PaloAlto Networks Panorama 6.1 Service manual

Panorama™
Administrator’s
Guide
Version6.1

2•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
ContactInformation
CorporateHeadquarters:
PaloAltoNetworks
4401GreatAmericaParkway
SantaClara,CA95054
www.paloaltonetworks.com/company/contact‐support
AboutthisGuide
ThisguidedescribeshowtosetupandusePanorama™forcentralizedmanagement;itisintendedforadministrators
whowantthebasicframeworktoquicklysetupthePanoramavirtualapplianceortheM‐100appliancefor
centralizedadministrationofPaloAltoNetworksfirewalls.
IfyouhaveanM‐100appliance,thisguidetakesoverafteryoufinishrackmountingyourM‐100appliance.
Formoreinformation,refertothefollowingsources:
ForinformationonhowtoconfigureothercomponentsinthePaloAltoNetworksNext‐GenerationSecurity
Platform,gototheTechnicalDocumentationportal:https://www.paloaltonetworks.com/documentationor
searchthedocumentation.
Foraccesstotheknowledgebase,completedocumentationset,discussionforums,andvideos,referto
https://live.paloaltonetworks.com.
Forcontactingsupport,forinformationonsupportprograms,tomanageyouraccountordevices,ortoopena
supportcase,refertohttps://www.paloaltonetworks.com/support/tabs/overview.html.
ForthemostcurrentPAN‐OSandPanorama6.1releasenotes,goto
https://www.paloaltonetworks.com/documentation/61/pan‐os/pan‐os‐release‐notes.html.
Toprovidefeedbackonthedocumentation,pleasewritetousat:[email protected].
PaloAltoNetworks,Inc.
www.paloaltonetworks.com
©2014–2017PaloAltoNetworks,Inc.PaloAltoNetworksisaregisteredtrademarkofPaloAltoNetworks.Alistofourtrademarkscanbe
foundat
https://www.paloaltonetworks.com/company/trademarks.html
.Allothermarksmentionedhereinmaybetrademarksof
theirrespectivecompanies.
RevisionDate:June27,2017

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•3
TableofContents
PanoramaOverview...................................................9
AboutPanorama..................................................................10
PanoramaPlatforms...............................................................11
CentralizedConfigurationandDeploymentManagement...............................12
ContextSwitch—FirewallorPanorama ...........................................12
Templates ....................................................................12
DeviceGroups ................................................................13
CentralizedLoggingandReporting ..................................................16
LoggingOptions ...............................................................16
ManagedCollectorsandCollectorGroups........................................17
CaveatsforaCollectorGroupwithMultipleLogCollectors .........................17
CentralizedReporting..........................................................19
PanoramaCommitOperations......................................................20
Role‐BasedAccessControl.........................................................22
AdministrativeRoles...........................................................22
AuthenticationProfilesandSequences...........................................23
AccessDomains ...............................................................24
AdministrativeAuthentication ...................................................24
PanoramaRecommendedDeployments ..............................................25
PanoramaforCentralizedManagementandReporting .............................25
PanoramainaDistributedLogCollectionDeployment .............................26
PlanYourDeployment .............................................................27
DeployPanorama:TaskOverview ...................................................29
SetUpPanorama....................................................31
DeterminePanoramaLogStorageRequirements......................................32
SetUpthePanoramaVirtualAppliance ..............................................34
SetupPrerequisitesforthePanoramaVirtualAppliance ............................34
InstallPanoramaontheESX(i)Server.............................................35
PerformInitialConfigurationofthePanoramaVirtualAppliance .....................36
ExpandLogStorageCapacityonthePanoramaVirtualAppliance ....................38
IncreaseCPUsandMemoryonthePanoramaVirtualAppliance.....................40
CompletethePanoramaVirtualApplianceSetup ..................................41
SetUptheM‐100Appliance........................................................42
PerformInitialConfigurationoftheM‐100Appliance..............................43
SetuptheM‐100ApplianceasaLogCollector ....................................46
IncreaseStorageontheM‐100Appliance ........................................50
MigratefromaPanoramaVirtualAppliancetoanM‐100Appliance......................52
PrerequisitesforMigratingtoanM‐100Appliance.................................52
PlantoMigratetoanM‐100Appliance...........................................52
MigratetoanM‐100Appliance .................................................53
ResumeFirewallManagementafterMigratingtoanM‐100Appliance................54

4•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents
RegisterPanoramaandInstallLicenses...............................................56
RegisterPanorama.............................................................56
ActivateaPanoramaSupportLicense.............................................57
Activate/RetrieveaDeviceManagementLicenseonthePanoramaVirtualAppliance ...57
Activate/RetrieveaDeviceManagementLicenseontheM‐100Appliance ............58
InstallContentandSoftwareUpdatesforPanorama ...................................60
Panorama,LogCollector,andFirewallVersionCompatibility ........................60
InstallUpdatesforPanoramainanHAConfiguration ...............................61
InstallUpdatesforPanoramawithanInternetConnection ..........................62
InstallUpdatesforPanoramawithoutanInternetConnection .......................66
AccessandNavigatePanoramaManagementInterfaces ................................70
LogintothePanoramaWebInterface ............................................70
NavigatethePanoramaWebInterface............................................70
LogintothePanoramaCLI......................................................71
SetUpAdministrativeAccesstoPanorama ...........................................73
CreateanAdministrativeAccount ................................................73
DefineanAccessDomain .......................................................75
CreateanAuthenticationProfile.................................................75
DefineanAuthenticationSequence..............................................76
ConfigureAdministrativeAuthentication..........................................77
ManageFirewalls ....................................................83
AddaFirewallasaManagedDevice .................................................84
ManageDeviceGroups.............................................................85
AddaDeviceGroup ............................................................85
CreateObjectsforUseinSharedorDeviceGroupPolicy ...........................86
ManageSharedObjects.........................................................87
SelectaURLFilteringVendoronPanorama .......................................88
PushaPolicytoaSubsetofFirewalls .............................................89
ManagetheRuleHierarchy .....................................................90
ManageTemplates.................................................................93
TemplateCapabilitiesandExceptions.............................................93
AddaTemplate ................................................................94
OverrideaTemplateSetting.....................................................96
Disable/RemoveTemplateSettings ..............................................97
TransitionaFirewalltoPanoramaManagement .......................................98
UseCase:ConfigureFirewallsUsingPanorama ........................................99
DeviceGroups.................................................................99
Templates....................................................................100
SetUpYourCentralizedConfigurationandPolicies ...............................101
ManageLogCollection .............................................107
EnableLogForwardingtoPanorama................................................108
LogForwardingtoPanorama:WorkflowsbyLogType.............................108
ConfigureLogForwardingtoPanorama..........................................109
ConfigureaManagedCollector.....................................................113

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•5
TableofContents
ManageCollectorGroups ......................................................... 117
ConfigureaCollectorGroup ................................................... 117
MoveaLogCollectortoaDifferentCollectorGroup .............................. 120
RemoveaFirewallfromaCollectorGroup....................................... 121
VerifyLogForwardingtoPanorama ................................................ 122
ModifyLogForwardingandBufferingDefaults....................................... 123
EnableLogForwardingfromPanoramatoExternalDestinations ....................... 125
LogCollectionDeployments ....................................................... 128
PlanaLogCollectionDeployment .............................................. 128
DeployPanoramawithDedicatedLogCollectors................................. 131
DeployPanoramawithDefaultLogCollectors.................................... 137
DeployPanoramaVirtualApplianceswithLocalLogCollection ..................... 144
ManageLicensesandUpdates........................................147
ManageLicensesonFirewallsUsingPanorama....................................... 148
DeployUpdatestoDevicesUsingPanorama ......................................... 149
SupportedUpdatesbyDeviceType ............................................. 149
ScheduleContentUpdatestoDevicesUsingPanorama............................ 149
DeployUpdatestoDeviceswhenPanoramaHasanInternetConnection ............ 151
DeployUpdatestoDeviceswhenPanoramaHasNoInternetConnection ........... 154
MonitorNetworkActivity............................................159
UsePanoramaforVisibility........................................................ 160
MonitortheNetworkwiththeACCandAppScope ............................... 160
AnalyzeLogData ............................................................. 162
Generate,Schedule,andEmailReports.......................................... 162
UseCase:MonitorApplicationsUsingPanorama..................................... 166
UseCase:RespondtoanIncidentUsingPanorama................................... 170
IncidentNotification.......................................................... 170
ReviewThreatLogs ........................................................... 171
ReviewWildFireLogs......................................................... 172
ReviewDataFilteringLogs..................................................... 173
UpdateSecurityPolicies ....................................................... 173
PanoramaHighAvailability...........................................175
PanoramaHAPrerequisites........................................................ 176
PriorityandFailoveronPanoramainHA ............................................ 177
FailoverTriggers ................................................................. 179
HAHeartbeatPollingandHelloMessages....................................... 179
HAPathMonitoring........................................................... 179
LoggingConsiderationsinPanoramaHA ............................................ 181
LoggingFailoveronaPanoramaVirtualAppliance ................................ 181
LoggingFailoveronanM‐100Appliance ........................................ 181
SynchronizationBetweenPanoramaHAPeers ....................................... 183

6•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents
ManageaPanoramaHAPair .......................................................184
SetUpHAonPanorama.......................................................184
TestPanoramaHAFailover ....................................................186
SwitchPriorityafterPanoramaFailovertoResumeNFSLogging ....................186
RestorethePrimaryPanoramatotheActiveState ................................187
AdministerPanorama...............................................189
ManageConfigurationBackups.....................................................190
ScheduleExportofConfigurationFiles...........................................190
ManagePanoramaConfigurationBackups .......................................191
ConfiguretheNumberofConfigurationBackupsPanoramaStores ..................192
LoadaConfigurationBackuponaManagedFirewall ..............................192
CompareChangesinPanoramaConfigurations .......................................194
RestrictAccesstoConfigurationChanges............................................195
TypesofLocks................................................................195
LocationsforTakingaLock ....................................................195
TakeaLock ..................................................................196
ViewLockHolders............................................................196
EnableAutomaticAcquisitionoftheCommitLock ................................196
RemoveaLock ...............................................................197
AddCustomLogostoPanorama ....................................................198
ViewPanoramaTaskCompletionHistory ............................................199
ReallocateLogStorageQuota ......................................................200
MonitorPanorama ................................................................202
PanoramaSystemandConfigurationLogs........................................202
SetUpEmailAlertsforPanorama...............................................203
SetUpSNMPtoMonitorPanorama .............................................204
RebootorShutDownPanorama....................................................208
GenerateDiagnosticFilesforPanorama.............................................209
ConfigurePanoramaPasswordProfilesandComplexity ...............................210
ReplaceaFailedDiskonanM‐100Appliance........................................212
ReplacetheVirtualDiskonaPanoramaVirtualAppliance .............................213
Troubleshooting ...................................................215
TroubleshootPanoramaSystemIssues..............................................216
DiagnosePanoramaSuspendedState............................................216
MonitortheFileSystemIntegrityCheck.........................................216
ManagePanoramaStorageforSoftwareandContentUpdates .....................216
RecoverfromSplitBraininPanoramaHADeployments............................217
TroubleshootLogStorageandConnectionIssues .....................................219
WhatPortsareUsedbyPanorama?.............................................219
ResolveZeroLogStorageforaCollectorGroup...................................220
RecoverLogsafterFailure/RMAofM‐100ApplianceinLogCollectorMode .........220
RecoverLogsafterFailure/RMAofM‐100ApplianceinPanoramaMode ............224
RecoverLogsafterPanoramaFailure/RMAinNon‐HADeployments ................229
RegenerateMetadataforM‐100ApplianceRAIDPairs............................231

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•7
TableofContents
ReplaceanRMAFirewall .......................................................... 233
PartialDeviceStateGenerationforFirewalls ..................................... 233
BeforeStartingRMAFirewallReplacement...................................... 233
RestoretheFirewallConfigurationafterReplacement ............................. 235
DiagnoseTemplateCommitFailures ................................................ 238
ViewTaskSuccessorFailureStatus ................................................ 239

8•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•9
PanoramaOverview
PanoramaprovidescentralizedmanagementandvisibilityofmultiplePaloAltoNetworksnext‐generation
firewalls.Itallowsyoutooverseeallapplications,users,andcontenttraversingthenetworkfromone
location,andthenusethisknowledgetocreateapplicationenablementpoliciesthatprotectandcontrolthe
entirenetwork.UsingPanoramaforcentralizedpolicyanddevicemanagementincreasesoperational
efficiencyinmanagingandmaintainingadistributednetworkoffirewalls.
ThefollowingsectionsdescribePanoramaandprovideguidelinesforplanningyourPanoramadeployment:
AboutPanorama
PanoramaPlatforms
CentralizedConfigurationandDeploymentManagement
CentralizedLoggingandReporting
PanoramaCommitOperations
Role‐BasedAccessControl
PanoramaRecommendedDeployments
PlanYourDeployment
DeployPanorama:TaskOverview

10•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
AboutPanorama PanoramaOverview
AboutPanorama
PanoramaprovidescentralizedmanagementofthePaloAltoNetworksnext‐generationfirewalls,asthe
followingfigureillustrates:
Panoramaallowsyoutoeffectivelyconfigure,manage,andmonitoryourPaloAltoNetworksfirewallsusing
centraloversightwithlocalcontrol,asrequired.ThethreefocalareasinwhichPanoramaaddsvalueare:
Centralizedconfigurationanddeployment—Tosimplifycentralmanagementandrapiddeploymentof
thefirewallsonyournetwork,usePanoramatopre‐stagethefirewallsfordeployment.Youcanthen
assemblethefirewallsintogroups,andcreatetemplatestoapplyabasenetworkanddevice
configurationandusedevicegroupstoadministergloballysharedandlocalpolicies.SeeCentralized
ConfigurationandDeploymentManagement.
Aggregatedloggingwithcentraloversightforanalysisandreporting—Collectinformationonactivity
acrossallthemanagedfirewallsonthenetworkandcentrallyanalyze,investigateandreportonthedata.
Thiscomprehensiveviewofnetworktraffic,useractivity,andtheassociatedrisksempowersyouto
respondtopotentialthreatsusingtherichsetofpoliciestosecurelyenableapplicationsonyournetwork.
SeeCentralizedLoggingandReporting.
Distributedadministration—Allowsyoutodelegateorrestrictaccesstoglobalandlocalfirewall
configurationsandpolicies.SeeRole‐BasedAccessControlfordelegatingappropriatelevelsofaccessfor
distributedadministration.
Panoramaisavailableintwoplatforms:asavirtualapplianceandasadedicatedhardwareappliance.For
moreinformation,seePanoramaPlatforms.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•11
PanoramaOverview PanoramaPlatforms
PanoramaPlatforms
Panoramaisavailableintwoplatforms,eachofwhichsupportsfirewallmanagementlicensesformanaging
upto25,100,or1,000firewalls:
Panoramavirtualappliance—ThePanoramavirtualapplianceisinstalledonaVMwareserver.Itallows
forasimpleinstallationandfacilitatesserverconsolidationforsitesthatneedavirtualmanagement
appliance.ItalsosupportsintegrationwithaNetworkFileSystem(NFS)forincreasedstorageand(>2TB)
logretentioncapabilities.
ThePanoramavirtualappliancebestsuitsenvironmentswithloggingratesofupto10,000logs/second.
M‐100appliance—Adedicatedhardwareapplianceintendedforlargescaledeployments.In
environmentswithhighloggingratesandlogretentionrequirements,thisplatformenablesscalingof
yourlogcollectioninfrastructure.TheappliancesupportsRAID1mirroringtoprotectagainstdisk
failures,andthedefaultconfigurationshipswithtwo1TBdrives;withadditionalRAIDpairs,theM‐100
appliancecansupportupto4TBoflogstorage.
TheM‐100applianceallowsforseparationofthecentralmanagementfunctionfromthelogcollection
functionbysupportingthefollowingdeploymentmodes:
– Panoramamode:Theapplianceperformsboththecentralmanagementandthelogcollection
functions.Thisisthedefaultmode.
–LogCollectormode:TheappliancefunctionsasadedicatedLogCollector,whicheitheranM‐100
applianceinPanoramamodeoraPanoramavirtualappliancecanmanage.
WhendeployedinLogCollectormode,theappliancedoesnothaveawebinterface;administrative
accessisCLIonly.However,youmanagetheapplianceusingthePanoramamanagementserver
(M‐100applianceinPanoramamodeoraPanoramavirtualappliance).CLIaccesstoanM‐100
applianceinLogCollectormodeisonlynecessaryforinitialsetupanddebugging.
Theplatformchoicedependsonyourneedforavirtualapplianceandyourlogcollectionrequirements(see
DeterminePanoramaLogStorageRequirements):
LogCollectionRate Platform
Upto10,000logs/second Panoramavirtualappliance
Upto30,000logs/second M‐100appliance

12•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedConfigurationandDeploymentManagement PanoramaOverview
CentralizedConfigurationandDeploymentManagement
PanoramausesDeviceGroupsandTemplatestogroupdevicesintosmallerandmorelogicalsetsthatrequire
similarconfiguration.Allconfigurationelements,policies,andobjectsonthemanagedfirewallscanbe
centrallymanagedonPanoramausingDeviceGroupsandTemplates.Inadditiontomanagingconfiguration
andpolicies,Panoramaenablesyoutocentrallymanagelicenses,softwareandassociatedcontentupdates:
SSL‐VPNclients,GlobalProtectagents,dynamiccontentupdates(Applications,Threats,WildFireand
Antivirus).
ContextSwitch—FirewallorPanorama
Templates
DeviceGroups
ContextSwitch—FirewallorPanorama
ThePanoramawebinterfaceallowsyoutotogglebetweenaPanorama‐centricviewandafirewall‐centric
viewusingthecontextswitch.YoucanchoosetomanagethefirewallcentrallyusingPanoramaandthen
switchcontexttoaspecificmanagedfirewalltoconfigurethefirewallusingthefirewalluserinterface.The
similarityoftheuserinterfaceonthemanagedfirewallsandPanoramaallowsyoutoseamlesslymove
betweentheinterfacestoadministerandmonitorthefirewallasrequired.
IfyouhaveconfiguredAccessDomainstorestrictadministrativeaccesstospecificmanagedfirewalls,the
Panoramauserinterfacedisplaysonlythefirewalls/featuresforwhichthelogged‐inadministratorhas
permissions.
Templates
Youusetemplatestoconfigurethesettingsthatmanagedfirewallsrequiretooperateonthenetwork.
TemplatesenableyoutodefineacommonbaseconfigurationusingtheNetworkandDevicetabson
Panorama.Forexample,youcanusetemplatestomanageinterfaceandzoneconfigurations,serverprofiles
forloggingandSNMPaccess,andnetworkprofilesforcontrollingaccesstozonesandIKEgateways.When
yougroupfirewallstodefineTemplatesettings,considergroupingfirewallsthatarealikeinhardwaremodel,
andrequireaccesstosimilarnetworkresources,suchasgatewaysandsyslogservers.
Usingtemplates,youcanpushalimitedcommonbaseconfigurationtoagroupoffirewallsandthen
configuretherestofthesettingsmanuallyonthefirewall.Alternatively,youcanpushalargercommonbase
configurationandthenoverridethetemplatesettingsonthefirewalltoaccommodatefirewall‐specific
changes.Whenyouoverrideasettingonthefirewall,thesettingissavedtothelocalconfigurationofthe
firewallandisnolongermanagedbythePanoramatemplate.Youcan,however,usePanoramatoforcethe
templateconfigurationontothefirewallorrestorethetemplatesettingsonthefirewall.Forexample,you
candefineacommonNTPserverinthetemplate,butoverridetheNTPserverconfigurationonthefirewall
toaccommodateforthelocaltimezoneonthefirewall.Ifyouthendecidetorestorethetemplatesettings,
youcaneasilyundoorrevertthelocalchangesthatyouimplementedonthefirewall.
TemplatescannotbeusedtodefineanoperationalstatechangesuchasFIPSmodeortoenablemulti‐vsys
modeonthefirewalls.Formoreinformation,seeTemplateCapabilitiesandExceptions.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•13
PanoramaOverview CentralizedConfigurationandDeploymentManagement
DeviceGroups
TousePanoramaeffectively,youmustgroupthefirewallsonyournetworkintologicalunitscalleddevice
groups.Adevicegroupallowsgroupingbasedonnetworksegmentation,geographiclocation,orbytheneed
toimplementsimilarpolicyconfigurations.Adevicegroupcanincludephysicalfirewalls,virtualfirewalls
and/oravirtualsystem.Bydefault,allmanageddevicesbelongtotheShareddevicegrouponPanorama.
DeviceGroupsenablecentralmanagementofpoliciesandobjectsusingthePoliciesandObjectstabson
Panorama.Objectsareconfigurationelementsthatarereferencedinpolicies.Someoftheobjectsthat
firewallpoliciesmakeuseofare:IPaddresses,URLcategories,securityprofiles,users,services,and
applications.
UsingDeviceGroupsyoucancreatesharedobjectsordevicegroup‐specificobjectsandthenusethese
objectstocreateahierarchyofrules(andrulebases)toenforcehowmanagedfirewallshandleinboundand
outboundtraffic.Forexample,acorporateacceptableusepolicycouldbedefinedasasetofsharedpolicies.
Then,toallowonlytheregionalofficestoaccesspeer‐to‐peertrafficsuchasBitTorrent,youcancreatea
securityruleasasharedpolicyandtargetittotheregionalofficesormakeitadevicegrouprulethatis
pushedtotheregionaloffices.SeeUseCase:ConfigureFirewallsUsingPanorama.
Policies
Objects
Policies
Devicegroupsprovideawaytoimplementalayeredapproachformanagingpoliciesacrossanetworkof
managedfirewalls.Thefollowingtableliststhepolicylayers,thefirewallstowhichthepoliciesapply,and
theplatformwhereyouadministerthepolicies:
Bothsharedpoliciesanddevicegroup‐specificpoliciesallowyoutocraftpre‐rulesandpost‐rulesto
centrallymanagealltherulebases:Security,NAT,QoS,PolicyBasedForwarding,Decryption,Application
Override,CaptivePortal,andDoSProtection.
Pre‐rules—RulesyouaddtothetopoftheruleorderandthatPAN‐OSevaluatesfirst.Youcanuse
pre‐rulestoenforcetheAcceptableUsePolicyforanorganization;forexample,toblockaccessto
specificURLcategories,ortoallowDNStrafficforallusers.Pre‐rulescanbesharedordevice
group‐specific.
Post‐rules—RulesthatPAN‐OSevaluatesafterthepre‐rulesandthelocalfirewallrules.Post‐rules
typicallyincluderulestodenyaccesstotrafficbasedontheApp‐ID,User‐ID,orService.Likepre‐rules,
postrulescanbesharedordevicegroup‐specific.
Policy Scope AdministrationPlatform
Shared Allthefirewallsinalldevicegroups. Panorama
Devicegroup‐specific Allthefirewallsassignedtoasingledevicegroup. Panorama
Local(firewall‐specific) Asinglefirewall.Firewall
Default(securityrules
only)
Bydefault,thedefaultrulesareshared(applytoallfirewallsin
alldevicegroups)andarepartofthepredefinedconfiguration.
However,ifyouedit(override)therules,theirscopechanges
tothelevelatwhichyouperformedtheedits:devicegroupor
local(firewall/virtualsystem).
PanoramaorFirewall

14•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedConfigurationandDeploymentManagement PanoramaOverview
Thepre‐rulesandpost‐rulesthatPanoramapushesarevisibleonthemanagedfirewallsbutonlyeditablein
Panorama.ThelocalfirewalladministratororaPanoramaadministratorwhoswitchestoalocalfirewall
contextcaneditlocalfirewallrules.
DefaultpoliciesapplyonlytotheSecurityrulebase.Thedefaultruleinterzone‐defaultspecifiesthatthe
firewalldeniesallinterzone(betweenzones)trafficthatdoesn’tmatchanotherrule.Thedefaultrule
intrazone‐defaultspecifiesthatthefirewallallowsallintrazone(withinazone)trafficthatdoesn’tmatch
anotherrule.WhenyoupreviewrulesinPanorama,thedefaultrulesappearbelowallotherrules.Initially
thedefaultrulesareread‐only,eitherbecausetheyarepartofthepredefinedconfigurationsettingsor
becausePanoramapushedthemtodevices.However,youcanoverridethesettingsfortags,action(allow
ordeny),logging,andsecurityprofiles.Thedevicecontextdeterminesthelevelatwhichyoucanedit
(override)defaultrules:
OnPanorama,youcaneditdefaultrulesthatarepartofthepredefinedconfiguration.Youcaneditrules
inadevicegrouporsharedcontext.
Onthefirewall,youcaneditdefaultrulesthatarepartofthepredefinedconfiguration,orpushedfrom
aPanoramasharedordevicegroupcontext.Thedefaultrulescanbevirtualsystem(vsys)specific.
Theorderofprecedencefordefaultrulesrunsfromthelowestcontexttothehighest:settingseditedatthe
firewallleveloverridesettingsatthedevicegrouplevel,whichoverridesettingsatthesharedlevel.
Theevaluationorder(fromtop‐firsttobottom‐last)ofallrulesis:
Whentrafficmatchesapolicyrule,thedefinedactionistriggeredandthefirewalldisregardsallsubsequent
policies.Thisabilitytolayerpoliciescreatesahierarchyofruleswherelocalpoliciesarebetweenthepre‐
andpost‐rules,andareeditablebyswitchingtothelocalfirewallcontext,orbyaccessingthefirewalllocally.
Thefirewallwebinterfacevisuallydemarcatesthiscascadeofrulesforeachdevicegroup(andmanaged
firewall),andprovidestheabilitytoscanthroughalargenumbersofrules.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•15
PanoramaOverview CentralizedConfigurationandDeploymentManagement
Fordetailsonrulemanagement,refertothePAN‐OSAdministrator’sGuide.
Objects
Objectsareconfigurationelementsthatarereferencedinpolicies.Someoftheobjectsthatfirewallpolicies
makeuseofare:IPaddresses,URLcategories,securityprofiles,users,services,andapplications.Because
objectscanbereusedacrosspolicies,creatingsharedobjectsordevicegroupobjectsreducesduplicationof
theseconfigurationelements.Forexample,creatingsharedaddressobjectsandaddressgroupsorshared
serviceobjectsandservicegroupsallowsyoutocreateoneinstanceoftheobjectandreferenceitinany
rulebasetomanagethefirewallsacrossmultipledevicegroups.Becausesharedobjectsaredefinedoncebut
usedmanytimes,theyreduceadministrativeoverhead,andmaintainconsistencyandaccuracyeverywhere
thesharedobjectisused.
Pre‐rules,post‐rulesandruleslocallydefinedonafirewallcanallusesharedobjectsanddevicegroup
objects.WhencreatinganobjectonPanorama,configurethebehaviorbasedonwhether:
Thedevicegroupobjecttakesprecedenceoverasharedobject,whenbothobjectshavethesamename.
Bydefault,theSharedObjectTakesPrecedenceoptionisdisabledonPanorama.Thisbehaviorensures
thatasharedobjectonlysupersedesadevicegroupobjectwiththesamenameifyouexplicitlywantthe
valueofasharedobjecttoprevail.Whenyouenabletheoptionforsharedobjectstotakeprecedence,
Panoramainformsyouofallthedevicegroupobjectsthatwillbeshadowed.However,ifadevicehasa
locallycreatedobjectwiththesamenameasasharedoradevicegroupobjectthatispushedfrom
Panorama,acommitfailurewilloccur.
AllsharedanddevicegroupobjectsthataredefinedonPanoramaarepushedtothemanageddevices.
Bydefault,allobjects—thosethatareandarenotreferencedinpolicies—arepushedtothemanaged
devices.

16•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedLoggingandReporting PanoramaOverview
CentralizedLoggingandReporting
Panoramaaggregatesdatafromallmanagedfirewallsandprovidesvisibilityacrossallthetrafficonthe
network.Italsoprovidesanaudittrailforallpolicymodificationsandconfigurationchangesmadetothe
managedfirewalls.Inadditiontoaggregatinglogs,PanoramacanaggregateandforwardSNMPtraps,email
notifications,andsyslogmessagestoanexternaldestination.
TheApplicationCommandCenter(ACC)onPanoramaprovidesasinglepaneforunifiedreportingacrossall
thefirewalls;itallowsyoutocentrallyanalyze,investigate,andreportonnetworktrafficandsecurity
incidents.OnPanorama,youcanviewlogsandgeneratereportsfromlogsforwardedtoPanoramaortothe
managedLogCollectors,ifconfigured,oryoucanquerythemanagedfirewallsdirectly.Forexample,youcan
generatereportsabouttraffic,threat,and/oruseractivityinthemanagednetworkbasedonlogsstoredon
Panorama(andthemanagedLogCollectors)orbyaccessingthelogsstoredlocallyonthemanagedfirewalls.
IfyouchoosenottoconfigurethemanagedfirewallstoforwardlogstoPanorama,youcanschedulereports
toberunoneachmanagedfirewallandforwardtheresultstoPanoramaforacombinedviewofuseractivity
andnetworktraffic.Althoughthisviewdoesnotprovidegranulardrill‐downonspecificdataandactivities,
itstillprovidesaunifiedreportingapproach.
LoggingOptions
ManagedCollectorsandCollectorGroups
CaveatsforaCollectorGroupwithMultipleLogCollectors
CentralizedReporting
LoggingOptions
BoththePanoramavirtualapplianceandM‐100appliancecancollectlogsthatthemanagedfirewalls
forward.YoucanthenconfigurePanoramatoforwardtheseaggregatedlogstoexternalservices(Syslog
server,emailserver,orSNMPtrapserver).Theloggingoptionsvaryoneachplatform.
PanoramaPlatform LoggingOptions
Virtualappliance Offersthreeloggingoptions:
•Usetheapproximately11GBofinternalstoragespaceallocatedforloggingassoonas
youinstallthevirtualappliance.
•Addavirtualdiskthatcansupportupto2TBofstorage.
•MountaNetworkFileSystem(NFS)datastoreinwhichyoucanconfigurethestorage
capacitythatisallocatedforlogging.
M‐100appliance Thedefaultshippingconfigurationincludes1TBdisksinaRAIDpair,whichyoucan
increaseto4TBRAIDstorage(seeIncreaseStorageontheM‐100Appliance).Whenthe
M‐100applianceisinPanoramamode,youcanenabletheRAIDdisksandusethesedisks
asthedefaultLogCollector.IfyouhaveM‐100applianceisinLogCollectormode
(dedicatedLogCollectors),youusePanoramatoassignfirewallstothededicatedLog
Collectors.InadeploymentwithmultiplededicatedLogCollectors,Panoramaqueriesall
managedLogCollectorstogenerateanaggregatedviewoftrafficandcohesivereports.
Foreasyscaling,beginwithasinglePanoramaandincrementallyadddedicatedLog
Collectorsasyourneedsexpand.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•17
PanoramaOverview CentralizedLoggingandReporting
ManagedCollectorsandCollectorGroups
ALogCollectorcanbelocaltoanM‐100applianceinPanoramamode(defaultLogCollector)orcanbean
M‐100applianceinLogCollectormode(dedicatedLogCollector).BecauseyouusePanoramatoconfigure
andmanageLogCollectors,theyarealsoknownasManagedCollectors.AnM‐100applianceinPanorama
modeoraPanoramavirtualappliancecanmanagededicatedLogCollectors.ToadministerdedicatedLog
CollectorsusingthePanoramawebinterface,youmustaddthemasManagedCollectors.Otherwise,
administrativeaccesstoadedicatedLogCollectorisonlyavailablethroughitsCLIusingthedefault
administrativeuser(admin)account.DedicatedLogCollectorsdonotsupportadditionaladministrativeuser
accounts.
ACollectorGroupis1to16managedcollectorsthatoperateasasinglelogicallogcollectionunit.Ifthe
groupcontainsdedicatedLogCollectors,thelogsareuniformlydistributedacrossallthedisksineachLog
CollectorandacrossallmembersintheCollectorGroup.Thisdistributionmaximizestheuseoftheavailable
storagespace.TomanageaLogCollector,youmustaddittoaCollectorGroup.PaloAltoNetworks
recommendsplacingonlyoneLogCollectorinaCollectorGroupunlessmorethan4TBofstoragespaceis
requiredinaCollectorGroup.Fordetails,seeCaveatsforaCollectorGroupwithMultipleLogCollectors.
TheCollectorGroupconfigurationspecifieswhichmanagedfirewallscansendlogstotheLogCollectorsin
thegroup.AfteryouconfiguretheLogCollectorsandenablethefirewallstoforwardlogs,eachfirewall
forwardsitslogstotheassignedLogCollector.
ManagedCollectorsandCollectorGroupsareintegraltoadistributedlogcollectiondeploymenton
Panorama.Adistributedlogcollectiondeploymentallowsforeasyscalabilityandincrementaladditionof
dedicatedLogCollectorsasyourloggingneedsgrow.TheM‐100applianceinPanoramamodecanlogtoits
defaultCollectorGroupandthenbeexpandedtoadistributedlogcollectiondeploymentwithoneormore
CollectorGroupsthatincludededicatedLogCollectors.
CaveatsforaCollectorGroupwithMultipleLogCollectors
AlthoughPaloAltoNetworksrecommendsplacingonlyoneLogCollectorinaCollectorGroup,ifyouhave
ascenariowhereyouneedmorethan4TBoflogstoragecapacityinaCollectorGroupfortherequiredlog
retentionperiod,youcanaddupto16LogCollectorstothegroup.Forexample,ifasinglemanagedfirewall
generates12TBoflogs,youwillrequireatleastthreeLogCollectorsintheCollectorGroupthatreceives
thoselogs.
IfaCollectorGroupcontainsmultipleLogCollectors,theavailablestoragespaceisusedasonelogicalunit
andthelogsareuniformlydistributedacrossalltheLogCollectorsintheCollectorGroup.Thelog
distributionisbasedonthediskcapacityoftheLogCollectors(whichrangesfrom1TBto4TB,depending
onthenumberofdiskpairs)andahashalgorithmthatdynamicallydecideswhichLogCollectorownsthe
logsandwritestodisk.AlthoughPanoramausesapreferencelisttoprioritizethelistofLogCollectorsto
whichamanagedfirewallcanforwardlogs,PanoramadoesnotnecessarilywritethelogstothefirstLog
Collectorspecifiedinthepreferencelist.Forexample,considerthefollowingpreferencelist:
IfyouusePanoramatomanagefirewallsrunningbothPAN‐OS5.0andaPAN‐OSversionearlier
than5.0,notethefollowingcompatibilityrequirements:
•OnlydevicesrunningPAN‐OSv5.0cansendlogstoadedicatedLogCollector.
•DevicesrunningPAN‐OSversionsearlierthan5.0canonlysendlogstoaPanoramavirtual
applianceortoanM‐100applianceinPanoramamode.

18•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedLoggingandReporting PanoramaOverview
Usingthislist,FW1willforwardlogstoL1,itsprimaryLogCollector,butthehashalgorithmcoulddetermine
thatthelogswillbewrittenonL2.IfL2becomesinaccessibleorhasachassisfailure,FW1willnotknow
aboutitsfailurebecauseitisstillabletoconnecttoL1,itsprimaryLogCollector.
InthecasewhereaCollectorGrouphasonlyoneLogCollectorandtheLogCollectorfails,thefirewallstores
thelogstoitsHDD/SSD(theavailablestoragespacevariesbyhardwaremodel),andresumesforwarding
logstotheLogCollectorwhereitleftoffbeforethefailureoccurredassoonasconnectivityisrestored.
WithmultipleLogCollectorsinaCollectorGroup,thefirewalldoesnotbufferlogstoitslocalstoragewhen
itcanconnecttoitsPrimaryLogCollector.Therefore,FW1willcontinuesendinglogstoL1.BecauseL2is
unavailable,thePrimaryLogCollectorL1buffersthelogstoitsHDD,whichhas10GBoflogspace.IfL2
remainsunavailableandthelogspendingforL2exceed10GB,L1willoverwritetheolderlogentriesto
continuelogging.Insuchanevent,lossoflogsisarisk.Therefore,PaloAltoNetworksrecommendsthe
followingmitigationsifusingmultipleLogCollectorsinaCollectorGroup:
ObtainanOn‐Site‐Spare(OSS)toenablepromptreplacementifaLogCollectorfailureoccurs.
InadditiontoforwardinglogstoPanorama,enableforwardingtoanexternalserviceasbackupstorage.
TheexternalservicecanbeaSyslogserver,emailserver,orSimpleNetworkManagementProtocol
(SNMP)trapserver.Fordetails,seeEnableLogForwardingtoPanorama.
ManagedFirewall LogForwardingPreferenceListDefinedonaCollectorGroup
FW1 L1,L2,L3
FW2 L4,L5,L6

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•19
PanoramaOverview CentralizedLoggingandReporting
CentralizedReporting
Panoramaaggregateslogsfromallmanagedfirewallsandenablesreportingontheaggregateddatafora
globalviewofapplicationuse,useractivity,andtrafficpatternsacrosstheentirenetworkinfrastructure.As
soonasthefirewallsareaddedtoPanorama,theACCcandisplayalltraffictraversingyournetwork.With
loggingenabled,clickingintoalogentryintheACCprovidesdirectaccesstogranulardetailsaboutthe
application.
Forgeneratingreports,Panoramausestwosources:thelocalPanoramadatabaseandtheremotefirewalls
thatitmanages.ThePanoramadatabasereferstothelocalstorageonPanoramathatisallocatedforstoring
bothsummarizedlogsandsomedetailedlogs.IfyouhaveaDistributedLogCollectiondeployment,the
PanoramadatabaseincludesthelocalstorageonPanoramaandallthemanagedLogCollectors.Panorama
summarizestheinformation—traffic,application,threat—collectedfromallmanagedfirewallsat15‐minute
intervals.UsingthelocalPanoramadatabaseallowsforfasterresponsetimes,however,ifyouprefertonot
forwardlogstoPanorama,Panoramacandirectlyaccesstheremotefirewallandrunreportsondatathatis
storedlocallyonthemanagedfirewalls.
Panoramaoffersmorethan40predefinedreportsthatcanbeusedasis,ortheycanbecustomizedby
combiningelementsofotherreportstogeneratecustomreportsandreportgroupsthatcanbesaved.
Reportscanbegeneratedondemand,onarecurringschedule,andcanbescheduledforemaildelivery.
Thesereportsprovideinformationontheuserandthecontextsothatyoucorrelateeventsandidentify
patterns,trends,andpotentialareasofinterest.Withtheintegratedapproachtologgingandreporting,the
ACCenablescorrelationofentriesfrommultiplelogsrelatingtothesameevent.

20•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
PanoramaCommitOperations PanoramaOverview
PanoramaCommitOperations
WheneditingtheconfigurationonPanorama,youarechangingthecandidateconfigurationfile.The
candidateconfigurationisacopyoftherunningconfigurationalongwithanychangesyoumadesincethe
lastcommit.ThePanoramawebinterfacedisplaysalltheconfigurationchangesimmediately.However,
Panoramawon’timplementthechangesuntilyoucommitthem.Thecommitprocessvalidatesthechanges
inthecandidateconfigurationfileandsavesitastherunningconfigurationonPanorama.
WheninitiatingacommitonPanorama,selectoneofthefollowingtypes:
Whenyouperformacommit,Panoramapushestheentireconfigurationtothemanagedfirewalls.Whenthe
commitcompletes,aresultdisplays:Commit succeededorCommit succeeded with warnings.
Someothercommitchoicesare:
Preview Changes—ThisoptionisavailablewhentheCommit TypeisPanorama.Itenablesyoutocompare
thecandidateconfigurationwiththerunningconfigurationinthesamewayasthePanorama > Config Audit
feature(seeCompareChangesinPanoramaConfigurations).AfterclickingPreview Changes,selectthe
numberoflinestoincludeforcontext,andclickOK.Asabestpractice,previewyourconfiguration
changesbeforecommittingthem.
Include Device and Network Templates—Thisoptionisavailablewhencommittingadevicegroupfrom
Panorama.Itallowsyoutocommitbothdevicegroupandtemplatechanges,tothepertinentfirewalls,in
asinglecommitoperation.
Ifyouprefertocommityourchangesasseparatecommitoperations,donotselectthischeckbox.
AfteranysystemeventoradministratoractioncausesPanoramatoreboot,allyourchangessince
thelastcommitwillbelost.Topreservechangeswithoutcommittingthem,periodicallyclick
Saveatthetoprightofthewebinterfacetosaveasnapshotofthecandidateconfiguration.Ifa
rebootoccurs,youcanthenreverttothesnapshot.Fordetailsonbackingupandrestoring
runningandcandidateconfigurations,seeManagePanoramaConfigurationBackups.
CommitOptions Description
Panorama Commitsthechangesonthecurrentcandidateconfigurationtotherunning
configurationonPanorama.YoumustfirstcommityourchangesonPanorama,before
committinganyconfigurationupdates(templatesordevicegroups)tothemanaged
firewallsorCollectorGroups.
Template CommitsnetworkanddeviceconfigurationsfromaPanoramatemplatetotheselected
firewalls.
Device Group CommitspoliciesandobjectsconfiguredfromPanoramatotheselectedfirewalls/virtual
systems.
Collector Group CommitschangestothespecifiedCollectorGroupsthatPanoramamanages.
Becausethepreviewresultsdisplayinanewwindow,yourbrowsermustallowpop‐upwindows.
Ifthepreviewwindowdoesnotopen,refertoyourbrowserdocumentationforthestepsto
unblockpop‐upwindows.
Table of contents
Other PaloAlto Networks Server manuals
Popular Server manuals by other brands

Fujitsu
Fujitsu PRIMERGY BX960 S1 operating manual

Supermicro
Supermicro SUPERSERVER 6013A-T Hardware specifications

Digital Equipment
Digital Equipment DEC 10000 Service manual

Supermicro
Supermicro SUPERSERVER 6028TP-HC1R user manual

ANTAIRA
ANTAIRA STW-611C installation guide

Correlate
Correlate SmartSERVER installation guide