Automatic Content Updates Through Offline Panorama
Table of Contents
10.0 (EoL)
Expand all | Collapse all
-
- Automatic Content Updates Through Offline Panorama
- Enhanced Authentication for Dedicated Log Collectors and WildFire Appliances
- Syslog Forwarding Using Ethernet Interfaces
- Increased Configuration Size for Panorama
- Access Domain Enhancements for Multi-Tenancy
- Enhanced Performance for Panorama Query and Reporting
- Log Query Debugging
- Configurable Key Limits in Scheduled Reports
- Multiple Plugin Support for Panorama
End-of-Life (EoL)
Automatic Content Updates Through Offline Panorama
Use an SCP server to download content updates from an
outer Panorama™ management server to firewalls, WildFire® appliances,
and Log Collectors managed by an air-gapped Panorama.
PAN-OS® 10.0 enables you to automatically
download content updates to firewalls, Log Collectors, and WildFire® appliances
in air-gapped networks where the Panorama™ management server and
the managed firewalls, Log Collectors, and WildFire appliances are
not connected to the internet. To accomplish this, you must deploy
an additional Panorama with internet access and an SCP server. After
you deploy the Panorama with internet access, you configure the
internet-connected Panorama to automatically download content updates
to the SCP server. From the SCP server, the air-gapped Panorama
is configured to automatically download and install dynamic updates
as per your dynamic updates schedule. Panorama generates a system
log when the Panorama with internet access downloads dynamic updates to
the SCP server or when the air-gapped Panorama downloads and installs
dynamic updates from the SCP server.
Do not manipulate or
change the dynamic update file name after you successfully download
it to the SCP server. Panorama cannot download and install dynamic updates
with altered file names. Additionally, for the automatic content
update to be successful, you must ensure that there is enough disk
space on the SCP server, that the SCP server is running when a download
is about to start, and that both Panoramas are powered on and not
in the middle of a reboot.
This example shows how to configuring
the automatic content updates for Applications and Threats dynamic
updates.
- Deploy an SCP server.Dynamic updates for managed firewalls, Log Collectors, and WildFire appliances downloads from the internet-connected Panorama. The air-gapped Panorama downloads the dynamic updates from the SCP server and then installs the updates on managed firewalls, WildFire appliances, and Log Collectors.When you create the folder directory for dynamic updates, it is a best practice to create a folder for each type of type of dynamic update. This is the burden of managing a large volume of dynamic updates and reduces the possibility of deleting dynamic updates that should not be deleted from the SCP server.
- Set up the Panorama with internet access.This Panorama communicates with the Palo Alto Networks update server and downloads the dynamic updates to the SCP server.
- Set Up Panorama.
- Log in to the Panorama web interface.
- Create an SCP server profile.
- Select PanoramaServer ProfilesSCP and Add a new SCP server profile.
- Enter a descriptive Name for the SCP server profile.
- Enter the SCP Server IP address.
- Enter the Port.
- Enter the SCP server User Name.
- Enter the SCP server Password and Confirm Password.
- Click OK to save your changes.
- Create a dynamic update schedule to
regularly download content updates to the SCP server.You must create a schedule for each type of dynamic update you intend to automatically download and install on managed firewalls, Log Collectors, and WildFire appliances.
- Commit your changes.
- Set up the air-gapped Panorama. This Panorama communicates with the SCP server to download the dynamic updates and then installs the updates on managed firewalls, Log Collectors, and WildFire appliances.
- Configure the air-gapped Panorama to download dynamic
updates from the SCP server and then install the updates on your
managed firewalls, Log Collectors, and WildFire appliances.
- Log in to the Panorama web interface.
- Create an SCP server profile.
- Select PanoramaServer ProfilesSCP and Add a new SCP server profile.
- Enter a descriptive Name for the SCP server profile.
- Enter the SCP Server IP address.
- Enter the Port.
- Enter the SCP server User Name.
- Enter the SCP server Password and Confirm Password.
- Click OK to save your changes.
- Create a dynamic update schedule to
regularly download content updates from the SCP server.You must create a schedule for each type of dynamic update you intend to automatically download and install on managed firewalls, Log Collectors, and WildFire appliances.
- Commit your changes.