If you manage your firewalls with Panorama, choose
Yes
and enter its serial number. This will link your Panorama management server
with the applications in this TSG. You can find the Panorama serial number in
your
Customer Service Portal account in
. After you choose
Yes and enter your
Panorama serial number,
Device Security displays the materials you need to
get the certificate or certificates that firewalls need to secure their
connections with
Device Security and the logging service.
If you have a Device Security license that includes
Strata Logging Service, then Panorama must be part of the
same TSG as Strata Logging Service.
To get a device certificate, click the link to the Customer
Support Portal, log in to your account, and then follow the
instructions below. To generate a logging service certificate, copy
the OTP or PSK and follow the instructions below.
If you don’t use Panorama, choose No. Because
an OTP for a logging service certificate applies only to Panorama,
it's not shown.
Consider the following points when deciding which certificates you
need and how to generate them:
Device Certificate: Firewalls require a device certificate
to authenticate with Device Security and to also authenticate with
the logging service. To generate and install a device certificate on
firewalls directly and through Panorama:
Use Panorama to
generate and install a device certificate on one or more
firewalls.
When a device certificate is installed on a firewall so
it can authenticate itself to the logging service and
Device Security, the firewall can’t decrypt encrypted
traffic to inspect it and enforce policy rules on it.
Therefore, don't try to use decryption policy rules on
firewalls that have a device certificate installed on
them.
Logging Service Certificate – One-Time
Password: An OTP is necessary for Panorama to verify
itself with its logging service instance and obtain logging service
certificates for Panorama managed firewalls.
A logging service certificate authenticates firewalls with the
logging service.
- Regenerate the OTP if necessary and copy it.
Log in to the Panorama web interface as an admin
user and select and Get
certificate.
Paste the OTP and then click OK.
Logging Service Certificate – Pre-Shared Key:
A PSK is necessary to generate a logging service certificate on
firewalls without Panorama management running PAN-OS 9.0.3-10.0.x. A
logging service certificate authenticates firewalls with the logging
service. To generate a logging service certificate:
Regenerate the PSK if necessary and copy it.
Log in to your PAN-OS 9.0.3-10.0.x firewall and select .
In the Cloud Logging section, click
Connect next to Onboard without
Panorama.
This opens the Onboard without Panorama dialog.
Paste the PSK and Connect.
The firewall first connects to the Customer Support Portal,
submits the PSK, and downloads a logging service
certificate. It then uses the certificate to authenticate
itself and connect securely to the logging service.
Click the Edit icon (gear) for Cloud Logging.
Select Enable Enhanced Application Logging.
If you want to send the logs to the cloud logging service and to
Panorama, also select
Enable duplicate logging (cloud and on-premise).
If you don't need to send the logs to Panorama, select
Enable cloud logging. Select one of these
options in addition to enabling enhanced application logging.
Panorama streams logs through cloud logging for Device Security
to ingest, even if you have a Doesn't Require Data Lake license.
Choose the region where Strata Logging Service will ingest logs
from your firewalls.
For PA-7000 and PA-5200 models, enter the number of
connections for sending logs from the firewall to the
logging service. The range is 1-20 and the default is 5.
When done, click OK.
The term “Strata Logging Service” is a bit of a misnomer. The
firewall forwards logs to Strata Logging Service, which
only saves them to Strata Logging Service if you’re using it
for data retention. An Device Security, Doesn’t Require
Data Lake subscription still uses Strata Logging Service to
receive EAL logs from the firewall. Even if you have a Device Security
DRDL license, you need to enable Strata Logging Service so that
the firewall can forward EAL logs to Device Security.