Hi @chens ,
Great question! Adding a locally managed NGFW to Panorama is tricky. You have to do it a few times to get used to it. Here are the steps:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management
However, in the long run, it will be worth it because you can change something once and push it to your NGFWs. Here are some pointers:
The HA pair document has extra steps. Be sure to go through those. My step #s below refer to the top URL.
When you import the device configuration, it will create a new device group and template.
Uncheck "Import devices's shared objects into Panorama's shared context (device group specific objects will be created if unique)" if you have LOTS of objects. Otherwise you can get conflicts and commit errors. You can move your objects to the Shared device group and resolve duplicates after the NGFWs are imported.
I usually import my rules into the Post Rulebase.
Do not make any changes to the device group or template until after you are finished with these steps.
You can always rename the device group and/or template any time. Don't worry about it for now.
Step 5 is very important! (Step 4 on the HA doc.). Do not do the 1st push from the Commit menu. Push & Commit from the Panorama > Setup > Operations > Export or push device config bundle menu. This step deletes the local policies and objects so that you will not have duplicate object commit errors. After this step, push normally.
Finally, the top URL document above is not complete! (The HA one has this step.). If you want to managed the Network and Device configuration from Panorama, select Force Template Values in step 6.
This will override IP addresses, etc. So, make sure you have automated commit recovery enabled so that if the NGFW cannot communicate with Panorama it revert the configuration. This is critical if the NGFW is at a remote location.
Like step 5, this only needs to be done once.
Try it out!
Thanks,
Tom
... View more