PaloAlto Networks Panorama 6.1 Service manual

Panorama™
Administrator’s
Guide
Version6.1

2•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
ContactInformation
CorporateHeadquarters:
PaloAltoNetworks
4401GreatAmericaParkway
SantaClara,CA95054
www.paloaltonetworks.com/company/contact‐support
AboutthisGuide
ThisguidedescribeshowtosetupandusePanorama™forcentralizedmanagement;itisintendedforadministrators
whowantthebasicframeworktoquicklysetupthePanoramavirtualapplianceortheM‐100appliancefor
centralizedadministrationofPaloAltoNetworksfirewalls.
IfyouhaveanM‐100appliance,thisguidetakesoverafteryoufinishrackmountingyourM‐100appliance.
Formoreinformation,refertothefollowingsources:
ForinformationonhowtoconfigureothercomponentsinthePaloAltoNetworksNext‐GenerationSecurity
Platform,gototheTechnicalDocumentationportal:https://www.paloaltonetworks.com/documentationor
searchthedocumentation.
Foraccesstotheknowledgebase,completedocumentationset,discussionforums,andvideos,referto
https://live.paloaltonetworks.com.
Forcontactingsupport,forinformationonsupportprograms,tomanageyouraccountordevices,ortoopena
supportcase,refertohttps://www.paloaltonetworks.com/support/tabs/overview.html.
ForthemostcurrentPAN‐OSandPanorama6.1releasenotes,goto
https://www.paloaltonetworks.com/documentation/61/pan‐os/pan‐os‐release‐notes.html.
Toprovidefeedbackonthedocumentation,pleasewritetousat:[email protected].
PaloAltoNetworks,Inc.
www.paloaltonetworks.com
©2014–2017PaloAltoNetworks,Inc.PaloAltoNetworksisaregisteredtrademarkofPaloAltoNetworks.Alistofourtrademarkscanbe
foundat
https://www.paloaltonetworks.com/company/trademarks.html
.Allothermarksmentionedhereinmaybetrademarksof
theirrespectivecompanies.
RevisionDate:June27,2017

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•3
TableofContents
PanoramaOverview...................................................9
AboutPanorama..................................................................10
PanoramaPlatforms...............................................................11
CentralizedConfigurationandDeploymentManagement...............................12
ContextSwitch—FirewallorPanorama ...........................................12
Templates ....................................................................12
DeviceGroups ................................................................13
CentralizedLoggingandReporting ..................................................16
LoggingOptions ...............................................................16
ManagedCollectorsandCollectorGroups........................................17
CaveatsforaCollectorGroupwithMultipleLogCollectors .........................17
CentralizedReporting..........................................................19
PanoramaCommitOperations......................................................20
Role‐BasedAccessControl.........................................................22
AdministrativeRoles...........................................................22
AuthenticationProfilesandSequences...........................................23
AccessDomains ...............................................................24
AdministrativeAuthentication ...................................................24
PanoramaRecommendedDeployments ..............................................25
PanoramaforCentralizedManagementandReporting .............................25
PanoramainaDistributedLogCollectionDeployment .............................26
PlanYourDeployment .............................................................27
DeployPanorama:TaskOverview ...................................................29
SetUpPanorama....................................................31
DeterminePanoramaLogStorageRequirements......................................32
SetUpthePanoramaVirtualAppliance ..............................................34
SetupPrerequisitesforthePanoramaVirtualAppliance ............................34
InstallPanoramaontheESX(i)Server.............................................35
PerformInitialConfigurationofthePanoramaVirtualAppliance .....................36
ExpandLogStorageCapacityonthePanoramaVirtualAppliance ....................38
IncreaseCPUsandMemoryonthePanoramaVirtualAppliance.....................40
CompletethePanoramaVirtualApplianceSetup ..................................41
SetUptheM‐100Appliance........................................................42
PerformInitialConfigurationoftheM‐100Appliance..............................43
SetuptheM‐100ApplianceasaLogCollector ....................................46
IncreaseStorageontheM‐100Appliance ........................................50
MigratefromaPanoramaVirtualAppliancetoanM‐100Appliance......................52
PrerequisitesforMigratingtoanM‐100Appliance.................................52
PlantoMigratetoanM‐100Appliance...........................................52
MigratetoanM‐100Appliance .................................................53
ResumeFirewallManagementafterMigratingtoanM‐100Appliance................54

4•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents
RegisterPanoramaandInstallLicenses...............................................56
RegisterPanorama.............................................................56
ActivateaPanoramaSupportLicense.............................................57
Activate/RetrieveaDeviceManagementLicenseonthePanoramaVirtualAppliance ...57
Activate/RetrieveaDeviceManagementLicenseontheM‐100Appliance ............58
InstallContentandSoftwareUpdatesforPanorama ...................................60
Panorama,LogCollector,andFirewallVersionCompatibility ........................60
InstallUpdatesforPanoramainanHAConfiguration ...............................61
InstallUpdatesforPanoramawithanInternetConnection ..........................62
InstallUpdatesforPanoramawithoutanInternetConnection .......................66
AccessandNavigatePanoramaManagementInterfaces ................................70
LogintothePanoramaWebInterface ............................................70
NavigatethePanoramaWebInterface............................................70
LogintothePanoramaCLI......................................................71
SetUpAdministrativeAccesstoPanorama ...........................................73
CreateanAdministrativeAccount ................................................73
DefineanAccessDomain .......................................................75
CreateanAuthenticationProfile.................................................75
DefineanAuthenticationSequence..............................................76
ConfigureAdministrativeAuthentication..........................................77
ManageFirewalls ....................................................83
AddaFirewallasaManagedDevice .................................................84
ManageDeviceGroups.............................................................85
AddaDeviceGroup ............................................................85
CreateObjectsforUseinSharedorDeviceGroupPolicy ...........................86
ManageSharedObjects.........................................................87
SelectaURLFilteringVendoronPanorama .......................................88
PushaPolicytoaSubsetofFirewalls .............................................89
ManagetheRuleHierarchy .....................................................90
ManageTemplates.................................................................93
TemplateCapabilitiesandExceptions.............................................93
AddaTemplate ................................................................94
OverrideaTemplateSetting.....................................................96
Disable/RemoveTemplateSettings ..............................................97
TransitionaFirewalltoPanoramaManagement .......................................98
UseCase:ConfigureFirewallsUsingPanorama ........................................99
DeviceGroups.................................................................99
Templates....................................................................100
SetUpYourCentralizedConfigurationandPolicies ...............................101
ManageLogCollection .............................................107
EnableLogForwardingtoPanorama................................................108
LogForwardingtoPanorama:WorkflowsbyLogType.............................108
ConfigureLogForwardingtoPanorama..........................................109
ConfigureaManagedCollector.....................................................113

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•5
TableofContents
ManageCollectorGroups ......................................................... 117
ConfigureaCollectorGroup ................................................... 117
MoveaLogCollectortoaDifferentCollectorGroup .............................. 120
RemoveaFirewallfromaCollectorGroup....................................... 121
VerifyLogForwardingtoPanorama ................................................ 122
ModifyLogForwardingandBufferingDefaults....................................... 123
EnableLogForwardingfromPanoramatoExternalDestinations ....................... 125
LogCollectionDeployments ....................................................... 128
PlanaLogCollectionDeployment .............................................. 128
DeployPanoramawithDedicatedLogCollectors................................. 131
DeployPanoramawithDefaultLogCollectors.................................... 137
DeployPanoramaVirtualApplianceswithLocalLogCollection ..................... 144
ManageLicensesandUpdates........................................147
ManageLicensesonFirewallsUsingPanorama....................................... 148
DeployUpdatestoDevicesUsingPanorama ......................................... 149
SupportedUpdatesbyDeviceType ............................................. 149
ScheduleContentUpdatestoDevicesUsingPanorama............................ 149
DeployUpdatestoDeviceswhenPanoramaHasanInternetConnection ............ 151
DeployUpdatestoDeviceswhenPanoramaHasNoInternetConnection ........... 154
MonitorNetworkActivity............................................159
UsePanoramaforVisibility........................................................ 160
MonitortheNetworkwiththeACCandAppScope ............................... 160
AnalyzeLogData ............................................................. 162
Generate,Schedule,andEmailReports.......................................... 162
UseCase:MonitorApplicationsUsingPanorama..................................... 166
UseCase:RespondtoanIncidentUsingPanorama................................... 170
IncidentNotification.......................................................... 170
ReviewThreatLogs ........................................................... 171
ReviewWildFireLogs......................................................... 172
ReviewDataFilteringLogs..................................................... 173
UpdateSecurityPolicies ....................................................... 173
PanoramaHighAvailability...........................................175
PanoramaHAPrerequisites........................................................ 176
PriorityandFailoveronPanoramainHA ............................................ 177
FailoverTriggers ................................................................. 179
HAHeartbeatPollingandHelloMessages....................................... 179
HAPathMonitoring........................................................... 179
LoggingConsiderationsinPanoramaHA ............................................ 181
LoggingFailoveronaPanoramaVirtualAppliance ................................ 181
LoggingFailoveronanM‐100Appliance ........................................ 181
SynchronizationBetweenPanoramaHAPeers ....................................... 183

6•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents
ManageaPanoramaHAPair .......................................................184
SetUpHAonPanorama.......................................................184
TestPanoramaHAFailover ....................................................186
SwitchPriorityafterPanoramaFailovertoResumeNFSLogging ....................186
RestorethePrimaryPanoramatotheActiveState ................................187
AdministerPanorama...............................................189
ManageConfigurationBackups.....................................................190
ScheduleExportofConfigurationFiles...........................................190
ManagePanoramaConfigurationBackups .......................................191
ConfiguretheNumberofConfigurationBackupsPanoramaStores ..................192
LoadaConfigurationBackuponaManagedFirewall ..............................192
CompareChangesinPanoramaConfigurations .......................................194
RestrictAccesstoConfigurationChanges............................................195
TypesofLocks................................................................195
LocationsforTakingaLock ....................................................195
TakeaLock ..................................................................196
ViewLockHolders............................................................196
EnableAutomaticAcquisitionoftheCommitLock ................................196
RemoveaLock ...............................................................197
AddCustomLogostoPanorama ....................................................198
ViewPanoramaTaskCompletionHistory ............................................199
ReallocateLogStorageQuota ......................................................200
MonitorPanorama ................................................................202
PanoramaSystemandConfigurationLogs........................................202
SetUpEmailAlertsforPanorama...............................................203
SetUpSNMPtoMonitorPanorama .............................................204
RebootorShutDownPanorama....................................................208
GenerateDiagnosticFilesforPanorama.............................................209
ConfigurePanoramaPasswordProfilesandComplexity ...............................210
ReplaceaFailedDiskonanM‐100Appliance........................................212
ReplacetheVirtualDiskonaPanoramaVirtualAppliance .............................213
Troubleshooting ...................................................215
TroubleshootPanoramaSystemIssues..............................................216
DiagnosePanoramaSuspendedState............................................216
MonitortheFileSystemIntegrityCheck.........................................216
ManagePanoramaStorageforSoftwareandContentUpdates .....................216
RecoverfromSplitBraininPanoramaHADeployments............................217
TroubleshootLogStorageandConnectionIssues .....................................219
WhatPortsareUsedbyPanorama?.............................................219
ResolveZeroLogStorageforaCollectorGroup...................................220
RecoverLogsafterFailure/RMAofM‐100ApplianceinLogCollectorMode .........220
RecoverLogsafterFailure/RMAofM‐100ApplianceinPanoramaMode ............224
RecoverLogsafterPanoramaFailure/RMAinNon‐HADeployments ................229
RegenerateMetadataforM‐100ApplianceRAIDPairs............................231

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•7
TableofContents
ReplaceanRMAFirewall .......................................................... 233
PartialDeviceStateGenerationforFirewalls ..................................... 233
BeforeStartingRMAFirewallReplacement...................................... 233
RestoretheFirewallConfigurationafterReplacement ............................. 235
DiagnoseTemplateCommitFailures ................................................ 238
ViewTaskSuccessorFailureStatus ................................................ 239

8•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
TableofContents

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•9
PanoramaOverview
PanoramaprovidescentralizedmanagementandvisibilityofmultiplePaloAltoNetworksnext‐generation
firewalls.Itallowsyoutooverseeallapplications,users,andcontenttraversingthenetworkfromone
location,andthenusethisknowledgetocreateapplicationenablementpoliciesthatprotectandcontrolthe
entirenetwork.UsingPanoramaforcentralizedpolicyanddevicemanagementincreasesoperational
efficiencyinmanagingandmaintainingadistributednetworkoffirewalls.
ThefollowingsectionsdescribePanoramaandprovideguidelinesforplanningyourPanoramadeployment:
AboutPanorama
PanoramaPlatforms
CentralizedConfigurationandDeploymentManagement
CentralizedLoggingandReporting
PanoramaCommitOperations
Role‐BasedAccessControl
PanoramaRecommendedDeployments
PlanYourDeployment
DeployPanorama:TaskOverview

10•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
AboutPanorama PanoramaOverview
AboutPanorama
PanoramaprovidescentralizedmanagementofthePaloAltoNetworksnext‐generationfirewalls,asthe
followingfigureillustrates:
Panoramaallowsyoutoeffectivelyconfigure,manage,andmonitoryourPaloAltoNetworksfirewallsusing
centraloversightwithlocalcontrol,asrequired.ThethreefocalareasinwhichPanoramaaddsvalueare:
Centralizedconfigurationanddeployment—Tosimplifycentralmanagementandrapiddeploymentof
thefirewallsonyournetwork,usePanoramatopre‐stagethefirewallsfordeployment.Youcanthen
assemblethefirewallsintogroups,andcreatetemplatestoapplyabasenetworkanddevice
configurationandusedevicegroupstoadministergloballysharedandlocalpolicies.SeeCentralized
ConfigurationandDeploymentManagement.
Aggregatedloggingwithcentraloversightforanalysisandreporting—Collectinformationonactivity
acrossallthemanagedfirewallsonthenetworkandcentrallyanalyze,investigateandreportonthedata.
Thiscomprehensiveviewofnetworktraffic,useractivity,andtheassociatedrisksempowersyouto
respondtopotentialthreatsusingtherichsetofpoliciestosecurelyenableapplicationsonyournetwork.
SeeCentralizedLoggingandReporting.
Distributedadministration—Allowsyoutodelegateorrestrictaccesstoglobalandlocalfirewall
configurationsandpolicies.SeeRole‐BasedAccessControlfordelegatingappropriatelevelsofaccessfor
distributedadministration.
Panoramaisavailableintwoplatforms:asavirtualapplianceandasadedicatedhardwareappliance.For
moreinformation,seePanoramaPlatforms.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•11
PanoramaOverview PanoramaPlatforms
PanoramaPlatforms
Panoramaisavailableintwoplatforms,eachofwhichsupportsfirewallmanagementlicensesformanaging
upto25,100,or1,000firewalls:
Panoramavirtualappliance—ThePanoramavirtualapplianceisinstalledonaVMwareserver.Itallows
forasimpleinstallationandfacilitatesserverconsolidationforsitesthatneedavirtualmanagement
appliance.ItalsosupportsintegrationwithaNetworkFileSystem(NFS)forincreasedstorageand(>2TB)
logretentioncapabilities.
ThePanoramavirtualappliancebestsuitsenvironmentswithloggingratesofupto10,000logs/second.
M‐100appliance—Adedicatedhardwareapplianceintendedforlargescaledeployments.In
environmentswithhighloggingratesandlogretentionrequirements,thisplatformenablesscalingof
yourlogcollectioninfrastructure.TheappliancesupportsRAID1mirroringtoprotectagainstdisk
failures,andthedefaultconfigurationshipswithtwo1TBdrives;withadditionalRAIDpairs,theM‐100
appliancecansupportupto4TBoflogstorage.
TheM‐100applianceallowsforseparationofthecentralmanagementfunctionfromthelogcollection
functionbysupportingthefollowingdeploymentmodes:
– Panoramamode:Theapplianceperformsboththecentralmanagementandthelogcollection
functions.Thisisthedefaultmode.
–LogCollectormode:TheappliancefunctionsasadedicatedLogCollector,whicheitheranM‐100
applianceinPanoramamodeoraPanoramavirtualappliancecanmanage.
WhendeployedinLogCollectormode,theappliancedoesnothaveawebinterface;administrative
accessisCLIonly.However,youmanagetheapplianceusingthePanoramamanagementserver
(M‐100applianceinPanoramamodeoraPanoramavirtualappliance).CLIaccesstoanM‐100
applianceinLogCollectormodeisonlynecessaryforinitialsetupanddebugging.
Theplatformchoicedependsonyourneedforavirtualapplianceandyourlogcollectionrequirements(see
DeterminePanoramaLogStorageRequirements):
LogCollectionRate Platform
Upto10,000logs/second Panoramavirtualappliance
Upto30,000logs/second M‐100appliance

12•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedConfigurationandDeploymentManagement PanoramaOverview
CentralizedConfigurationandDeploymentManagement
PanoramausesDeviceGroupsandTemplatestogroupdevicesintosmallerandmorelogicalsetsthatrequire
similarconfiguration.Allconfigurationelements,policies,andobjectsonthemanagedfirewallscanbe
centrallymanagedonPanoramausingDeviceGroupsandTemplates.Inadditiontomanagingconfiguration
andpolicies,Panoramaenablesyoutocentrallymanagelicenses,softwareandassociatedcontentupdates:
SSL‐VPNclients,GlobalProtectagents,dynamiccontentupdates(Applications,Threats,WildFireand
Antivirus).
ContextSwitch—FirewallorPanorama
Templates
DeviceGroups
ContextSwitch—FirewallorPanorama
ThePanoramawebinterfaceallowsyoutotogglebetweenaPanorama‐centricviewandafirewall‐centric
viewusingthecontextswitch.YoucanchoosetomanagethefirewallcentrallyusingPanoramaandthen
switchcontexttoaspecificmanagedfirewalltoconfigurethefirewallusingthefirewalluserinterface.The
similarityoftheuserinterfaceonthemanagedfirewallsandPanoramaallowsyoutoseamlesslymove
betweentheinterfacestoadministerandmonitorthefirewallasrequired.
IfyouhaveconfiguredAccessDomainstorestrictadministrativeaccesstospecificmanagedfirewalls,the
Panoramauserinterfacedisplaysonlythefirewalls/featuresforwhichthelogged‐inadministratorhas
permissions.
Templates
Youusetemplatestoconfigurethesettingsthatmanagedfirewallsrequiretooperateonthenetwork.
TemplatesenableyoutodefineacommonbaseconfigurationusingtheNetworkandDevicetabson
Panorama.Forexample,youcanusetemplatestomanageinterfaceandzoneconfigurations,serverprofiles
forloggingandSNMPaccess,andnetworkprofilesforcontrollingaccesstozonesandIKEgateways.When
yougroupfirewallstodefineTemplatesettings,considergroupingfirewallsthatarealikeinhardwaremodel,
andrequireaccesstosimilarnetworkresources,suchasgatewaysandsyslogservers.
Usingtemplates,youcanpushalimitedcommonbaseconfigurationtoagroupoffirewallsandthen
configuretherestofthesettingsmanuallyonthefirewall.Alternatively,youcanpushalargercommonbase
configurationandthenoverridethetemplatesettingsonthefirewalltoaccommodatefirewall‐specific
changes.Whenyouoverrideasettingonthefirewall,thesettingissavedtothelocalconfigurationofthe
firewallandisnolongermanagedbythePanoramatemplate.Youcan,however,usePanoramatoforcethe
templateconfigurationontothefirewallorrestorethetemplatesettingsonthefirewall.Forexample,you
candefineacommonNTPserverinthetemplate,butoverridetheNTPserverconfigurationonthefirewall
toaccommodateforthelocaltimezoneonthefirewall.Ifyouthendecidetorestorethetemplatesettings,
youcaneasilyundoorrevertthelocalchangesthatyouimplementedonthefirewall.
TemplatescannotbeusedtodefineanoperationalstatechangesuchasFIPSmodeortoenablemulti‐vsys
modeonthefirewalls.Formoreinformation,seeTemplateCapabilitiesandExceptions.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•13
PanoramaOverview CentralizedConfigurationandDeploymentManagement
DeviceGroups
TousePanoramaeffectively,youmustgroupthefirewallsonyournetworkintologicalunitscalleddevice
groups.Adevicegroupallowsgroupingbasedonnetworksegmentation,geographiclocation,orbytheneed
toimplementsimilarpolicyconfigurations.Adevicegroupcanincludephysicalfirewalls,virtualfirewalls
and/oravirtualsystem.Bydefault,allmanageddevicesbelongtotheShareddevicegrouponPanorama.
DeviceGroupsenablecentralmanagementofpoliciesandobjectsusingthePoliciesandObjectstabson
Panorama.Objectsareconfigurationelementsthatarereferencedinpolicies.Someoftheobjectsthat
firewallpoliciesmakeuseofare:IPaddresses,URLcategories,securityprofiles,users,services,and
applications.
UsingDeviceGroupsyoucancreatesharedobjectsordevicegroup‐specificobjectsandthenusethese
objectstocreateahierarchyofrules(andrulebases)toenforcehowmanagedfirewallshandleinboundand
outboundtraffic.Forexample,acorporateacceptableusepolicycouldbedefinedasasetofsharedpolicies.
Then,toallowonlytheregionalofficestoaccesspeer‐to‐peertrafficsuchasBitTorrent,youcancreatea
securityruleasasharedpolicyandtargetittotheregionalofficesormakeitadevicegrouprulethatis
pushedtotheregionaloffices.SeeUseCase:ConfigureFirewallsUsingPanorama.
Policies
Objects
Policies
Devicegroupsprovideawaytoimplementalayeredapproachformanagingpoliciesacrossanetworkof
managedfirewalls.Thefollowingtableliststhepolicylayers,thefirewallstowhichthepoliciesapply,and
theplatformwhereyouadministerthepolicies:
Bothsharedpoliciesanddevicegroup‐specificpoliciesallowyoutocraftpre‐rulesandpost‐rulesto
centrallymanagealltherulebases:Security,NAT,QoS,PolicyBasedForwarding,Decryption,Application
Override,CaptivePortal,andDoSProtection.
Pre‐rules—RulesyouaddtothetopoftheruleorderandthatPAN‐OSevaluatesfirst.Youcanuse
pre‐rulestoenforcetheAcceptableUsePolicyforanorganization;forexample,toblockaccessto
specificURLcategories,ortoallowDNStrafficforallusers.Pre‐rulescanbesharedordevice
group‐specific.
Post‐rules—RulesthatPAN‐OSevaluatesafterthepre‐rulesandthelocalfirewallrules.Post‐rules
typicallyincluderulestodenyaccesstotrafficbasedontheApp‐ID,User‐ID,orService.Likepre‐rules,
postrulescanbesharedordevicegroup‐specific.
Policy Scope AdministrationPlatform
Shared Allthefirewallsinalldevicegroups. Panorama
Devicegroup‐specific Allthefirewallsassignedtoasingledevicegroup. Panorama
Local(firewall‐specific) Asinglefirewall.Firewall
Default(securityrules
only)
Bydefault,thedefaultrulesareshared(applytoallfirewallsin
alldevicegroups)andarepartofthepredefinedconfiguration.
However,ifyouedit(override)therules,theirscopechanges
tothelevelatwhichyouperformedtheedits:devicegroupor
local(firewall/virtualsystem).
PanoramaorFirewall

14•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedConfigurationandDeploymentManagement PanoramaOverview
Thepre‐rulesandpost‐rulesthatPanoramapushesarevisibleonthemanagedfirewallsbutonlyeditablein
Panorama.ThelocalfirewalladministratororaPanoramaadministratorwhoswitchestoalocalfirewall
contextcaneditlocalfirewallrules.
DefaultpoliciesapplyonlytotheSecurityrulebase.Thedefaultruleinterzone‐defaultspecifiesthatthe
firewalldeniesallinterzone(betweenzones)trafficthatdoesn’tmatchanotherrule.Thedefaultrule
intrazone‐defaultspecifiesthatthefirewallallowsallintrazone(withinazone)trafficthatdoesn’tmatch
anotherrule.WhenyoupreviewrulesinPanorama,thedefaultrulesappearbelowallotherrules.Initially
thedefaultrulesareread‐only,eitherbecausetheyarepartofthepredefinedconfigurationsettingsor
becausePanoramapushedthemtodevices.However,youcanoverridethesettingsfortags,action(allow
ordeny),logging,andsecurityprofiles.Thedevicecontextdeterminesthelevelatwhichyoucanedit
(override)defaultrules:
OnPanorama,youcaneditdefaultrulesthatarepartofthepredefinedconfiguration.Youcaneditrules
inadevicegrouporsharedcontext.
Onthefirewall,youcaneditdefaultrulesthatarepartofthepredefinedconfiguration,orpushedfrom
aPanoramasharedordevicegroupcontext.Thedefaultrulescanbevirtualsystem(vsys)specific.
Theorderofprecedencefordefaultrulesrunsfromthelowestcontexttothehighest:settingseditedatthe
firewallleveloverridesettingsatthedevicegrouplevel,whichoverridesettingsatthesharedlevel.
Theevaluationorder(fromtop‐firsttobottom‐last)ofallrulesis:
Whentrafficmatchesapolicyrule,thedefinedactionistriggeredandthefirewalldisregardsallsubsequent
policies.Thisabilitytolayerpoliciescreatesahierarchyofruleswherelocalpoliciesarebetweenthepre‐
andpost‐rules,andareeditablebyswitchingtothelocalfirewallcontext,orbyaccessingthefirewalllocally.
Thefirewallwebinterfacevisuallydemarcatesthiscascadeofrulesforeachdevicegroup(andmanaged
firewall),andprovidestheabilitytoscanthroughalargenumbersofrules.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•15
PanoramaOverview CentralizedConfigurationandDeploymentManagement
Fordetailsonrulemanagement,refertothePAN‐OSAdministrator’sGuide.
Objects
Objectsareconfigurationelementsthatarereferencedinpolicies.Someoftheobjectsthatfirewallpolicies
makeuseofare:IPaddresses,URLcategories,securityprofiles,users,services,andapplications.Because
objectscanbereusedacrosspolicies,creatingsharedobjectsordevicegroupobjectsreducesduplicationof
theseconfigurationelements.Forexample,creatingsharedaddressobjectsandaddressgroupsorshared
serviceobjectsandservicegroupsallowsyoutocreateoneinstanceoftheobjectandreferenceitinany
rulebasetomanagethefirewallsacrossmultipledevicegroups.Becausesharedobjectsaredefinedoncebut
usedmanytimes,theyreduceadministrativeoverhead,andmaintainconsistencyandaccuracyeverywhere
thesharedobjectisused.
Pre‐rules,post‐rulesandruleslocallydefinedonafirewallcanallusesharedobjectsanddevicegroup
objects.WhencreatinganobjectonPanorama,configurethebehaviorbasedonwhether:
Thedevicegroupobjecttakesprecedenceoverasharedobject,whenbothobjectshavethesamename.
Bydefault,theSharedObjectTakesPrecedenceoptionisdisabledonPanorama.Thisbehaviorensures
thatasharedobjectonlysupersedesadevicegroupobjectwiththesamenameifyouexplicitlywantthe
valueofasharedobjecttoprevail.Whenyouenabletheoptionforsharedobjectstotakeprecedence,
Panoramainformsyouofallthedevicegroupobjectsthatwillbeshadowed.However,ifadevicehasa
locallycreatedobjectwiththesamenameasasharedoradevicegroupobjectthatispushedfrom
Panorama,acommitfailurewilloccur.
AllsharedanddevicegroupobjectsthataredefinedonPanoramaarepushedtothemanageddevices.
Bydefault,allobjects—thosethatareandarenotreferencedinpolicies—arepushedtothemanaged
devices.

16•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedLoggingandReporting PanoramaOverview
CentralizedLoggingandReporting
Panoramaaggregatesdatafromallmanagedfirewallsandprovidesvisibilityacrossallthetrafficonthe
network.Italsoprovidesanaudittrailforallpolicymodificationsandconfigurationchangesmadetothe
managedfirewalls.Inadditiontoaggregatinglogs,PanoramacanaggregateandforwardSNMPtraps,email
notifications,andsyslogmessagestoanexternaldestination.
TheApplicationCommandCenter(ACC)onPanoramaprovidesasinglepaneforunifiedreportingacrossall
thefirewalls;itallowsyoutocentrallyanalyze,investigate,andreportonnetworktrafficandsecurity
incidents.OnPanorama,youcanviewlogsandgeneratereportsfromlogsforwardedtoPanoramaortothe
managedLogCollectors,ifconfigured,oryoucanquerythemanagedfirewallsdirectly.Forexample,youcan
generatereportsabouttraffic,threat,and/oruseractivityinthemanagednetworkbasedonlogsstoredon
Panorama(andthemanagedLogCollectors)orbyaccessingthelogsstoredlocallyonthemanagedfirewalls.
IfyouchoosenottoconfigurethemanagedfirewallstoforwardlogstoPanorama,youcanschedulereports
toberunoneachmanagedfirewallandforwardtheresultstoPanoramaforacombinedviewofuseractivity
andnetworktraffic.Althoughthisviewdoesnotprovidegranulardrill‐downonspecificdataandactivities,
itstillprovidesaunifiedreportingapproach.
LoggingOptions
ManagedCollectorsandCollectorGroups
CaveatsforaCollectorGroupwithMultipleLogCollectors
CentralizedReporting
LoggingOptions
BoththePanoramavirtualapplianceandM‐100appliancecancollectlogsthatthemanagedfirewalls
forward.YoucanthenconfigurePanoramatoforwardtheseaggregatedlogstoexternalservices(Syslog
server,emailserver,orSNMPtrapserver).Theloggingoptionsvaryoneachplatform.
PanoramaPlatform LoggingOptions
Virtualappliance Offersthreeloggingoptions:
•Usetheapproximately11GBofinternalstoragespaceallocatedforloggingassoonas
youinstallthevirtualappliance.
•Addavirtualdiskthatcansupportupto2TBofstorage.
•MountaNetworkFileSystem(NFS)datastoreinwhichyoucanconfigurethestorage
capacitythatisallocatedforlogging.
M‐100appliance Thedefaultshippingconfigurationincludes1TBdisksinaRAIDpair,whichyoucan
increaseto4TBRAIDstorage(seeIncreaseStorageontheM‐100Appliance).Whenthe
M‐100applianceisinPanoramamode,youcanenabletheRAIDdisksandusethesedisks
asthedefaultLogCollector.IfyouhaveM‐100applianceisinLogCollectormode
(dedicatedLogCollectors),youusePanoramatoassignfirewallstothededicatedLog
Collectors.InadeploymentwithmultiplededicatedLogCollectors,Panoramaqueriesall
managedLogCollectorstogenerateanaggregatedviewoftrafficandcohesivereports.
Foreasyscaling,beginwithasinglePanoramaandincrementallyadddedicatedLog
Collectorsasyourneedsexpand.

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•17
PanoramaOverview CentralizedLoggingandReporting
ManagedCollectorsandCollectorGroups
ALogCollectorcanbelocaltoanM‐100applianceinPanoramamode(defaultLogCollector)orcanbean
M‐100applianceinLogCollectormode(dedicatedLogCollector).BecauseyouusePanoramatoconfigure
andmanageLogCollectors,theyarealsoknownasManagedCollectors.AnM‐100applianceinPanorama
modeoraPanoramavirtualappliancecanmanagededicatedLogCollectors.ToadministerdedicatedLog
CollectorsusingthePanoramawebinterface,youmustaddthemasManagedCollectors.Otherwise,
administrativeaccesstoadedicatedLogCollectorisonlyavailablethroughitsCLIusingthedefault
administrativeuser(admin)account.DedicatedLogCollectorsdonotsupportadditionaladministrativeuser
accounts.
ACollectorGroupis1to16managedcollectorsthatoperateasasinglelogicallogcollectionunit.Ifthe
groupcontainsdedicatedLogCollectors,thelogsareuniformlydistributedacrossallthedisksineachLog
CollectorandacrossallmembersintheCollectorGroup.Thisdistributionmaximizestheuseoftheavailable
storagespace.TomanageaLogCollector,youmustaddittoaCollectorGroup.PaloAltoNetworks
recommendsplacingonlyoneLogCollectorinaCollectorGroupunlessmorethan4TBofstoragespaceis
requiredinaCollectorGroup.Fordetails,seeCaveatsforaCollectorGroupwithMultipleLogCollectors.
TheCollectorGroupconfigurationspecifieswhichmanagedfirewallscansendlogstotheLogCollectorsin
thegroup.AfteryouconfiguretheLogCollectorsandenablethefirewallstoforwardlogs,eachfirewall
forwardsitslogstotheassignedLogCollector.
ManagedCollectorsandCollectorGroupsareintegraltoadistributedlogcollectiondeploymenton
Panorama.Adistributedlogcollectiondeploymentallowsforeasyscalabilityandincrementaladditionof
dedicatedLogCollectorsasyourloggingneedsgrow.TheM‐100applianceinPanoramamodecanlogtoits
defaultCollectorGroupandthenbeexpandedtoadistributedlogcollectiondeploymentwithoneormore
CollectorGroupsthatincludededicatedLogCollectors.
CaveatsforaCollectorGroupwithMultipleLogCollectors
AlthoughPaloAltoNetworksrecommendsplacingonlyoneLogCollectorinaCollectorGroup,ifyouhave
ascenariowhereyouneedmorethan4TBoflogstoragecapacityinaCollectorGroupfortherequiredlog
retentionperiod,youcanaddupto16LogCollectorstothegroup.Forexample,ifasinglemanagedfirewall
generates12TBoflogs,youwillrequireatleastthreeLogCollectorsintheCollectorGroupthatreceives
thoselogs.
IfaCollectorGroupcontainsmultipleLogCollectors,theavailablestoragespaceisusedasonelogicalunit
andthelogsareuniformlydistributedacrossalltheLogCollectorsintheCollectorGroup.Thelog
distributionisbasedonthediskcapacityoftheLogCollectors(whichrangesfrom1TBto4TB,depending
onthenumberofdiskpairs)andahashalgorithmthatdynamicallydecideswhichLogCollectorownsthe
logsandwritestodisk.AlthoughPanoramausesapreferencelisttoprioritizethelistofLogCollectorsto
whichamanagedfirewallcanforwardlogs,PanoramadoesnotnecessarilywritethelogstothefirstLog
Collectorspecifiedinthepreferencelist.Forexample,considerthefollowingpreferencelist:
IfyouusePanoramatomanagefirewallsrunningbothPAN‐OS5.0andaPAN‐OSversionearlier
than5.0,notethefollowingcompatibilityrequirements:
•OnlydevicesrunningPAN‐OSv5.0cansendlogstoadedicatedLogCollector.
•DevicesrunningPAN‐OSversionsearlierthan5.0canonlysendlogstoaPanoramavirtual
applianceortoanM‐100applianceinPanoramamode.

18•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
CentralizedLoggingandReporting PanoramaOverview
Usingthislist,FW1willforwardlogstoL1,itsprimaryLogCollector,butthehashalgorithmcoulddetermine
thatthelogswillbewrittenonL2.IfL2becomesinaccessibleorhasachassisfailure,FW1willnotknow
aboutitsfailurebecauseitisstillabletoconnecttoL1,itsprimaryLogCollector.
InthecasewhereaCollectorGrouphasonlyoneLogCollectorandtheLogCollectorfails,thefirewallstores
thelogstoitsHDD/SSD(theavailablestoragespacevariesbyhardwaremodel),andresumesforwarding
logstotheLogCollectorwhereitleftoffbeforethefailureoccurredassoonasconnectivityisrestored.
WithmultipleLogCollectorsinaCollectorGroup,thefirewalldoesnotbufferlogstoitslocalstoragewhen
itcanconnecttoitsPrimaryLogCollector.Therefore,FW1willcontinuesendinglogstoL1.BecauseL2is
unavailable,thePrimaryLogCollectorL1buffersthelogstoitsHDD,whichhas10GBoflogspace.IfL2
remainsunavailableandthelogspendingforL2exceed10GB,L1willoverwritetheolderlogentriesto
continuelogging.Insuchanevent,lossoflogsisarisk.Therefore,PaloAltoNetworksrecommendsthe
followingmitigationsifusingmultipleLogCollectorsinaCollectorGroup:
ObtainanOn‐Site‐Spare(OSS)toenablepromptreplacementifaLogCollectorfailureoccurs.
InadditiontoforwardinglogstoPanorama,enableforwardingtoanexternalserviceasbackupstorage.
TheexternalservicecanbeaSyslogserver,emailserver,orSimpleNetworkManagementProtocol
(SNMP)trapserver.Fordetails,seeEnableLogForwardingtoPanorama.
ManagedFirewall LogForwardingPreferenceListDefinedonaCollectorGroup
FW1 L1,L2,L3
FW2 L4,L5,L6

©PaloAltoNetworks,Inc. Panorama6.1Administrator’sGuide•19
PanoramaOverview CentralizedLoggingandReporting
CentralizedReporting
Panoramaaggregateslogsfromallmanagedfirewallsandenablesreportingontheaggregateddatafora
globalviewofapplicationuse,useractivity,andtrafficpatternsacrosstheentirenetworkinfrastructure.As
soonasthefirewallsareaddedtoPanorama,theACCcandisplayalltraffictraversingyournetwork.With
loggingenabled,clickingintoalogentryintheACCprovidesdirectaccesstogranulardetailsaboutthe
application.
Forgeneratingreports,Panoramausestwosources:thelocalPanoramadatabaseandtheremotefirewalls
thatitmanages.ThePanoramadatabasereferstothelocalstorageonPanoramathatisallocatedforstoring
bothsummarizedlogsandsomedetailedlogs.IfyouhaveaDistributedLogCollectiondeployment,the
PanoramadatabaseincludesthelocalstorageonPanoramaandallthemanagedLogCollectors.Panorama
summarizestheinformation—traffic,application,threat—collectedfromallmanagedfirewallsat15‐minute
intervals.UsingthelocalPanoramadatabaseallowsforfasterresponsetimes,however,ifyouprefertonot
forwardlogstoPanorama,Panoramacandirectlyaccesstheremotefirewallandrunreportsondatathatis
storedlocallyonthemanagedfirewalls.
Panoramaoffersmorethan40predefinedreportsthatcanbeusedasis,ortheycanbecustomizedby
combiningelementsofotherreportstogeneratecustomreportsandreportgroupsthatcanbesaved.
Reportscanbegeneratedondemand,onarecurringschedule,andcanbescheduledforemaildelivery.
Thesereportsprovideinformationontheuserandthecontextsothatyoucorrelateeventsandidentify
patterns,trends,andpotentialareasofinterest.Withtheintegratedapproachtologgingandreporting,the
ACCenablescorrelationofentriesfrommultiplelogsrelatingtothesameevent.

20•Panorama6.1Administrator’sGuide ©PaloAltoNetworks,Inc.
PanoramaCommitOperations PanoramaOverview
PanoramaCommitOperations
WheneditingtheconfigurationonPanorama,youarechangingthecandidateconfigurationfile.The
candidateconfigurationisacopyoftherunningconfigurationalongwithanychangesyoumadesincethe
lastcommit.ThePanoramawebinterfacedisplaysalltheconfigurationchangesimmediately.However,
Panoramawon’timplementthechangesuntilyoucommitthem.Thecommitprocessvalidatesthechanges
inthecandidateconfigurationfileandsavesitastherunningconfigurationonPanorama.
WheninitiatingacommitonPanorama,selectoneofthefollowingtypes:
Whenyouperformacommit,Panoramapushestheentireconfigurationtothemanagedfirewalls.Whenthe
commitcompletes,aresultdisplays:Commit succeededorCommit succeeded with warnings.
Someothercommitchoicesare:
Preview Changes—ThisoptionisavailablewhentheCommit TypeisPanorama.Itenablesyoutocompare
thecandidateconfigurationwiththerunningconfigurationinthesamewayasthePanorama > Config Audit
feature(seeCompareChangesinPanoramaConfigurations).AfterclickingPreview Changes,selectthe
numberoflinestoincludeforcontext,andclickOK.Asabestpractice,previewyourconfiguration
changesbeforecommittingthem.
Include Device and Network Templates—Thisoptionisavailablewhencommittingadevicegroupfrom
Panorama.Itallowsyoutocommitbothdevicegroupandtemplatechanges,tothepertinentfirewalls,in
asinglecommitoperation.
Ifyouprefertocommityourchangesasseparatecommitoperations,donotselectthischeckbox.
AfteranysystemeventoradministratoractioncausesPanoramatoreboot,allyourchangessince
thelastcommitwillbelost.Topreservechangeswithoutcommittingthem,periodicallyclick
Saveatthetoprightofthewebinterfacetosaveasnapshotofthecandidateconfiguration.Ifa
rebootoccurs,youcanthenreverttothesnapshot.Fordetailsonbackingupandrestoring
runningandcandidateconfigurations,seeManagePanoramaConfigurationBackups.
CommitOptions Description
Panorama Commitsthechangesonthecurrentcandidateconfigurationtotherunning
configurationonPanorama.YoumustfirstcommityourchangesonPanorama,before
committinganyconfigurationupdates(templatesordevicegroups)tothemanaged
firewallsorCollectorGroups.
Template CommitsnetworkanddeviceconfigurationsfromaPanoramatemplatetotheselected
firewalls.
Device Group CommitspoliciesandobjectsconfiguredfromPanoramatotheselectedfirewalls/virtual
systems.
Collector Group CommitschangestothespecifiedCollectorGroupsthatPanoramamanages.
Becausethepreviewresultsdisplayinanewwindow,yourbrowsermustallowpop‐upwindows.
Ifthepreviewwindowdoesnotopen,refertoyourbrowserdocumentationforthestepsto
unblockpop‐upwindows.
Table of contents
Other PaloAlto Networks Server manuals
Popular Server manuals by other brands

Dell
Dell POWEREDGE M905 Getting Started With Your System

Asus
Asus ESC8000 4G Series user guide

NEC
NEC Express5800/B110d Configuration guide

Compaq
Compaq ProLiant 1000 Installation and configuration guide

Dell
Dell EMC DSS 9620 Installation and service manual

Ruijie
Ruijie Cloud Class RCD V3 Series user manual