: Bootstrapping VM-Series in Virtual Metadata Collector Mode
Focus
Focus

Bootstrapping VM-Series in Virtual Metadata Collector Mode

Table of Contents

Bootstrapping VM-Series in Virtual Metadata Collector Mode

Learn about boostrapping the VM-Series in Virtual Metadata collector mode.
Virtual metadata collector mode is a specialized sub-mode for the VM-Series firewall designed to improve IoT data collection efficiency while minimizing your resource usage. This section outlines the key considerations for bootstrapping a VM-Series firewall in virtual metadata collector mode.
The virtual metadata collector mode is supported only on ESXi and KVM platform with PAN-OS version 11.2.5 or later.
To bootstrap a VM-Series firewall in virtual metadata collector mode, ensure that you include the virtual metadata sensor keyword to the op-command-modes parameter as key value pair in the config/init-cfg.txt file.
For example:
op-command-modes=metadata-sensor
For more information, see Create the init-cfg.txt File, init-cfg.txt File Components, and Bootstrap the VM-Series firewall for the complete bootstrapping work flow.
  • A default allow-all security policy is automatically configured when you perform the initial configuration of your VM-Series firewall. This policy and its associated default security profiles are non-editable. Any attempt to modify or add policies will fail with an error during commit operations.
  • IoT policy recommendations from the IoT cloud will not apply to virtual metadata collector VMs. Panorama commits for these recommendations will fail.
Panorama is required for managing virtual metadata collector mode VMs. After you bootstrap and license, the VM connects and syncs with Panorama automatically. Additionally, Panorama information can also be provisioned in the firewall after it comes up either through firewall CLI or the web interface. Verify Panorama connectivity with the following command:
show panorama-status