Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 5068 Views
  • 0 replies
  • 0 Likes

Custom Admin Template Examples for GP Admin and Network Engineer?

So recently we (as in voluntold lol) decided to get rid of our dedicated Cisco L3 devices and move the L1 (VMWire) only FW's into L3 as a "cost saving measure". Won't get into how much I hate this but the decision has been made. Also this entire thing is managed via Panorama so don't need "do local FW overrides of templates". Also virtual syst...

PeterT by L2 Linker
  • 2734 Views
  • 1 replies
  • 0 Likes

Cant push config due to error

Getting error when trying to push configs from Pan - checked policy and it looks fine was not a problem previously? Details:. Validation Error:. rulebase -> security -> rules -> Deny_Inbound_Internet_Bad_IPsBOTNET -> source-hip unexpected here. rulebase -> security -> rules is invalid. Commit failed

After changing exiting object name at panorama, got commit failed message

• . Validation Error:. rulebase -> security -> rules -> <our rule name A>-> source ‘<want to amend object name> is not an allowed keyword. rulebase -> security -> rules -> <our rule name A>-> source ‘<want to amend object name> is an invalid ipv4/v6 address. rulebase -> security -> rules -&gt...

Multiple Virtual Routers in a single system - Issues with Failover in an Active/Standby setup

Hello, We have a pair of PA5050 appliances that operate dual virtual-routers in order to provide dual ISP connectivity using eBGP between them. We also have some site to site and AWS VPNs terminating on VR1 and GlobalProtect VPNS terminating in VR2. The issue we have seen is that when upgrading the PAN-OS, the appliances fail over as do se...

Resolved! Issue with Panorama import

While doing policies import to newly added FW , mistakenly i didn't uncheck the box as shown below in the snapshot ( "Import device's shared object into Panorama shared context ...." , consequently Panorama imported FW template in already created Device groups which is undesired - I see no option to remove these unwanted template from other devi...

farmangee_0-1633973049223.png

Panarama migration M-100 to M-200

So I have been running my Panorama on an M-100 since I inherited it, now the M-100s are end of life and it is time to move on. So I bought an M-200, seemed reasonable at the time. Now trying to migrate, after working with TAC for a couple of weeks, they tell me you can't migrate M-100 to M-200? It is actually in the documentation. What The.....

jdemares by L1 Bithead
  • 5473 Views
  • 1 replies
  • 0 Likes

Logging service license not assigned from Panorama to FW

There's deployment with Panorama and currently one HA PA pair managed by it. Panorama sitting at 9.1.5, firewalls at 9.1.4.Cortex Data Lake license is assigned to Panorama and seen in the Panorama -> Licenses section. In order for the firewalls to send the logs to Data Lake, I followed this guide: https://docs.paloaltonetworks.com/cortex/cort...

nikoo by L3 Networker
  • 10666 Views
  • 5 replies
  • 0 Likes

changing a gateway's management IP?

If i have a gateway managed via Panorama, what would be the steps needed if that gateway's management IP needs to change? The actual change of IP is straight forward. But then what about the changes needed between Panorama and that gateway?

Resolved! Is Panorama running on 10.1 the only version able to generate a stats dump file for managed firewalls

Is Panorama running on 10.1 is the only version able to generate a stats dump file for managed firewalls? Seems crazy to me but that's what I've been told, how are large customers pulling Stats Dump Files across 100+ firewalls? I'm sure it can be scripted but I wanted to confirm no GUI option before 10.1. Thanks

Resolved! Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push

Panorama (eth1/1) to firewall (Loop0 or vlan interface) configuration push Hey guys Not sure if it's a valid solution but I need your advise. Panorama - M500 FW - PA3220 Scenario 1: Panorama (MGT Interface) <---------- (MGT Subnet) ----------> (MGT Interface) Firewall can push the config from Panorama to FW everyth...

Resolved! Panorama different Dynamic Update Sections

Trying to figure out what Panorama > Dynamic Updates are used for, the Device Deployment updates make sense but not sure what Panorama > Dynamic Updates is actually doing if anything.. Panorama > Device Deployment > Dynamic Updates vs Panorama > Dynamic Updates Thanks

Resolved! Network Interface not pushed from Panorama

Hello, We need to add an extra IP Range to route out one of the existing sub interfaces on the Palo Alto firewall.The change has been committed and pushed in Panorama but is not showing on the firewall.Both using version 8.1.3 Firewall network interface: Panorama network interface with the change circle in red: How do we push this change to th...

FW network interface.jpg
Panorama network interface.jpg

Resolved! Panorama: why can't we edit Application settings in Device Groups?

Specifically, why can't we disable the SIP ALG in Panorama, in order to push that out to the firewalls? Even more specifically, why isn't that option available in the Panorama GUI? It's a real pain having to manually change that on each individual firewall, and commit the change locally, instead of setting it once in a Device Group and having i...

fjwcash by L4 Transporter
  • 9314 Views
  • 5 replies
  • 1 Likes

PAN-OS command for view a rule

Hello, I am looking for a command in PAN-OS for view one rule created by GUI but I can't find it. I want to view a rule configured searching it by rule name or by rule number. Best the first option. Anybody can help me? Thanks in advance

carlostg by L1 Bithead
  • 5175 Views
  • 4 replies
  • 0 Likes
  • 728 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels