48
4 • Panorama 7.0 Administrator’s Guide
© Palo Alto Networks, Inc.
Table of Contents
Install Content and Software Updates for Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .59
Panorama, Log Collector, and Firewall Version Compatibility . . . . . . . . . . . . . . . . . . . . . . . .59
Install Updates for Panorama with HA Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .59
Install Updates for Panorama with Internet Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . .60
Install Updates for Panorama without Internet Connection. . . . . . . . . . . . . . . . . . . . . . . . . .63
Transition to a Different Panorama Platform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .67
Migrate from a Panorama Virtual Appliance to an M‐Series Appliance . . . . . . . . . . . . . . . .67
Migrate from an M‐100 Appliance to an M‐500 Appliance . . . . . . . . . . . . . . . . . . . . . . . . . .70
Access and Navigate Panorama Management Interfaces. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .73
Log in to the Panorama Web Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .73
Navigate the Panorama Web Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .73
Log in to the Panorama CLI. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .74
Set Up Administrative Access to Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .76
Configure an Admin Role Profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .76
Configure an Access Domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .76
Configure Administrative Accounts and Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . .77
Configure an Administrative Account. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .77
Configure an Administrator with Kerberos SSO, External, or Local Authentication. . . . . .78
Configure an Administrator with Certificate‐Based Authentication for the Web Interface .
79
Configure an Administrator with SSH Key‐Based Authentication for the CLI. . . . . . . . . . .80
Configure RADIUS Vendor‐Specific Attributes for Administrator Authentication . . . . . . .81
Manage Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .83
Add a Firewall as a Managed Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .84
Manage Device Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .85
Add a Device Group. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .85
Create a Device Group Hierarchy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .86
Create Objects for Use in Shared or Device Group Policy . . . . . . . . . . . . . . . . . . . . . . . . . . .87
Revert to Inherited Object Values. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .89
Manage Unused Shared Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .89
Manage Precedence of Inherited Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .90
Move or Clone a Policy Rule or Object to a Different Device Group . . . . . . . . . . . . . . . . . .90
Select a URL Filtering Vendor on Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .91
Push a Policy Rule to a Subset of Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .95
Manage the Rule Hierarchy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .96
Manage Templates and Template Stacks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98
Template Capabilities and Exceptions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98
Add a Template. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98
Configure a Template Stack . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .100
Override a Template Setting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .101
Disable/Remove Template Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .102
Transition a Firewall to Panorama Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .103
Plan the Transition to Panorama Management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .103
Migrate a Firewall to Panorama Management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .104
Load a Partial Firewall Configuration into Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .107
44
© Palo Alto Networks, Inc.
Panorama 7.0 Administrator’s Guide • 5
Table of Contents
Use Case: Configure Firewalls Using Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .110
Device Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .110
Templates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .111
Set Up Your Centralized Configuration and Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .112
Manage Log Collection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .119
Configure a Managed Collector . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .120
Manage Collector Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .123
Configure a Collector Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .123
Move a Log Collector to a Different Collector Group. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .126
Remove a Firewall from a Collector Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .128
Configure Log Forwarding to Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .129
Verify Log Forwarding to Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .131
Modify Log Forwarding and Buffering Defaults. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .132
Configure Log Forwarding from Panorama to External Destinations. . . . . . . . . . . . . . . . . . . . .134
Log Collection Deployments. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .136
Plan a Log Collection Deployment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .136
Deploy Panorama with Dedicated Log Collectors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .138
Deploy Panorama with Default Log Collectors. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .143
Deploy Panorama Virtual Appliances with Local Log Collection. . . . . . . . . . . . . . . . . . . . .149
Manage Licenses and Updates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .151
Manage Licenses on Firewalls Using Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .152
Deploy Updates to Firewalls and Log Collectors Using Panorama. . . . . . . . . . . . . . . . . . . . . . .153
Supported Updates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .153
Schedule a Content Update Using Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .154
Deploy an Update to Log Collectors when Panorama is Internet‐connected. . . . . . . . . .154
Deploy an Update to Log Collectors when Panorama is not Internet‐connected . . . . . .156
Deploy an Update to Firewalls when Panorama is Internet‐connected. . . . . . . . . . . . . . .158
Deploy an Update to Firewalls when Panorama is not Internet‐connected . . . . . . . . . . .159
Monitor Network Activity. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .163
Use Panorama for Visibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .164
Monitor the Network with the ACC and AppScope . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .164
Analyze Log Data. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .166
Generate, Schedule, and Email Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .167
Use Case: Monitor Applications Using Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .170
Use Case: Respond to an Incident Using Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .174
Incident Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .174
Review the Widgets in the ACC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .175
Review Threat Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .176
Review WildFire Logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .177
Review Data Filtering Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .178
Update Security Rules. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .178
44
6 • Panorama 7.0 Administrator’s Guide
© Palo Alto Networks, Inc.
Table of Contents
Panorama High Availability. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181
Panorama HA Prerequisites. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .182
Priority and Failover on Panorama in HA. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .183
Failover Triggers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .185
HA Heartbeat Polling and Hello Messages. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .185
HA Path Monitoring. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .185
Logging Considerations in Panorama HA. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .187
Logging Failover on a Panorama Virtual Appliance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .187
Logging Failover on an M‐Series Appliance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .187
Synchronization Between Panorama HA Peers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .189
Manage a Panorama HA Pair. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .190
Set Up HA on Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .190
Test Panorama HA Failover . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .192
Switch Priority after Panorama Failover to Resume NFS Logging. . . . . . . . . . . . . . . . . . . .192
Restore the Primary Panorama to the Active State . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .193
Administer Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195
Manage Configuration Backups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .196
Schedule Export of Configuration Files. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .196
Manage Panorama and Firewall Configuration Backups . . . . . . . . . . . . . . . . . . . . . . . . . . . .197
Configure the Number of Configuration Backups Panorama Stores. . . . . . . . . . . . . . . . . .198
Load a Configuration Backup on a Managed Firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .199
Compare Changes in Panorama Configurations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .200
Validate a Panorama Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .201
Restrict Access to Configuration Changes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .202
Types of Locks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .202
Locations for Taking a Lock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .202
Take a Lock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .203
View Lock Holders . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .203
Enable Automatic Acquisition of the Commit Lock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .203
Remove a Lock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .204
Add Custom Logos to Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .205
View Panorama Task Completion History. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .206
Manage Storage Quotas and Expiration Periods for Logs and Reports . . . . . . . . . . . . . . . . . . .207
Log and Report Storage. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .207
Log and Report Expiration Periods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .207
Configure Storage Quotas and Expiration Periods for Logs and Reports. . . . . . . . . . . . . .208
Monitor Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .210
Panorama System and Configuration Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .210
Monitor Panorama and Log Collector Statistics Using SNMP . . . . . . . . . . . . . . . . . . . . . . .211
Reboot or Shut Down Panorama. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .213
Configure Panorama Password Profiles and Complexity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .214
28
© Palo Alto Networks, Inc.
Panorama 7.0 Administrator’s Guide • 7
Table of Contents
Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .217
Troubleshoot Panorama System Issues. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .218
Generate Diagnostic Files for Panorama . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .218
Diagnose Panorama Suspended State . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .218
Monitor the File System Integrity Check. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .218
Manage Panorama Storage for Software and Content Updates . . . . . . . . . . . . . . . . . . . . .219
Recover from Split Brain in Panorama HA Deployments . . . . . . . . . . . . . . . . . . . . . . . . . . .219
Troubleshoot Log Storage and Connection Issues. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .221
Verify Panorama Port Usage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .221
Resolve Zero Log Storage for a Collector Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .222
Replace a Failed Disk on an M‐Series Appliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .222
Replace the Virtual Disk on a Panorama ESXi Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .223
Replace the Virtual Disk on vCloud Air . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .223
Migrate Logs to a New M‐Series Appliance in Log Collector Mode . . . . . . . . . . . . . . . . . .224
Migrate Logs to a New M‐Series Appliance in Panorama Mode. . . . . . . . . . . . . . . . . . . . .228
Recover Logs after Panorama Failure/RMA in Non‐HA Deployments. . . . . . . . . . . . . . . .233
Regenerate Metadata for M‐Series Appliance RAID Pairs . . . . . . . . . . . . . . . . . . . . . . . . . .235
Replace an RMA Firewall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .237
Partial Device State Generation for Firewalls. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .237
Before Starting RMA Firewall Replacement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .237
Restore the Firewall Configuration after Replacement. . . . . . . . . . . . . . . . . . . . . . . . . . . . .239
Troubleshoot Commit Failures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .241
Troubleshoot Registration or Serial Number Errors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .242
Troubleshoot Reporting Errors. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .243
View Task Success or Failure Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .244
3
8 • Panorama 7.0 Administrator’s Guide
© Palo Alto Networks, Inc.
Table of Contents
26
© Palo Alto Networks, Inc.
Panorama 7.0 Administrator’s Guide • 9
Panorama Overview
Panorama provides centralized monitoring and management of multiple Palo Alto Networks next‐generation
firewalls. It provides a single location from which you can oversee all applications, users, and content
traversing your network, and then use this knowledge to create application enablement policies that protect
and control the network. Using Panorama for centralized policy and device management increases
operational efficiency in managing and maintaining a distributed network of firewalls.
About Panorama
Panorama Platforms
Centralized Configuration and Deployment Management
Centralized Logging and Reporting
Panorama Commit Operations
Role‐Based Access Control
Panorama Recommended Deployments
Plan Your Deployment
Deploy Panorama: Task Overview
28
10 • Panorama 7.0 Administrator’s Guide
© Palo Alto Networks, Inc.
About Panorama
Panorama Overview
About Panorama
Panorama provides centralized management of Palo Alto Networks next‐generation firewalls, as the
following figure illustrates:
Panorama allows you to effectively configure, manage, and monitor your Palo Alto Networks firewalls using
central oversight with local control, as required. The three focal areas in which Panorama adds value are:
Centralized configuration and deployment—To simplify central management and rapid deployment of
the firewalls on your network, use Panorama to pre‐stage the firewalls for deployment. You can then
assemble the firewalls into groups, and create templates to apply a base network and device
configuration and use device groups to administer globally shared and local policy rules. See Centralized
Configuration and Deployment Management.
Aggregated logging with central oversight for analysis and reporting—Collect information on activity
across all the managed firewalls on the network and centrally analyze, investigate and report on the data.
This comprehensive view of network traffic, user activity, and the associated risks empowers you to
respond to potential threats using the rich set of policies to securely enable applications on your network.
See Centralized Logging and Reporting.
Distributed administration—Allows you to delegate or restrict access to global and local firewall
configurations and policies. See Role‐Based Access Control for delegating appropriate levels of access for
distributed administration.
Panorama is available in two platforms: as a virtual appliance and as a dedicated hardware appliance. For
more information, see Panorama Platforms.
Documents you may be interested
Documents you may be interested