Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5045 Views
  • 0 replies
  • 0 Likes

Identify Panorama Template Overrides on Firewalls

I have a scenario where we have 70 firewalls, in HA pairs, managed by Panorama.Templates are set up, and pushed to the firewalls, but *some* of the firewalls have template overrides set for various things.I am looking for a good way to identify, whithout visually eyeballing every web gui page on every firewall, which settings on individual firew...

Panorama appliance question

We have an old Panorama physical appliance (5 years old) which will be replaced within the next four days I'm wondering if by any chance it can be used as host. That of course would mean wiping the ssd disk and installing a linux distribution. In a nutshell can a Panorama physical appliance be treated as normal host once deprived from its PAN‑OS...

Migrate Panorama to AWS

Hi, I'm planning to do a migration of Panorama from esxi to AWS. This will require the Panorama to have a different IP address. What's the best way to handle the IP change, if the firewalls are getting the Panorama IP config from device template setting? Is it best to override locally after the migration and then update the template after?

Create policies from flows in file excel/csv to a Panorama particular - Device Group

Create policies from flows in file excel/csv to a Panorama particular - Device Group Hello Live Community, good evening, as always, thanks for the collaboration, the good vibes and the good vibes. I tell you that I have the following scenario/situation: Panorama- Device Groups - HA Firewalls - Policies on Device Groups, Any/Any Allow - Loc...

Metgatz by L4 Transporter
  • 4352 Views
  • 2 replies
  • 1 Likes

Complete application traffic report for firewall rule

Hi! We have migrated our customers old firewalls to Palo altos and managing them through Panorama. Now we want to convert the old rules into specific application rules. From server to server , Application by application. So what I need is a complete traffic log/report, rule by rule to be able to start with the new Application rules. It s...

Resolved! Syntax for PA3050 and PA3020

I would like to check if what are the differences between the syntax of xml configuration for the two models? Particularly for the configuration of the two models to the Panorama server.

Deleting multiple rules associated to a single ip from panorama

Hi, I would like to know if there is a method to delete multiple rules associated to a single ip address from panorama ?? That single ip is permitted on several firewalls for communication and the server holding that ip was decommissioned and so the rules relating to it need to be cleaned up from all the existing firewalls. I am able to get bu...

Unable to perform initial export and push due to shared objects

Hello I am encountering a particularly frustrating problem. After importing a device's configuration into Panorama, the commit fails because the initial export and push includes shared objects, but not shared items in the templates. So if I, for example, have email log forwarding in my shared objects, commit on the device fails because the e...

SomeSuch by L1 Bithead
  • 6812 Views
  • 3 replies
  • 1 Likes

Resolved! firewall change event monitor

Hello Guy's 1. Add allow any/any rule:- If adding any new policies any/any rules in our environment. How I can forward/analyze logs to the Syslog server?2. Added administrator account:- If any new admin account is added in Palo Alto locally. How can see the logs in the Syslog server?3. Add authentication method:- We have SAML authentication in o...

Resolved! EDL in Panorama

Hi all, i've configured a couple of EDL in Panorama as shared list and pushed to all the devices. No problem at this point. Now,if i check the accessibility of the URL is normally available But if i try to list all the domains ,the output is always 0 entries. the test source URL is successfull from both Panorama and local device. I tried to ...

test (002).png
list_entry (002).png
MGMGMG by L1 Bithead
  • 4867 Views
  • 4 replies
  • 0 Likes

FW connectivity with Panorama in AWS

Cordial greetings Palo Alto Team This is to clarify a doubt regarding the integration of devices to Panorama. Currently the appliance is deployed in an AWS region, however, we have FW VM-Series deployed in GCP, Azure and AWS cloud. The AWS FWs are already integrated, however, I would like to know how I could integrate the appliances that are i...

Error When Adding IP Address to Address Group via the XML API

I am working on a SOAR automation workflow that automatically adds an IP address to a Block List if Palo Alto identifies it as a “CRITICAL” or “HIGH” vulnerability coming from outside to inside our network. I am getting an error once the workflow reaches the part where it attempts to add the IP address to the block list. The error is the respo...

Resolved! Access Domains and context switching

HI All, I have configured access domains to control read only access to certain device groups, but the context switching is not working, I have configured a Admin Role locally, added the user to the local device with an admin role, even added the username as the device and vsys role to see if that would work, the log output from #tail follow...

Resolved! pn do not use tempalte ,only use device group

The customer manages multiple sets of firewalls through panorama. Considering that the configuration of the template is not changed much in the future, the customer considers porting the configuration of the template to the local wall. If the parameters are changed, it will not be pushed through panorama. Panorama is only responsible for pushing...

Felixcao by L3 Networker
  • 2047 Views
  • 1 replies
  • 0 Likes
  • 726 Posts
  • 47 Subscriptions
Top Liked Authors
Labels