Panorama Commit Best Practices for Large Environments

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Panorama Commit Best Practices for Large Environments

L1 Bithead

 

Hi everyone,

I'm looking for some guidance on Panorama commit workflows in larger environments.

For those managing multiple device groups and templates, what has worked best for reducing commit times and avoiding unnecessary changes?

Do you typically use selective commits whenever possible, or do you have another workflow that has proven reliable? Also, are there any best practices for minimizing the impact of policy updates across a large number of managed firewalls?

I'd appreciate hearing how others handle this in production. Thanks!

1 REPLY 1

Cyber Elite

Hello @kosarbnu

 

thanks for post!

 

Below are a few points I can think of based on my experience.

 

In the past I was using managed device tag: Managed Firewall Administration in the Panorama under: Panorama > Managed Devices > Summary to have 3 tier hierarchy to push policies to managed Firewalls based on tags. If you have many Firewalls with large number of policies, I found tags effective way to filter and deploy policies.

 

If you have huge number of objects, I would recommend to look into disabling: "Share Unused Address and Service Objects with Device". Reference: How to Limit the Number of Shared Objects Panorama Pushes to the Managed Device , Address object limit exceeded on Panorama Managed Low End platforms even if "Share Unused Address an....

 

 If you have an environment where some of the configuration is managed locally directly in Firewall by different admins, then I would recommend to deselect: “Merge with Candidate Config” to prevent your Panorama pushed configuration is also committing someone else configuration: How Configuration Change is Being Applied Depending on “Merge with Candidate Config” Commit Option.

 

If you have large organization with multiple admins in different regions managing configuration through Panorama it might be worth looking into: Access Domains.

 

Lastly, I recommend to have pre-policy on the top that explicitly allows managed Firewalls to communicate with Panorama. In the case there is a misconfiguration by pushing a policy that cuts off manage Firewalls, you can still maintain access to rollback change.  This applies when Firewall policy can break path between managed Firewalls and Panorama. This is handy in the case Automated Commit Recovery does not take an effect.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 73 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!