Working with Panorama Templates

What are Panorama Templates?

To use Panorama for managing Palo Alto Networks firewalls, you must add the firewalls as managed devices and then assign them to device groups and templates. Panorama Templates allow you manage the configuration options on the Device and Network tabs on the managed firewalls. Using templates you can define a base configuration for centrally staging new firewalls and then make device-specific exceptions in configuration, if required. For example, you can use templates to define administrative access to the device, set up User-ID, manage certificates, set up the firewalls in a high availability pair, define log settings, and define server profiles on the managed firewalls.

How can I create a template?

Until you add a template on Panorama, the Device and Network tabs required to define the network set up elements and device configuration elements on the firewall will not display.

When creating templates, make sure to assign similar devices to a template. For example, group devices with a single virtual system in a one template and devices enabled for multiple virtual systems in another template, or group devices that require very similar network interface and zone configuration in a template.

After adding a template you can then use the template to administer a base configuration.

To delete/remove a template, you must first Disable/Remove Template Settings on the managed firewall locally.

Where can I find tips on troubleshooting template commit failures?

If you receive commit errors after creating and committing a template, see the topic diagnose and resolve template commit failures.

For more information on working with templates, see Manage Firewalls in the Panorama Administrator’s Guide Version 6.1.

[Palo Alto Networks Blog]

Get Started with Threat Prevention

How does the Palo Alto Networks Next-Generation Firewall prevent threats?

The Palo Alto Networks Next-Generation Firewall protects and defends your network from commodity threats and advanced persistent threats (APTs). The firewall’s multi-pronged detection mechanisms include a signature-based (IPS/Command and Control/Antivirus) approach, heuristics-based (bot detection) approach, sandbox-based (WildFire) approach, and Layer 7 protocol analysis-based (App-ID) approach.

Fantastic! Where can I read more about threat prevention?

Here are some resources from our 6.1 documentation to get you started:

To view a list of Threats and Applications that Palo Alto Networks products can identify, use the following links:

  • Applipedia—Provides details on the applications that Palo Alto Networks can identify.
  • Threat Vault—Lists threats that Palo Alto Networks products can identify. You can search by Vulnerability, Spyware, or Virus. Click the Details icon next to the ID number for more information about a threat.

[Palo Alto Networks Blog]

Why Put Up With Complex Network Security Management?

In this latest of our lightboard sessions, Joerg Sieber maps out important updates to Panorama and how you can simplify policy and device management without sacrificing good data or business productivity.

For more

[Palo Alto Networks Blog]

Now Available: On-Demand Next-generation Firewall for Amazon Web Services

As more organizations incorporate Amazon Web Services (AWS) into their data center architectures, the value of immediate access to complete computing environments becomes apparent. In a matter of a few minutes, AWS customers can scale their data centers to address seasonal spikes in computing demand driven by the nature of their business, while preserving the agility and resiliency they sought when choosing AWS in the first place.

Security has to keep up. That’s why our VM-Series for AWS can be deployed on-demand with your new AWS projects.

VM-Series for AWS Usage-based Licensing

Our recently released PAN-OS 7.0 introduced the ability to select and purchase a predefined VM-Series for AWS bundle directly from AWS on either an hourly or annual subscription basis. AWS users can choose from two bundles, both of which include a VM-300 firewall, subscriptions and support as shown in the table below. (Note that the VM-Series for AWS bring-your-own-license model is also still available.) See descriptions of the available bundles here.

But Wait, There’s More!

The new licensing model allows us to take advantage of the AWS Free Trial and Test Drive programs, which enable you to gain hands-on experience with the Palo Alto Networks VM-Series firewall in an AWS environment.

  • Free Trial: Select from one of the two available bundles and deploy them in your AWS account for 15 days. At the end of the 15-day period, you can choose to continue with a usage-based subscription (hourly or annual) or select the BYOL option and chose the options that best fit your needs. You can launch a Free Trial here.
  • Test Drive: Available as of June 29, the VM-Series for AWS Test Drive provides you with a guide tour of the VM-Series though the use of hands-on lab exercises. Lasting roughly an hour, the Test Drive allows you to build policies, troubleshoot, execute a simulated attack than is then blocked and perform forensics. You can take a Test Drive here. Once your Test Drive is complete, you can chose which licensing option, BYOL or usage-based best fits your needs.

Both of these AWS programs allow you to gain hands-on experience with the rich set of features that the VM-Series for AWS provides.

See us at upcoming AWS Summits

As they say at Apple, One. More. Thing. We’ll be participating in some of the upcoming AWS Summits this week and next week so come see Palo Alto Networks if you want to hear more about how we can help you protect your AWS environment with our next-generation firewall functionality including:

  • Visibility into application traffic
  • Application enablement at the gateway
  • Segmentation between applications (VPCs)
  • Advanced threat prevention

Join Palo Alto Networks:

[Palo Alto Networks Blog]

Better Threat Intelligence and Information Sharing Among Global Retailers

The increasing volume and sophistication of cyber threats means all organizations must evolve their security posture. This is especially important in retail: a business environment in which undetected cyber attacks can negatively affect customer loyalty and hurt brand reputation among consumers.

Helping retailers realize the benefits of next-generation security — and prevent breaches — is one reason Palo Alto Networks has joined the Retail Cyber Intelligence Sharing Center (R-CISC) through its Associate Member Program. The Associate Member Program allows the R-CISC’s retailer and commercial services member organizations to collaborate and share threat intelligence and critical cybersecurity information in real time with the industry’s leading security solutions providers.

Our participation in R-CISC means that R-CISC members will receive access to Palo Alto Networks threat intelligence, including information on advanced attacks, campaigns and adversaries from the AutoFocus and WildFire services, and the Unit 42 research and analysis team.

For more

[Palo Alto Networks Blog]

English
Exit mobile version