Install Panorama on KVM
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on KVM.
You can now deploy Panorama™ and a Dedicated Log Collector on KVM. Panorama deployed on KVM is Bring Your Own License (BYOL), supports all deployment modes (Panorama, Log Collector, and Management Only), and shares the same processes and functionality as the M-Series hardware appliances. For more information on Panorama modes, see Panorama Models.
- Download the Panorama virtual appliance image
- Log in to the Palo Alto Networks Support Portal.
- Select Software Updates and find the Panorama for KVM Base image.
- Download the latest available Panorama .qcow2 file.
- Create a new virtual machine image and add the Panorama
virtual appliance image for KVM to the Virtual Machine Manager.
- On the Virtual Machine Manager, select Create a new virtual machine.
- Select Import Existing disk image and click Forward.
- Browse and select the Panorama virtual appliance image volume and Choose volume.
- Click Forward.
- Configure the memory and CPU settings.Review the Setup Prerequisites for the Panorama Virtual Appliance for minimum resource requirements.If you plan to use the Panorama virtual appliance as a Dedicated Log Collector, ensure that you configure the appliance with the required resources during initial deployment. The Panorama virtual appliance does not remain in Log Collector mode if you resize the virtual machine after you deploy it, and this results in a loss of log data.
- Configure the Memory based
on the requirements for the desired operational mode.The Virtual Machine Manager may use MiB (mebibyte) to allocate memory depending on the version you are running. If MiB is used, be sure to correctly convert your required memory allocation to avoid under provisioning the Panorama virtual appliance.
- Configure the CPU based on the requirements for the desired operational mode.
- Click Forward.
- Configure the Memory based on the requirements for the desired operational mode.
- Name the Panorama virtual appliance, enable configuration
customization, and select the management interface bridge.
- Enter a descriptive Name for the Panorama virtual appliance.
- Customize configuration before install.
- Make a Network selection—select the bridge for the management interface and accept the default settings.
- Click Finish.
- Configure the virtual system disk settings.
- Select IDE Disk 1,
go to Advanced options, and select the following:
- Disk Bus—VirtIO or IDE, depending on your configuration.
- Storage format—qcow2
- Go to Performance options and set Cache mode to writethrough. This setting improves installation time and execution speed on the Panorama virtual appliance.
- Click Apply.
- Select IDE Disk 1, go to Advanced options, and select the following:
- Configure the virtual machine console display
to use the VNC server to interact with the virtual machine.
- Select Display Spice.Continue to the next step if Display VNC is listed in the Hardware list because the virtual machine is already configured to use the VNC server for the display.
- In the Type drop-down, select VNC server.
- Click Apply.
- Select Display Spice.
- (Panorama and Log Collector mode) Add additional
storage for log collection. Repeat this step as needed to add additional
virtual logging disks.If you intend to use the Panorama virtual appliance in Panorama mode or as a Dedicated Log Collector, add the virtual logging disks during the initial deployment. By default, the Panorama virtual appliance is in Panorama mode for the initial deployment when you meet the Panorama mode resource requirements and have added at least one virtual logging disk. Otherwise, the Panorama virtual appliance defaults to Management Only mode. Change the Panorama virtual appliance to Management Only mode if you just want to manage devices and Dedicated Log Collectors, and to not collect logs locally.The Panorama virtual appliance on KVM only supports 2TB logging disks, and in total supports up to 24TB of log storage. You are unable to add a logging disk smaller than 2TB, or a logging disk with a size not divisible by the 2TB logging disk requirement. The Panorama virtual appliance partitions logging disks larger than 2TB into 2TB partitions.
- Add Hardware.
- Configure the new Storage disk:
- Create a disk image for a virtual machine and configure the virtual disk storage capacity to 14901.2 GiB (this is equivalent to 2TB).The Virtual Machine Manager may use GiB (gibibyte) to allocate memory depending on the version you are running. If GiB is used, be sure to correctly convert the required storage capacity to avoid under provisioning the virtual logging disk and sending the Panorama virtual appliance into maintenance mode.
- Set the Device type to Disk device.
- Set the Bus type to VirtIO or IDE, depending on your configuration.
- Go to Advanced options and set Cache mode to writethrough.
- Click Finish.
- Begin Installation ( ). The Panorama virtual appliances takes approximately 10 minutes to boot.
- Configure the network access settings for the management
- Open a connection to the console.
- Log in to the firewall using the default username and password: admin/admin.
- Enter configuration mode using the following command:
- Use the following commands to configure and enable
access to the management interface:
admin# set deviceconfig system type static admin# set deviceconfig system ip-address <Panorama-IP> netmask <netmask> default-gateway <gateway-IP> dns-setting servers primary <DNS-IP>where <Panorama-IP> is the IP address you want to assign to the management interface, <netmask> is the subnet mask, <gateway-IP> is the IP address of the network gateway, and <DNS-IP> is the IP address of the DNS server.
- Activate the device management license and support license on the Panorama virtual appliance.
- Complete configuring the Panorama virtual appliance for
your deployment needs.
- (Management Only mode) Set up a Panorama Virtual Appliance in Management Only Mode.
- (Log Collector mode) Begin at Step 6 to Switch from Panorama mode to Log Collector mode.Enter the Public IP address of the Dedicated Log Collector when you Add the Log Collector as a managed collector to the Panorama management server. You cannot specify the IP Address, Netmask, or Gateway.
- (Panorama and Management Only mode) Configure a Managed Collector to add a Dedicated Log Collector to the Panorama virtual appliance. Management Only mode does not support local log collection, and requires a Dedicated Log Collector to store managed device logs.
Install Panorama on Azure
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Amazon Web Services. ...
Install Panorama on Hyper-V
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Hyper-V. ...
Add a Virtual Disk to Panorama on KVM
Add a virtual logging disk to Panorama™ in Panorama or Log Collector mode on KVM. ...
Install Panorama on Google Cloud Platform
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector on Google™ Cloud Platform (GCP). ...
Setup Prerequisites for the Panorama Virtual Appliance
Minimum system requirements and instance recommendations for Panorama on AWS. ...
Install Panorama on AWS
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector in Amazon Web Services. ...
Set Up the Panorama Virtual Appliance
Set Up the Panorama Virtual Appliance The Panorama virtual appliance enables you to use your existing VMware virtual infrastructure to centrally manage and monitor Palo ...
Install Panorama on AWS GovCloud
How to deploy a Panorama™ virtual appliance and a virtual Dedicated Log Collector in Amazon Web Services GovCloud. ...
Install the Panorama Virtual Appliance
Install the Panorama Virtual Appliance Before installation, decide whether to run the virtual appliance in Panorama mode, Management Only mode, Log Collector mode, or Legacy ...