Automatically push dynamic content updates to VM-Series
and CN-Series firewalls on first connection to the Panorama™ management
server.
PAN-OS 10.2 introduces the ability to automatically push the latest Antivirus and Applications
and Threats content updates on first connection when onboarding a new
VM-Series and
CN-Series firewall to the Panorama™
management server. When leveraging auto-scale, enabling this setting allows you to
maintain existing images for VM-Series and CN-Series firewalls leveraging dynamic
content in their configurations, such as in policies and App-ID. This helps
eliminate the operational overhead required to update VM-Series and CN-Series
firewall images when new dynamic content update versions are introduced.
Panorama attempts to push the installed dynamic content updates on the first
connection only and does not attempt any subsequent pushes if the initial push fails
for any reason.
For example, you
add a VM-Series firewall to Panorama
management and enable
Auto Push on 1st Connect to
automatically push the device group and template stack configuration to the
VM-Series firewall on first connection. However, the template stack contains an
invalid configuration and the push to the VM-Series firewall fails. In this
scenario, the automatic content push to the VM-Series firewall also fails because
the configuration push and dynamic content version push are included in the same
push operation to the VM-Series firewall.