Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5008 Views
  • 0 replies
  • 0 Likes

XML API: Panorama: How to Create/Get/Update the field "Audit Comment" of a Security Policy rule?

Settings Panorama version: 10.1 (latest) When creating/updating a Security Policy rule (see attached images for more info), I'm able to add/update Audit comment for a rule via Web browser by following this guide https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/policies/audit-comment-archive.html . However, I fail to use X...

HermanEdwards_1-1645745621315.png
HermanEdwards_0-1645745433474.png

Panorama - Wrong Password Hashes/Salts After Migration To Panorama

Hi everybody, I noticed something when migration stand alone firewalls to panorama managed. In the past, I had multiple customers where I needed to migrate the local firewall configuration to panorama managed and I am allways following the official documentation here: https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewa...

SSH export is using temp location which is not defined

Lately we are having issue with SSH export bundle on Panorama. we have specified location /abc/abc/abc however in the system logs we can see logs as /tmp/pan/<file_name>: No such file or directory. tried resetting the config still same issue. Panoram version 9.1.12-h3

aggarwat by L1 Bithead
  • 2769 Views
  • 1 replies
  • 0 Likes

Post Panorama Upgrade to 9.1.12-h4, unable to Commit-Verify to firewalls

I completed the upgrade of Panorama from 8.1.18->8.1.21->9.0(dl)->9.0.15->9.1.0(dl)->9.1.12-h4. Seemed to go fine. After the upgrade, all firewalls listed in the Panorama-Summary tab are Out of Sync. Expected to have to Commit to all of the firewalls. However, when I did a Commit-Verify, in order to verify these, it started al...

Scheduled Backup/Export

So I have panorama backing up to ftp, all works well, but I noticed it doesn’t ever clean up the backups? Can we tell it how many copies/days to keep somewhere. It is not a huge amount of data but I have exports daring back over a year and will never go back to those.

bschaper by L2 Linker
  • 3427 Views
  • 3 replies
  • 0 Likes

Resolved! Traffic logs are not shown on the Panorama monitor tab

I configured Panorama 10.1.2 in panorama mode as a dedicated log collector with a 2TB disk.I then added a VM 10.1.2 as manged firewall. I can configure the firewall but I do not receive the logs on the monitor tab: 1. Managed Collector in sync but in statistics I have disk status unavailable: 2. On the CLI instead:   I kindly ask you for...

statistics.png
cli_disk.png

Disable ARP entry for outside interface

Hi Team, As per the ISP request, I need to disable ARP entry for my palo alto outside interface. Please suggest me how to proceed. Palo alto outside interface connected with ISP, as per their request we need to disable ARP entry on that interface. Please let us know how to disable. Its very urgent.

rbabu0 by L1 Bithead
  • 6067 Views
  • 5 replies
  • 0 Likes

Panorama Manager of Managers

I've been tasked with looking into and understanding how the Panorama Manager of Manager architecture works. I have had no luck in finding any documentation or tutorials on it, but our SE team has talked about it a few times. Has anyone had any first-hand experience in setting up and administering Panorama in this architecture? If so, could you ...

tominak by L0 Member
  • 2525 Views
  • 1 replies
  • 0 Likes

Panorama VM upgrade to PANOS 8.0.x & switch mode to Panorama Mode

Hi, This is my feedback experience after two weeks of migration process and troubleshooting moving to Panorama 8.0.7 in Panorama Mode. The most part of the process is available from the Panorama 8.0 Administrator's Guide 8.0 but I noticed a lack of information for certain steps. I hope that can help the next adventurers. #Existing configuration...

FRVSA by L1 Bithead
  • 49987 Views
  • 13 replies
  • 14 Likes

Panorama collector statistic

Anyone tell me what the day mean in Managed collector > statistics > oldest log ? I just checked the day and I found something is weird. 1) when I checked it less than 7 days , it almost matched with current local times 2) And oldest log day is increased a day per day , but i can't see traffic log over 8 days from current local time.

JeffKim_0-1643386696390.png
JeffKim by L2 Linker
  • 2282 Views
  • 1 replies
  • 0 Likes

Has anyone used Panorama to import a configuration from HA 5060s to use on new generation 5450s?

Goal is to replicate the current configuration from production 5060 firewalls to replacement 5450s firewalls. The intent is to use Panorama to bridge the OS difference between the 5060s (highest os 8.1.x) and 5450s (start with 10.1.x). The 5060s are HA and on panorama for object sharing but the policies (security, nat, pbf) are localized. Bot...

Resolved! Can't commit from Panorama due to mis-match Vsys number between Pan and local box

wanted to know if anyone has ever experienced this issue. recently configured a new Vsys "Vsys6" which was successfully added to the correct Template_stack and device groups. everything worked fine for 2-3 weeks, however last night after adding 2 Sec.policies to the new Vsys. the commit failed. FYI for security i've edited the zone names and pol...

  • 721 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels