: Automatic Panorama Connection Recovery
Focus
Focus

Automatic Panorama Connection Recovery

Table of Contents
End-of-Life (EoL)

Automatic Panorama Connection Recovery

Automatically revert the firewall and Panorama™ management server to the last the running configuration to automatically when the firewall loses connection to Panorama.
Recovering isolated firewalls can be painful as it can result in unintended downtime and a loss in productivity. PAN-OS 9.1.0 introduces the ability for managed firewalls to check for connectivity to the Panorama™ management server and automatically revert to the last running configuration when the firewall is unable to communicate with Panorama. This helps you quickly resolve any configuration or connectivity issues without the need for manual intervention.
Automatic commit recovery allows you to configure the firewall to attempt a specified number of connectivity tests after you push a configuration from Panorama or commit a configuration change locally on the firewall. Additionally, the firewall checks connectivity to Panorama every hour to ensure consistent communication in the event unrelated network configuration changes have disrupted connectivity between the firewall and Panorama or if implications to a pushed committed configuration may have affected connectivity. If an hourly connectivity check fails, the firewall generates a system log to alert admins of potential configuration or network connectivity issues. Additionally, a system log is generated when you disable the setting, a connectivity test fails, or when a firewall configuration reverts to the last running configuration.
In high availability (HA) firewall configurations, each HA peer performs connectivity tests independently of each other, and HA config syncs may only occur after each HA successfully tests connectivity to Panorama and verifies their connection.
  1. Log in to the Panorama Web Interface.
  2. Select DeviceSetupManagement.
  3. In the Template context drop-down, select the template or template stack that manages the devices for which you would like to configure the automated commit recovery parameters.
  4. Configure the automated commit recovery settings.
    1. Edit (
      ) the Panorama Settings.
    2. Verify that Enable automated commit recovery is enabled (checked).
    3. Enter the Number of attempts to check for Panorama connectivity.
    4. Enter the Interval between retries.
    5. Click OK to save your configuration changes.
  5. Repeat Steps 3 and 4 for templates or template stacks as needed.
  6. Select Commit and Commit and Push your configuration changes.