Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4839 Views
  • 0 replies
  • 0 Likes

question about panorama and proxy server

Hi,Bro The customer's network environment does not have direct access to the Internet, but wants panorama to update the contents and software of the managed firewall device through a proxy server. So the proxy server is configured to allow access to updates.paloaltoneytworks.com. We found that only updates.paloaltoneytworks.com is released on th...

Resolved! Service object injected from Panorama, local view on firewall says destination port [ object Object ].

Service object injected from Panorama, local view on firewall says destination port [ object Object ]. Thank you very much as always. Can you support and help me by confirming if this is completely normal behavior. I have a Panorama and I am injecting a new service to two firewalls in HA that share the same Template/Template Stack. Well ...

Destination_Port.png
2022-07-10 18_00_22-PA-VM.png
from_panorama.png
Metgatz by L4 Transporter
  • 3788 Views
  • 4 replies
  • 0 Likes

Panorama - Force Template Value Option

Hello good evening: As always, thank you very much for the support, collaboration, support and help. I have the following important question regarding a PANORAMA function, in relation to the "Forced Template Values" option.According to the documentation, this option performs the following function:Merge with Cadidate Config = Option to merge t...

Metgatz by L4 Transporter
  • 16594 Views
  • 1 replies
  • 0 Likes

Panorama 10.1.6 wants to push keys and secret every time

Hi all, I want to upgrade my Panorama, 220s and 3220s from 10.0.10 to 10.1.6. I started upgrading Panorama and a 3220 HA Active Passive Pair to 10.1.6 No issues during update. When I want to push config to devices, I notice that the 3220s are shown "in sync", but when I go to the diffs, it always wants to push modified keys and secrets: IPSec Tu...

DVB_Bank by L1 Bithead
  • 2092 Views
  • 1 replies
  • 0 Likes

Panorama Template Push to Firewall always fails, unless you push Device Group at the same time

Panorama - VM ESXi - Panorama mode - version 10.1.4 When Panorama Template Push to Firewall always this always fails, reports out of sync and when you log directly to the firewall you do not see the changes. When you push Device Group and the Template from Panorama to the firewalls, the Template changes are successfully. The options enabl...

CarlUK by L0 Member
  • 4285 Views
  • 2 replies
  • 0 Likes

Resolved! Duplicate config in panorama managed firewall

Hi Team, In my firewall i can 2 configuration at the same time. One i pushed from panorama and one is local that is scyronized from the passive peer. i can see everything is duplicate. How can i remove the duplicate config ( Local config from the firewall and keep the panorama pushed only. Thanks in advance

Add Shared Gateway FW into Panorama

I am trying to add a stand alone fw into Panorama, v 10.0.8. After I add the device in Pan and commit , the device shows as connected. I then import the config which includes a shared gateway. When I commit the config in Pan I receive an error message that suggests duplicate UUID's found and the commit fails - see attached. I don't see a shared ...

shaneo by L1 Bithead
  • 2297 Views
  • 0 replies
  • 0 Likes

Panorama template section is empty : No interfaces, no zones

Hello team, I have 2 firewalls managed in my panorama. When I go to template section on Panorama I can not see anything, any interfaces, zones so it's not possible to make any change from the Panorama. I have to make changes directely on the firewall. Do you know how can I fix out this issue ? Kind regards

Mamoudou by L2 Linker
  • 3130 Views
  • 2 replies
  • 0 Likes

Bulk add existing addresses to an existing group

Hello,I'm hoping someone can help out. I've just finished a merge from an ASA to Palo Alto through Expedition. The ASA had 3000+ addresses as part of an existing address group. I've tried multiple times to merge, and push the changes through the API, but it would appear all the addresses don't show up in the group.I guess what I'm asking, is ...

clwilson by L0 Member
  • 2099 Views
  • 1 replies
  • 0 Likes

Postponing Logdb Migration

I have a Legacy mode Panorama virtual appliance running PANOS 8.1 that I am planning on upgrading to 10.2. Would the below order of operations be a valid approach or does logdb migration NEED to occur before performing PANOS upgrades? 1. Perform Panorama mode conversion (adding resources etc.), but not logdb migration. 2. Perform PANOS Upgrade...

Shared RADIUS Server Profile, and Shared Authentication profile not showing up in a new Template?

Hi Friends, Please note that I have a Panorama running version 10.1.5-h1, and I just registered a couple of new PA-440 Palos which have the same software version 10.1.5-h1. I also provisioned it's corresponding Template Stack, Device Group, and pushed everything successfully to those new firewalls. However, my weird thing is that I should be abl...

Resolved! How to configure passive HA Panorama ethernet interface

We are currently deploying two Panorama M-series appliances with active/passive configuration. The expected interface configuration will be like this: Active/Primary Panorama: Management: 172.20.1.11 (only for Panorama management access) ethernet1/1: 10.20.5.100 (for device management, log collection, etc.) > devices will be connected to this...

KNau by L1 Bithead
  • 5227 Views
  • 2 replies
  • 0 Likes

Resolved! Access Panorama to Firewalls GUI switch-context and CLI-SSH switch-context

Access Panorama to firewall Gui context and CLI context Hello, good morning, I reiterate, thank you again for the information, help and support. Please support the following topic: Currently, with the account that logs me into Panorama, as long as I have access and permissions to all contexts, I was able to change the context to enter the fire...

Metgatz by L4 Transporter
  • 9223 Views
  • 3 replies
  • 0 Likes

Panorama log disk migration error - 10.1.5-h2

Hi All, We want to move Panorama's log disk from a passthrough iSCSI disk to a local VHDX (Hyper-V). We've tried cloning the volume, but Panorama wipes the data because it initializes the disk. If we try to start the log migration from the CLI we get Error restoring disks from RMAed device. (as described in PAN-105012, but not applicable to pa...

  • 844 Posts
  • 47 Subscriptions
Top Solution Authors