorama from PAN10.1.8 to 10.1.9-h1 currently, panorama running PAN-OS 10.1.9-h1, Firewall running PAN-OS 10.1.8-h2

I want to integrate LDAP in Panorama

I have Panorama on VM and i am trying to configure LDAP, i have setup LDAP profile and then trying to tie LDAP profile with Management interface but it looks like i am not getting any option where i can select LDAP profile from dropdown list, If LDAP tie up with Management Interface is not allowed ? Kindly help.

Resolved! Can I migrate policy rules from pre-rules to post-rules category and push to Firewalls without causing downtime?

So, I am new to palo-alto and I created some pretty general policies for internal-to-dmz communication, I now wanted to create a policy that would target specific host-to-destinations for testing, however, I noticed that the primary "Allow All" policy was set in the pre-rules, which takes precedence in the hierarchy. (Top to bottom). So what I n...

fbarnard by L0 Member
  • 3815 Views
  • 2 replies
  • 0 Likes

MIgrate drives from a retiring M200 and install them in a M600 appliance as expansion

I would like to take the 8 gig drives from a retiring M200 appliance, format, and install them in a M600 appliance in the expansion bays for additional storage. Is there a procedure available to 1. Format the drives on the M200, 2. Install in the M600, and 3. Add them to the existing storage as expanded space.

IPSEC VPN

I am working in a lab with VMware virtual machine and when I do VPN it throws the following error: ike phase 1 negotiation fails as initiator, main mode failed SA: 192.168.1.1[500]-203.0.113.40[500]Due to time. My firewall B is on another machine with another VM. Can you help me please?

When a firewall configuration migrated to the panorama, objects tab configuration imported as a shared object and got impact with other firewalls.

Hi team, While integrating a firewall into the panorama, I imported as a Device >Setup >Operations >Import device configuration as Panorama. The firewall configuration in the objects tab was imported as a shared object and impacted the other firewall configurations. I followed the admin guide for Firewall migration to the panorama. It i...

Screenshot 2023-05-03 173745.png
Screenshot 2023-05-03 173018.png
Screenshot 2023-05-03 173533.png
Screenshot 2023-05-04 201821.png

Panorama read only tunnel interfaces?

Hi I have a Panorama appliance and i am configuring our firewalls for global protect VPN, but i noticed once i pushed out the config for the gateway, it fails as the because it says the tunnel interface doesnt have a virtual router! I checked my config on the panorama and i have pushed out a default router, zones and interfaces to both firewall...

Resolved! Update software for a new Palo Alto 5260 FW through Panorama

Hi,I am fairly new to the game, and in need of some help. I have gotten a brand new PA-5260 fw. The plan for this is to have it in backup in case anything would happen to one of the others fw.My task is to only update the software on the new PA-5260 from 9.1.4 > 10.1.6-h6, which is the version the other fw are running on now. On the new PA-52...

Resolved! load config partial / bad encryption or wrong masterkey

We're replacing an HA pair for a customer with new hardware and building new templates as the current devices have local overrides for almost the entire device & network config (looks like the result of an improper transition to Panorama). The idea is we export the current device config and merge it into the new template. Both Panorama and t...

mb_equate by L3 Networker
  • 7983 Views
  • 3 replies
  • 0 Likes

localhost 31377 erno 111 connection refused

I made a configuration change on panorama. commit to panorama fail I checked the plug-in and only the sd_wan 2.02 plug-in was installed No other plug-ins are installed. My revert to running panorama configuration failed to solve the problem.

Panorama Log collector

Hello, I would like to know on a single log collector can you set up several profiles that send the logs to different servers depending on the source of the logs? We have several Firewall clusters on the panorama and we want to be able to send the logs to different ports depending on the clusters. Thanks in advance for your help.

Mamoudou by L2 Linker
  • 1797 Views
  • 1 replies
  • 0 Likes
  • 728 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels