Perform Initial Configuration of the Panorama Virtual Appliance
Based on your Panorama model, use the AWS, Azure, or GCP web interface, KVM Virtual Machine Manager, Hyper-V Manager, VMware vSphere Client, or vCloud Air web console to set up network access to the Panorama virtual appliance. By default, the Panorama virtual appliance is deployed in Panorama mode. For unified reporting, consider using Greenwich Mean Time (GMT) or Coordinated Universal Time (UTC) as the uniform time zone across Panorama and all the managed firewalls and Log Collectors.
- Gather the required information from your network
administrator.Collect the following information for the management (MGT) interface:
- IP address for the management (MGT) interface
- Default gateway
- DNS server IP addressTo complete the configuration of the MGT interface, you must specify the IP address, netmask (for IPv4) or prefix length (for IPv6), and default gateway. If you omit settings (such as the default gateway), you can access Panorama only through the console port for future configuration changes. As a best practice, always commit a complete MGT interface configuration.
- Access the console of the Panorama virtual appliance.
On AWS, Azure, GCP, KVM, and Hyper-V:
- Access the console.On an ESXi server:
- Launch the VMware vSphere Client.
- Select the Console tab for the Panorama virtual appliance and press enter to access the login screen.On vCloud Air:
- Access the vCloud Air web console and select your Virtual Private Cloud OnDemand region.
- Select the Virtual Machines tab, right-click the Panorama virtual machine, and select Open In Console.
- Enter your username and password to log in (default is admin for both).
- Access the console.
- Configure the network access settings for the MGT interface.Panorama uses the MGT interface for management traffic, high availability synchronization, log collection, and communication within Collector Groups.
- Enter the following commands, where <Panorama-IP> is
the IP address you want to assign to the Panorama management interface, <netmask> is
the subnet mask, <gateway-IP> is the IP address
of the network gateway, and <DNS-IP> is the
IP address of the DNS server:
> configure # set deviceconfig system ip-address <Panorama-IP> netmask <netmask> default-gateway <gateway-IP> dns-setting servers primary <DNS-IP> # commit # exit
- Use the ping utility to verify network access to external
services required for firewall management, such as the default gateway,
DNS server, and the Palo Alto Networks Update Server, as shown in
the following example:
admin@Panorama-Corp> ping host updates.paloaltonetworks.com PING updates.paloaltonetworks.com (126.96.36.199) 56(84) bytes of data. 64 bytes from 188.8.131.52: icmp_seq=1 ttl=243 time=40.5 ms 64 bytes from 184.108.40.206: icmp_seq=1 ttl=243 time=53.6 ms 64 bytes from 220.127.116.11: icmp_seq=1 ttl=243 time=79.5 msAfter verifying connectivity, press Ctrl+C to stop the pings.
- Enter the following commands, where <Panorama-IP> is the IP address you want to assign to the Panorama management interface, <netmask> is the subnet mask, <gateway-IP> is the IP address of the network gateway, and <DNS-IP> is the IP address of the DNS server:
- Configure the general settings.
- Using a secure connection (HTTPS) from a web browser, log in to the Panorama web interface using the IP address and password you assigned to the management interface (https://<IP address>).
- Select PanoramaSetupManagement and edit the General Settings.
- Enter a Hostname for the server and enter the network Domain name. The domain name is just a label; Panorama doesn’t use it to join the domain.
- Align the clock on Panorama and the managed firewalls
to use the same Time Zone, for example GMT
or UTC. If you plan to use the Logging Service, you must configure
NTP so that Panorama can stay in sync with the Logging Service.Timestamps are recorded when Panorama receives the logs and the managed firewalls generate the logs. Aligning the time zones on Panorama and the firewalls ensures that the timestamps are synchronized and the process of querying logs and generating reports on Panorama is harmonious.
- Enter the Latitude and Longitude to enable accurate placement of the Panorama management server on the world map.
- Enter the Serial Number you received in the order fulfillment email.
- Click OK to save your changes.
- Change the default administrator password.To ensure that the management interface remains secure, configure the Minimum Password Complexity (PanoramaSetupManagement).
- Click the admin link on the left side of the web interface footer.
- Enter the Old Password and the New Password in the appropriate fields and record the new password in a safe location.
- Click OK.
- (Optional) Modify the management interface settings.
- Select PanoramaSetupInterfaces and click Management.
- If your firewalls connect to the Panorama management server using a public IP address that is translated to a private IP address (NAT), enter the public IP in the Public IP Address field, and the private IP in the IP Address field to push both addresses to your firewalls.
- Select which Network Connectivity Services to allow
on the interface (such as SSH access).Don’t select Telnet or HTTP. These services use plaintext and are less secure than the other services.
- Click OK to save your changes to the interface.
- Commit your configuration changes.Select CommitCommit to Panorama and Commit your changes.
- Next steps...
- If necessary, Expand Log Storage Capacity on the Panorama Virtual Appliance.
- (Best Practice) Replace the default certificate that Panorama uses to secure HTTPS traffic over the management (MGT) interface.
- Activate a Panorama Support License
- Activate/Retrieve a Firewall Management License when the Panorama Virtual Appliance is Internet-connected
- Install Content and Software Updates for Panorama.
- Set Up Administrative Access to Panorama.
Install Panorama on Hyper-V
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Hyper-V. ...
Perform Initial Configuration of the M-Series Appliance
Perform Initial Configuration of the M-Series Appliance By default, Panorama has an IP address of 192.168.1.1 and a username/password of admin/admin. For security reasons, you ...
Install Panorama on AWS
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Amazon Web Services. ...
Set Up the M-Series Appliance as a Log Collector
Set Up the M-Series Appliance as a Log Collector If you want a dedicated appliance for log collection, configure an M-100, M-200, M-500, M-600 appliance ...
Panorama > Setup > Interfaces
Panorama > Setup > Interfaces Select Panorama Setup Interfaces to configure the interfaces that Panorama uses to manage firewalls and Log Collectors, deploy software and ...
Set Up The Panorama Virtual Appliance as a Log Collector
How to set up a Panorama virtual appliance on AWS, AWS GovCloud, Microsoft Azure, KVM, Hyper-V, or ESXi as a Dedicated Log Collector. ...
Perform Initial Configuration on the VM-Series on ESXi
Perform Initial Configuration on the VM-Series on ESXi Use the virtual appliance console on the ESXi server to set up network access to the VM-Series ...
Install Panorama on Google Cloud Platform
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Google Cloud Platform (GCP). ...
Panorama Virtual Appliance and Virtual Dedicated Log Collector on Google Cloud Platform
How to deploy a Panorama™ virtual appliance and virtual Dedicated Log Collector on Google® Cloud Platform (GCP™). ...