Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5039 Views
  • 0 replies
  • 0 Likes

Firewall not sending logs to correct log collector

Hi Friends, Firewall not sending logs to correct log collector, hence i followed the KB article. Firewall not sending logs to correct log collector - Knowledge Base - Palo Alto Networks But still same issue hence i say one more URL based on that executed delete log-collector preference-list. After that new panorama i am receiving logs. But is...

rbabu0 by L1 Bithead
  • 3458 Views
  • 2 replies
  • 0 Likes

Change Name of active Zones or Replace

Hi, we want to change the name from some active Zones that are active in policies. If we change the name than panormama display an error message. Is it possible and how, to change the name of a Zone oder replace it with a new one with the new name?

Resolved! TAGs for the use of Dynamic Address Group created on PANORAMAare not deployed to the firewalls if they are not used in some explicit way in the policy

I tell you the problem that we have detected today, with PANORAMA and our FWs,the objects that we are using through TAGs for the use of Dynamic Address Group are not deployed to the firewalls if they are not used in some explicit way in the policy. Do you know how it can be done so that it is shown?any idea?Greetings.

Alpalo by L4 Transporter
  • 3514 Views
  • 2 replies
  • 0 Likes

Managed PAs system log filtering and email alert on Panorama

If PAs are managed with Panorama and PAs are configured for log forwarding to Panorama. On Panorama > Log settings, Filter can be added for PAs system logs, logs can be seen on 'view filtered logs' as well. but email alerts are not generated. Only Panorama-based events are sent in email. If log settings are only for panorama system logs, then...

b.nazir by L0 Member
  • 6157 Views
  • 4 replies
  • 0 Likes

Resolved! VR Configuration for Tunnel not pushing

Hi Team, When I tried to create a tunnel interface from Panorama to push to the Managed device, But after the push the VR configuration is not reflected in the Managed device the VR showing none. But when I check in panorama the interface it properly attached with a VR and showing properly, There is no Commit error, We tried to ...

SubaMuthuram_0-1645769601083.png
SubaMuthuram_1-1645769984012.png

XML API: Panorama: How to Create/Get/Update the field "Audit Comment" of a Security Policy rule?

Settings Panorama version: 10.1 (latest) When creating/updating a Security Policy rule (see attached images for more info), I'm able to add/update Audit comment for a rule via Web browser by following this guide https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/policies/audit-comment-archive.html . However, I fail to use X...

HermanEdwards_1-1645745621315.png
HermanEdwards_0-1645745433474.png

Panorama - Wrong Password Hashes/Salts After Migration To Panorama

Hi everybody, I noticed something when migration stand alone firewalls to panorama managed. In the past, I had multiple customers where I needed to migrate the local firewall configuration to panorama managed and I am allways following the official documentation here: https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewa...

SSH export is using temp location which is not defined

Lately we are having issue with SSH export bundle on Panorama. we have specified location /abc/abc/abc however in the system logs we can see logs as /tmp/pan/<file_name>: No such file or directory. tried resetting the config still same issue. Panoram version 9.1.12-h3

aggarwat by L1 Bithead
  • 2778 Views
  • 1 replies
  • 0 Likes

Post Panorama Upgrade to 9.1.12-h4, unable to Commit-Verify to firewalls

I completed the upgrade of Panorama from 8.1.18->8.1.21->9.0(dl)->9.0.15->9.1.0(dl)->9.1.12-h4. Seemed to go fine. After the upgrade, all firewalls listed in the Panorama-Summary tab are Out of Sync. Expected to have to Commit to all of the firewalls. However, when I did a Commit-Verify, in order to verify these, it started al...

Scheduled Backup/Export

So I have panorama backing up to ftp, all works well, but I noticed it doesn’t ever clean up the backups? Can we tell it how many copies/days to keep somewhere. It is not a huge amount of data but I have exports daring back over a year and will never go back to those.

bschaper by L2 Linker
  • 3441 Views
  • 3 replies
  • 0 Likes

Resolved! Traffic logs are not shown on the Panorama monitor tab

I configured Panorama 10.1.2 in panorama mode as a dedicated log collector with a 2TB disk.I then added a VM 10.1.2 as manged firewall. I can configure the firewall but I do not receive the logs on the monitor tab: 1. Managed Collector in sync but in statistics I have disk status unavailable: 2. On the CLI instead:   I kindly ask you for...

statistics.png
cli_disk.png

Disable ARP entry for outside interface

Hi Team, As per the ISP request, I need to disable ARP entry for my palo alto outside interface. Please suggest me how to proceed. Palo alto outside interface connected with ISP, as per their request we need to disable ARP entry on that interface. Please let us know how to disable. Its very urgent.

rbabu0 by L1 Bithead
  • 6118 Views
  • 5 replies
  • 0 Likes

Panorama Manager of Managers

I've been tasked with looking into and understanding how the Panorama Manager of Manager architecture works. I have had no luck in finding any documentation or tutorials on it, but our SE team has talked about it a few times. Has anyone had any first-hand experience in setting up and administering Panorama in this architecture? If so, could you ...

tominak by L0 Member
  • 2535 Views
  • 1 replies
  • 0 Likes
  • 726 Posts
  • 47 Subscriptions
Top Solution Authors
Labels