Install Updates Automatically for Panorama without an Internet
Connection
Use an SCP server to download dynamic updates from an
outer Panorama™ management server to firewalls, WildFire
®
appliances,
and Log Collectors managed by an air-gapped Panorama.Automatically download dynamic updates to
firewalls, Log Collectors, and WildFire
®
appliances in
air-gapped networks where the Panorama™ management server, managed
firewalls, Log Collectors, and WildFire appliances are not connected
to the internet. To accomplish this, you must deploy an additional
Panorama with internet access and an SCP server. After you deploy
the Panorama with internet access, you configure the internet-connected
Panorama to automatically download dynamic updates to the SCP server.
From the SCP server, the air-gapped Panorama is configured to automatically
download and install dynamic updates as per your dynamic updates
schedule. Panorama generates a system log when the Panorama with
internet access downloads dynamic updates to the SCP server or when
the air-gapped Panorama downloads and installs dynamic updates from
the SCP server.Only the following dynamic update schedules
from an internet-connected Panorama to a Panorama without an internect
connection are supported:
Do not manipulate
or change the dynamic update file name after you successfully download
it to the SCP server. Panorama cannot download and install dynamic
updates with altered file names. Additionally, for the automatic
dynamic update to be successful, you must ensure that there is enough
disk space on the SCP server, that the SCP server is running when
a download is about to start, and that both Panoramas are powered on
and not in the middle of a reboot.
This example shows
how to configuring the automatic content updates for Applications
and Threats dynamic updates.
- Deploy an SCP server.Dynamic updates for managed firewalls, Log Collectors, and WildFire appliances downloads from the internet-connected Panorama. The air-gapped Panorama downloads the dynamic updates from the SCP server and then installs the updates on managed firewalls, WildFire appliances, and Log Collectors.When you create the folder directory for dynamic updates, it is a best practice to create a folder for each type of type of dynamic update. This is the burden of managing a large volume of dynamic updates and reduces the possibility of deleting dynamic updates that should not be deleted from the SCP server.
- Deploy the internet-connected Panorama.This Panorama communicates with the Palo Alto Networks update server and downloads the dynamic updates to the SCP server.
- Set up the Panorama management server.
- Perform the initial Panorama configuration.
- Deploy the Panorama without an internet connection.This Panorama communicates with the SCP server to download and install dynamic updates on managed firewalls, Log Collectors, and WildFire appliances.
- Set up the Panorama management server.
- Perform the initial Panorama configuration.
- Add your managed firewalls, Log Collectors, and WildFire appliances.
- Configure the internet-connected Panorama to download dynamic updates to your SCP server.
- Create an SCP server profile.
- SelectandPanoramaServer ProfilesSCPAdda new SCP server profile.
- Enter a descriptiveNamefor the SCP server profile.
- Enter the SCPServerIP address.
- Enter thePort.
- Enter the SCP serverUser Name.
- Enter the SCP serverPasswordandConfirm Password.
- ClickOKto save your changes.
- Create a dynamic updates schedule to regularly download dynamic updates to the SCP server.You must create a schedule for each type of dynamic update you intend to automatically download and install on managed firewalls, Log Collectors, and WildFire appliances.
- Select, selectPanoramaDevice DeploymentDynamic UpdatesSchedules, andAdda dynamic updates schedule.
- Enter a descriptiveNamefor the dynamic updates schedule.
- For theDownload Source, selectUpdate Server.
- Select the dynamic updateType.
- Select theRecurrenceto set the interval at which Panorama checks the Palo Alto Networks update server for new dynamic updates.To configure a more precise recurrence schedule, enter the number of minutes past the selected recurrence interval. If you have multiple dynamic updates scheduled to download using the same recurrence interval, stagger them to avoid overloading the Panorama and SCP server.
- For theAction, selectDownload And SCP.
- Select theSCP Profileyou configured in the previous step.
- Enter theSCP Pathfor the dynamic updates type.
- (Optional) Enter theThreshold, in hours, for the dynamic updates. Panorama downloads only dynamic updates that are this number of hours old (or older)
- ClickOKto save your changes.
- Commityour changes.
- Configure the air-gapped Panorama to download dynamic updates from the SCP server and then install the updates on your managed firewalls, Log Collectors, and WildFire appliances.
- Create an SCP server profile.
- SelectandPanoramaServer ProfilesSCPAdda new SCP server profile.
- Enter a descriptiveNamefor the SCP server profile.
- Enter the SCPServerIP address.
- Enter thePort.
- Enter the SCP serverUser Name.
- Enter the SCP serverPasswordandConfirm Password.
- ClickOKto save your changes.
- Create a dynamic updates schedule to regularly download and install dynamic updates from the SCP server.You must create a schedule for each type of dynamic update you intend to automatically download and install on managed firewalls, Log Collectors, and WildFire appliances.
- Select, selectPanoramaDevice DeploymentDynamic UpdatesSchedules, andAdda dynamic updates schedule.
- Enter a descriptiveNamefor the dynamic updates schedule.
- For theDownload Source, selectSCP.
- Select theSCP Profileyou configured in the previous step.
- Enter theSCP Pathfor the dynamic updates type.
- Select the dynamic updateType.
- Select theRecurrenceto set the interval at which Panorama checks the Palo Alto Networks update server for new dynamic updates.To configure a more precise recurrence schedule, enter the number of minutes past the selected recurrence interval. If you have multiple dynamic updates scheduled to download using the same recurrence interval, stagger them to avoid overloading the Panorama and SCP server.
- For theAction, selectDownloadorDownload And Install.OnlyDownloadandDownload and Installare supported when theDownload SourceisSCP.If you selectDownload, you must manually start the dynamic update install on your managed firewalls.
- Select theDeviceson which to install the dynamic updates.
- (Optional) Enter theThreshold, in hours, for the dynamic updates. Panorama downloads only dynamic updates that are this number of hours old (or older)
- ClickOKto save your changes.
- Commityour changes.
Recommended For You
Recommended Videos
Recommended videos not found.