Professional Documents
Culture Documents
Best Practices For Managing Firewalls With Panorama
Best Practices For Managing Firewalls With Panorama
with Panorama
10.1
docs.paloaltonetworks.com
Contact Informaon
Corporate Headquarters:
Palo Alto Networks
3000 Tannery Way
Santa Clara, CA 95054
www.paloaltonetworks.com/company/contact-support.html
Copyright
Palo Alto Networks, Inc.
www.paloaltonetworks.com
©2021 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto
Networks. A list of our trademarks can be found at www.paloaltonetworks.com/company/
trademarks.html. All other marks menoned herein may be trademarks of their respecve
companies.
Last Revised
May 19, 2021
Best Pracces for Managing Firewalls with Panorama Version 2 ©2021 Palo Alto Networks, Inc.
10.1
Table of Contents
Best Pracces to Add Firewalls to Panorama............................................. 5
Use Case - Onboarding New Next-Generaon Firewalls to Panorama.......................... 6
Use Case - Migrate Your Next-Generaon Firewalls to Panorama..................................7
Best Pracces for Managing Firewalls with Panorama Version 3 ©2021 Palo Alto Networks, Inc.
10.1
Table of Contents
Best Pracces for Managing Firewalls with Panorama Version 4 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces to Add Firewalls to
Panorama
The Panorama™ management server is the Palo Alto Networks network security
management soluon for centralized management and visibility for your next-
generaon firewalls. This document covers the best pracces for onboarding new
firewalls or migrang exisng firewalls to Panorama to simplify and streamline this
operaon.
5
Best Pracces to Add Firewalls to Panorama
STEP 2 | Enable Auto Push on 1st Connect and configure the To SW Version to automacally push
the device group and template stack configuraons to your managed firewalls when they
first successfully connect to Panorama and upgrade your managed firewalls to a specified
PAN-OS version of your choosing. This includes automacally installing all required content
updates for each PAN-OS version in the PAN-OS upgrade path.
If you are imporng all your new firewalls to Panorama in a CSV file, enable Auto Push
on 1st Connect and configure the To SW Version in the CSV file to streamline the import
process.
When implemenng role-based access control, leverage device group and template admins
to add firewalls to device groups and templates within their access domain rather than
enabling superuser privileges for all Panorama admins.
STEP 3 | Aer you successfully add your firewalls to Panorama, create and apply tags to make your
managed firewalls easier to search and filter. This helps you keep your managed firewalls
organized as the number of firewalls you manage using Panorama grows.
STEP 4 | If you are deploying firewalls in remote sites with lile to no IT staff, set up Zero Touch
Provisioning (ZTP) to streamline inial firewall deployment by automang new managed
firewall onboarding without the need for network or IT administrators at the remote site.
Best Pracces for Managing Firewalls with Panorama Version 6 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces to Add Firewalls to Panorama
STEP 2 | When you migrate a firewall to Panorama management, enable import devices’ shared
objects into Panorama’s shared context to avoid duplicang idencal configuraon objects.
STEP 3 | Aer a successful migraon, review the Policies to idenfy any duplicate rules. Delete one of
each duplicate rule before you Commit to Panorama to avoid commit errors.
STEP 4 | When you Export or push device config bundle to your managed firewalls, enable Merge
with Candidate Config, Include Device and Network Templates, and Force Template Values
to force a commit for any pending local changes on the firewall, include all device groups
and templates in the push, and delete any local configuraons not present in a device group
or template on Panorama. This ensures a baseline configuraon managed by Panorama is
pushed to all firewalls migrated to Panorama.
STEP 5 | Perform your post-migraon tests to verify that the migraon is successful and that
everything is working as intended. Over me, opmize the configuraon as needed. Use
migraon tools like Expedion the to periodically asses your configuraon hygiene by
removing any unused or duplicate objects and the Policy Opmizer to opmize your Security
policy rulebase.
Best Pracces for Managing Firewalls with Panorama Version 7 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces to Add Firewalls to Panorama
Best Pracces for Managing Firewalls with Panorama Version 8 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Firewall
Configuraon Management on
Panorama
Firewalls have two types of configuraons—security and network. Panorama uses
device groups to manage the security configuraons such as objects and policy rules
and templates and template stacks to manage the network configuraons.
9
Best Pracces for Firewall Configuraon Management on Panorama
Best Pracces for Managing Firewalls with Panorama Version 10 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Firewall Configuraon Management on Panorama
Best Pracces for Managing Firewalls with Panorama Version 11 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Firewall Configuraon Management on Panorama
Best Pracces for Managing Firewalls with Panorama Version 12 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Configuraon
Change Management
Manage the configuraon changes your administrators can make by leveraging role-
based access control (RBAC) and segmenng access to managed firewalls, ulizing
dynamic structures, such as External Dynamic Lists (EDL) and Dynamic User Groups
(DAG), to keep policy rules up to date, and leveraging granular control over what
configuraon changes administrators can commit and push to managed firewalls.
13
Best Pracces for Configuraon Change Management
Best Pracces for Managing Firewalls with Panorama Version 14 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Configuraon Change Management
Best Pracces for Managing Firewalls with Panorama Version 15 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Configuraon Change Management
Best Pracces for Managing Firewalls with Panorama Version 16 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Configuraon Change Management
Best Pracces for Managing Firewalls with Panorama Version 17 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Configuraon Change Management
Best Pracces for Managing Firewalls with Panorama Version 18 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Monitoring and
Visibility on Panorama
Design your logging infrastructure for opmal log ingeson and storage based on your
organizaonal requirement. Then, leverage the Applicaon Command Center (ACC),
PDF Summary reports, and custom reports to idenfy network acvity and threats
that need to be invesgated and resolved.
19
Best Pracces for Monitoring and Visibility on Panorama
Best Pracces for Managing Firewalls with Panorama Version 20 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Monitoring and Visibility on Panorama
Best Pracces for Managing Firewalls with Panorama Version 21 ©2021 Palo Alto Networks, Inc.
10.1
Best Pracces for Monitoring and Visibility on Panorama
Best Pracces for Managing Firewalls with Panorama Version 22 ©2021 Palo Alto Networks, Inc.
10.1