Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4919 Views
  • 0 replies
  • 0 Likes

Resolved! Syntax for PA3050 and PA3020

I would like to check if what are the differences between the syntax of xml configuration for the two models? Particularly for the configuration of the two models to the Panorama server.

Panorama slow since updating to 10.1

Since i have updated from 9.1 to 10.1 i have found Panorama to be noticeably slow. Especially when searching the traffic log or generating a report. Sometimes it will just time out. It is running in legacy mode. It appears to have adequate cpu and memory. Is it just me?

Deleting multiple rules associated to a single ip from panorama

Hi, I would like to know if there is a method to delete multiple rules associated to a single ip address from panorama ?? That single ip is permitted on several firewalls for communication and the server holding that ip was decommissioned and so the rules relating to it need to be cleaned up from all the existing firewalls. I am able to get bu...

Unable to perform initial export and push due to shared objects

Hello I am encountering a particularly frustrating problem. After importing a device's configuration into Panorama, the commit fails because the initial export and push includes shared objects, but not shared items in the templates. So if I, for example, have email log forwarding in my shared objects, commit on the device fails because the e...

SomeSuch by L1 Bithead
  • 6487 Views
  • 3 replies
  • 1 Likes

Resolved! firewall change event monitor

Hello Guy's 1. Add allow any/any rule:- If adding any new policies any/any rules in our environment. How I can forward/analyze logs to the Syslog server?2. Added administrator account:- If any new admin account is added in Palo Alto locally. How can see the logs in the Syslog server?3. Add authentication method:- We have SAML authentication in o...

Resolved! EDL in Panorama

Hi all, i've configured a couple of EDL in Panorama as shared list and pushed to all the devices. No problem at this point. Now,if i check the accessibility of the URL is normally available But if i try to list all the domains ,the output is always 0 entries. the test source URL is successfull from both Panorama and local device. I tried to ...

test (002).png
list_entry (002).png
MGMGMG by L1 Bithead
  • 4621 Views
  • 4 replies
  • 0 Likes

FW connectivity with Panorama in AWS

Cordial greetings Palo Alto Team This is to clarify a doubt regarding the integration of devices to Panorama. Currently the appliance is deployed in an AWS region, however, we have FW VM-Series deployed in GCP, Azure and AWS cloud. The AWS FWs are already integrated, however, I would like to know how I could integrate the appliances that are i...

Error When Adding IP Address to Address Group via the XML API

I am working on a SOAR automation workflow that automatically adds an IP address to a Block List if Palo Alto identifies it as a “CRITICAL” or “HIGH” vulnerability coming from outside to inside our network. I am getting an error once the workflow reaches the part where it attempts to add the IP address to the block list. The error is the respo...

Resolved! Access Domains and context switching

HI All, I have configured access domains to control read only access to certain device groups, but the context switching is not working, I have configured a Admin Role locally, added the user to the local device with an admin role, even added the username as the device and vsys role to see if that would work, the log output from #tail follow...

Resolved! pn do not use tempalte ,only use device group

The customer manages multiple sets of firewalls through panorama. Considering that the configuration of the template is not changed much in the future, the customer considers porting the configuration of the template to the local wall. If the parameters are changed, it will not be pushed through panorama. Panorama is only responsible for pushing...

Felixcao by L3 Networker
  • 1979 Views
  • 1 replies
  • 0 Likes

PanOs 10 application icons

At the risk of exposing myself as a complete idiot, can anyone point me at an explanation of these icons used by PANOS/Panorama? I am very familiar with the green gear that indicates an inherited value, but since upgrading to v10 almost all of the applications which are grouped under a master application have now got a red gear on their icon, s...

panos applicaitons.png
djr by L4 Transporter
  • 7941 Views
  • 2 replies
  • 0 Likes

Panorama is not connecting to the new firewall PA-460

Hi All, I am trying to add new firewall to the existing Panorama. It is in disconnected status since the time i added it. Both the devices are in version 10.2.2. I can ping both the devices from either devices. I can see connectivity is there between the devices. I also see one of the firewalls in the same subnet is connected and working. But ne...

Upgraded Pano to 10.1.6-h3

Upgraded Panorama to 10.1.6-h3 and when logging in I see this. Trying to see how to fix the issue."Unable to retrieve region list either region list has not been set or data format is wrong"

mmagee by L0 Member
  • 1867 Views
  • 1 replies
  • 0 Likes

Resolved! Missing license after upgrade to 10.1.8

After upgrading Panorama (virtual machine) from 10.1.3-h1 to 10.1.8 the license for 100 devices is back to 25 devices. In support portal assets, the device is registered with 'Device Management License qty. 100', but still when 'request license fetch', the device still says on 25. Since we have 30+ devices managed by Panorama, I now get the fo...

panorama-license-error.png
Anbjorn by L1 Bithead
  • 2640 Views
  • 1 replies
  • 0 Likes

Question about device registration authentication key re-certify

Hello all,Hope you are doing well.PA-460 (HA) : PAN-10.1.7M-200 : PAN 10.1.7I understand that the device registration authentication key expires after 90 days.

By the way, according to the admin guide, a message will be displayed to re-authenticate the authentication key to remaining valid after 90 days, but is this message only displayed in pa...

  • 854 Posts
  • 47 Subscriptions
Top Liked Authors