Palo Alto Panarama


Delivering a consistent security posture at scale

Shareability / Reusability


POND

Policy--Object--Network--Device


Capture on management interface

tcpdump filter "host 192.168.1.254"
view-pcap mgmt-pcap mgmt.pcap
scp export mgmt-pcap from mgmt.pcap to admin@192.168.1.1:/


 1. Concept

Basic deployment vs Distributed Deployment

Mode:
Panorama mode
Log Collector mode
Management only mode


2. Deployment

Select Thick Provision Lazy Zeroed as the disk format.


Wait for login prompt

Panorama login:


 2.1 Old Way: Register the Panorama Serial Number in CSP. 

For VM, Serial number is in the email:


In Support Portal Devices list, register received  Panorama Serial Number/Authcode, 

if VM doesn't have Internet connection, click the Action to download key, then in Panorama license page, click.
    Manually upload license key

if Panorama has Internet connection:
     1. VM only:
     Select 
Panorama>
Setup>
Management
 and edit the General Settings.
     Enter the Panorama 
Serial Number
 (included in the order fulfillment email) and click 
OK
.
     2. In license page, click
         Retrieve license keys from license server
—Panorama automatically retrieves and activates the firewall management license from the Panorama Update Server.


  • 2.2 New Eval with "Software NGFW Credits"
    • Request Eval

  • In received email, click Activate, will be redirected to CSP to create deployment profile.


 

  • Select Products > Software NGFW Credits and click the Details button on the credit pool you used to create your profile.
  •  On the far right, select the vertical ellipsis (More Options) and select Provision Panorama, and Provision, this will generate Panorama serial number and Auth-Code.
  • In newly installed Panorama, first time login will see.


 

             Ignore above, configure Panorama DNS then verify it can reach Internet.
             Panorama > Setup > Management, apply the serial number, it will connect to CSP and apply  license, relogin and retrieve license if needed.

 











https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/register-panorama-and-install-licenses/activateretrieve-a-firewall-management-license-on-the-panorama-virtual-appliance.html#id5fd6c4c0-1cc7-456d-a959-291b1726cda6



Add FW to Panorama:
1. Copy FW serial number, on Panorama > PANORAMA > Managed Device, click Add, paste FW serial number, Commit to Panorama.
2. On FW, Device > Setup > Panorama Settings, edit, input Panorama IP address, commit the change.















Add HA FW to Panorama:
 Clear 
Enable Config Sync
  On both FW

=======Panorama====


Template: Network, Device

Template Stack
    by default, template at the top take precedence

Each managed firewall can only be associated with one template stack (NOT template anymore), and one device group.

Allow Edit of Template Stacks, there by overriding default Template values

Template variable name starts with $

variables are case-sensitive

variable is defined and set initial value in either Template or Template Stack level, initial value can be override in template stack, to setup individual value for each FW stack, Export and Import Variable CSV.

Variable can also be overridden at device level: Manager Deices > Summary > "firewall" > Variable column > Edit. But not recommended.

On firewall, panorama pushed settings shows Read-Only, but can be override.


Device Group : Policies, Objects  - FW belongs to a single device group

Global shared group contains device group

Device groups are in hierarchy, children group inherits settings from parent; Templates are independent settings, Template Stack combines them together, and resolve conflict by templates order.

 By default, Panorama will use the value in the lowest group in the hierarchy


When you make changes to a firewall in an HA pair, Panorama sends the appropriate changes to each firewall separately. This operation is different from how redundant firewall pairs operate without Panorama.

You might have an item that you do not want modified for any reason in any descendant device groups. If you check the box for Disable override on the element itself 

This behavior is different from the behavior in templates. You can modify an element directly on a managed firewall when that element has been pushed down through a template from Panorama. You cannot modify an object directly on a managed firewall when that object has been pushed down through a device group from Panorama.


Policies

Pre Rules
Post Rules
Default Rules


Deploy order: Local rule takes precedence, but can be change to Shared group take precedency. 

shared group
device group
local config


no local device edit of shared object and policy

shared pre policy
device group pre policy
local FW policy
device group post policy
shared post policy 

combined rules preview.

yellowdot =override

Context - switch between global to individual device 

commit - Panorama|
push     - device


Troubleshooting

1. on Panorama:
    show devices all

2. on firewall:
    show panorama-status


========

admin@panorama> request system system-mode panorama
Server error : Failed to change system mode from management-only to panorama.
Please add a new virtual logging disk with more than 50.00 GB of storage capacity to support panorama mode.


Not enough RAM: Found 7.78 GB, need 16.0 GB to support panorama mode.


Not enough CPU cores: Found 4 cores, need 8 cores to support panorama mode


disconnect issue

By default, Panorama and firewalls use predefined (factory/PAN-OS built-in) certificates to set up that management SSL/TLS tunnel, not visibla in GUI Panorama > Certificate Management > Certificate

Panorama acts as the SSL server, the firewall acts as the client, and each presents a certificate to the other.

 Server certificate (Panorama's): predefined cert whose Common Name is the IP or FQDN of the Panorama management interface.

Client certificate (firewall's): predefined cert whose Common Name is the firewall's serial number.

Both chain up to a common, Palo Alto Networks–issued self-signed root CA that ships pre-deployed on both platforms.

You can check which mode is in use under Panorama > Managed Devices > Summary — it shows the certificate status as either "predefined" or, if you've switched to custom certs, "Deployed".

SC3 (Secure Connection v3) subsystem — the mechanism introduced in PAN-OS 10.1+ that handles the mutual-cert handshake between Panorama and a managed firewall

cfg.ms.ca is the config-database node that's supposed to hold the CA name of the client certificate currently in use for that connection.

show system state | match cfg.ms.ca shows the Common Name of the CA certificate signing the client certificate, either on the firewall or Panorama. 

Panorama> show system state | match cfg.ms.ca

cfg.ms.ca: 12bfda38-7e96-4927-8683-1a3398c79844


VM-FW2> show system state | match cfg.ms.ca

cfg.ms.ca: 12bfda38-7e96-4927-8683-1a3398c79844


When that node "does not exist," it simply means no device certificate/CA has been issued or registered yet for that connection — so SC3 can't build the SNI (Secure Name Indication) or CCN it needs to complete the handshake. 

VM-FW2> show system state | match cfg.ms

cfg.ms.csr: bb3c7446-e674-46e6-b36b-2482b0046ffa

means: the firewall generated a Certificate Signing Request (CSR) and sent it to Panorama, but never got the signed certificate back. Registration started but never completed — it's stuck mid-handshake.

Fix — clear the stuck CSR state and re-register cleanly:


On the firewall

request sc3 reset

debug software restart process management-server


Check firewall's own configd.log

tail follow yes mp-log configd.log


Warning: sc3_sendRegInfo(sc3_register.c:425): SC3R: AK not present.

Error: pan_cfg_get_cms_msg(pan_cfg_mgr.c:47047): SC3: reg - authkey needed, but missing


If re-enter auth-key in GUI doesn't work, try cli:


request authkey set <auth-key-string>



Resource List

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMjGCAW

Comments