: Install the Panorama Plugin for Cisco TrustSec
Focus

Install the Panorama Plugin for Cisco TrustSec

Table of Contents

Install the Panorama Plugin for Cisco TrustSec

To get started with endpoint monitoring with Cisco TrustSec, download and install the Cisco TrustSec plugin on Panorama. To correlate the plugin version with the Panorama version, see Panorama Plugins in the Compatibility Matrix.
Beginning with PAN-OS 12.1.2, you no longer have to manually find and download compatible plugin versions before installing them. Now, compatible plugins are automatically downloaded with the Panorama image, and you can directly install the ones you need. For more information on plugin bundling, see Panorama Plugins.
Cisco TrustSec plugin upgrade or downgrade requires a commit.
If you have a Panorama HA configuration, repeat this installation process on each Panorama peer. When installing the plugin on Panorama appliances in an HA pair, install the plugin on the passive peer before the active peer. After installing the plugin on the passive peer, it will transition to a non-functional state. Installing the plugin on the active peer returns the passive peer to a functional state.
If you have a standalone Panorama or two Panorama appliances installed in an HA pair with multiple plugins installed, plugins might not receive updated IP-tag information if one or more of the plugins is not configured. This occurs because Panorama will not forward IP-tag information to unconfigured plugins. Additionally, this issue can occur if one or more of the Panorama plugins is not in the Registered or Success state (positive state differs on each plugin). Ensure that your plugins are in the positive state before continuing or executing the commands described below.
If you encounter this issue, there are two workarounds:
  • Uninstall the unconfigured plugin or plugins. It is recommended that you do not install a plugin that you do not plan to configure right away
  • You can use the following commands to work around this issue. Execute the following command for each unconfigured plugin on each Panorama instance to prevent Panorama from waiting to send updates. If you do not, your firewalls may lose some IP-tag information.
    request plugins dau plugin-name <plugin-name> unblock-device-push yes
    You can cancel this command by executing:
    request plugins dau plugin-name <plugin-name> unblock-device-push no
The commands described are not persistent across reboots and must be used again for any subsequent reboots. For Panorama in HA pair, the commands must be executed on each Panorama.
  1. Select PanoramaPlugins.
  2. Click Check Now to get the latest version of the plugin.
  3. Select Download in the Action column to download the plugin.
  4. Select the version of the plugin and click Install in the Action column to install the plugin. Panorama will alert you when the installation is complete.
    Beginning with PAN-OS 12.1.2, you no longer have to manually find and download compatible plugin versions before installing them. Now, compatible plugins are automatically downloaded with the Panorama image, and you can directly install the ones you need. For more information on plugin bundling, see Panorama Plugins.