Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5009 Views
  • 0 replies
  • 0 Likes

Need to test policy on many policies

Hi. I need to test if an internal site is accessable from several different zones. the destination and port will always be the same, and any source IP in the zones would work as a test, is there a way to run a policy match in a bulk manner where I can input everything once and Pano just spits out the policy that each source hits?

Pan Configurator Failing to download Panorama Config

I have configured the latest version of the PAN-Configurator. I have created my API key from a superuser account. when I tried to issue a command to label some rules it fails php rules-edit.php in=api://192.168.0.10 ruletype=security location=NDH1-CHC-FW actions=tag-Add:REV4DELeltion 'filter=(rule is.disabled)'I get the following error:---------...

Kaliman by L1 Bithead
  • 10230 Views
  • 8 replies
  • 0 Likes

How to move all template configuration in "Shared" location into Vsys1

Hi all, Some help on this would appreciated. Evaluating a client panorama that has a variety of templates on it, with much of the configuration in the templates being done in the "Shared" location, and much of it in "vsys1" location, including a number of certificates that have been imported to one or the other inconsistently over the years....

Resolved! Bulk MTU Size Change via Panorama

Hi All, We have a number of tunnel interfaces managed by Panorama where we want to change the default MTU size. Just wondering if we can script this or does each interface need to be touched to make the change? Thank a Veteran today, Dan

Panorama integration

Do we foresee any downtime during taking existing running firewalls behind panorama server? Also what precautions we should consider for such work?

d.spider by L2 Linker
  • 2746 Views
  • 2 replies
  • 0 Likes

Resolved! How to upgrade software in firewalls when firewalls are managed by panorama

1.if firewalls are managed by panorama, Should we need to upgrade only from Panorama or can also upgrade from firewall as well ?2. if firewalls are managed by panorama, how to backup config for the specific firewall ? should we need to take config backup only from panorama or can also take backup from firewall as well ? 3.if firewalls are manage...

perumalj by L2 Linker
  • 4909 Views
  • 1 replies
  • 0 Likes

Custom Admin Template Examples for GP Admin and Network Engineer?

So recently we (as in voluntold lol) decided to get rid of our dedicated Cisco L3 devices and move the L1 (VMWire) only FW's into L3 as a "cost saving measure". Won't get into how much I hate this but the decision has been made. Also this entire thing is managed via Panorama so don't need "do local FW overrides of templates". Also virtual syst...

PeterT by L2 Linker
  • 2687 Views
  • 1 replies
  • 0 Likes

Cant push config due to error

Getting error when trying to push configs from Pan - checked policy and it looks fine was not a problem previously? Details:. Validation Error:. rulebase -> security -> rules -> Deny_Inbound_Internet_Bad_IPsBOTNET -> source-hip unexpected here. rulebase -> security -> rules is invalid. Commit failed

After changing exiting object name at panorama, got commit failed message

• . Validation Error:. rulebase -> security -> rules -> <our rule name A>-> source ‘<want to amend object name> is not an allowed keyword. rulebase -> security -> rules -> <our rule name A>-> source ‘<want to amend object name> is an invalid ipv4/v6 address. rulebase -> security -> rules -&gt...

Multiple Virtual Routers in a single system - Issues with Failover in an Active/Standby setup

Hello, We have a pair of PA5050 appliances that operate dual virtual-routers in order to provide dual ISP connectivity using eBGP between them. We also have some site to site and AWS VPNs terminating on VR1 and GlobalProtect VPNS terminating in VR2. The issue we have seen is that when upgrading the PAN-OS, the appliances fail over as do se...

Resolved! Issue with Panorama import

While doing policies import to newly added FW , mistakenly i didn't uncheck the box as shown below in the snapshot ( "Import device's shared object into Panorama shared context ...." , consequently Panorama imported FW template in already created Device groups which is undesired - I see no option to remove these unwanted template from other devi...

farmangee_0-1633973049223.png

Panarama migration M-100 to M-200

So I have been running my Panorama on an M-100 since I inherited it, now the M-100s are end of life and it is time to move on. So I bought an M-200, seemed reasonable at the time. Now trying to migrate, after working with TAC for a couple of weeks, they tell me you can't migrate M-100 to M-200? It is actually in the documentation. What The.....

jdemares by L1 Bithead
  • 5414 Views
  • 1 replies
  • 0 Likes
  • 721 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels