Cloud Computing

4 Mins Read

Operational Guide for Managing Palo Alto Security Infrastructure

Voiced by Amazon Polly

Overview

This blog post provides a comprehensive operational guide for administering Palo Alto Networks security infrastructure, specifically focusing on Panorama, VM-Series, and CN-Series firewalls.

It outlines routine activities such as access management, onboarding firewalls, configuring policies, upgrading software, managing licenses, and viewing reports.

This guide is structured to help security and network administrators perform day-to-day operations with clarity and consistency.

Pioneers in Cloud Consulting & Migration Services

  • Reduced infrastructural costs
  • Accelerated application deployment
Get Started

Introduction

This document aims to provide a step-by-step SOP (Standard Operating Procedure) for managing Palo Alto security components.

Access Management

How to Access Panorama and Firewalls

  • Via Web UI or CLI using a secure bastion/jump host
  • Ensure only authorized users have access to the firewalls or Panorama

Adding New Administrator Users

  1. Go to Panorama, then Administrators, then Add
  2. Enter username, password, and select role
  3. Set the Administrator Type to Dynamic
  4. Use the appropriate password profile

palo

Firewall Management

Adding a New Firewall to Panorama

In the event of a firewall failure or provisioning a new VM-Series instance, follow these steps:

Generate Device Registration Auth Key

  1. Navigate to Panorama > Device Registration Auth Key

Include a key that contains the name, type, count, and lifetime.

palo2

Add the New Firewall

  1. Go to Panorama > Managed Devices > Summary → Add
  2. Paste the Authentication Key after entering the serial number.
  3. Associate:
    • Appropriate Device Group
    • Template (based on Availability Zone)
    • Log Collector

4. Enable Auto Push on First Connect

palo3

Configure Panorama on Firewall

  • Go to Firewall UI → Device > Setup > Management
  • Input Panorama IP and Auth Key
  • Commit changes on both the firewall and Panorama
  • Verify device status shows Connected

Associate GWLB Endpoints (If Applicable)

Use the CLI:

Check with:

Firewall Policy Management

Adding or Modifying Security Rules

  1. To access Pre Rules, select Policies > Security.
  2. Select Device Group (based on environment)

palo4

3. Define:

    • Rule Name, Source/Destination
    • Applications, Services
    • Actions (Allow/Deny), Log Forwarding

Firewall Object Management

Types of Objects You Can Create

  • Address Object: Static IP or FQDN
  • Static Address Group: Collection of addresses
  • Dynamic Address Group: Use match criteria (tags)
  • Service Object: Custom TCP/UDP ports
  • Custom URL Category: For specific domain filtering

palo5

Software and Content Updates

Panorama Software Upgrade

  1. Backup Panorama config:
    Setup > Operations > Save/Export
  2. Update all dynamic packages (AV, Threats, WildFire, URL)
  3. To access Pre Rules, click Policies, then Security
  4. Download, Install, and Reboot (if prompted)
  5. Validate software version on Dashboard

palo6

VM-Series Firewall Software Upgrade

  1. Export config backup:
    Setup > Operations > Export Config Bundle
  2. Update Dynamic Content:
    Device Deployment > Dynamic Updates
  3. Upgrade PAN-OS via:
    Device Deployment > Software > Install
  4. Reboot the firewall after installation
  5. Repeat for all AZ firewall instances

palo7

License Management

Refresh Existing Licenses

  • Go to Device Deployment > Licenses > Refresh

Activate New Licenses

  1. Go to Device Deployment, then click on Licenses > Activate
  2. Input Auth Code → Click Activate

Some support licenses may need to be activated directly from the firewall interface.

palo8

Custom Reports

  1. Go to Manage Custom Reports
  2. Add or edit reports with required filters
  3. To generate click run and download reports

palo9

Conclusion

This guide offers an actionable reference for the day-to-day operations of Palo Alto Networks’ security infrastructure. Admins can ensure secure, up-to-date, and resilient firewall management using Panorama by following these structured procedures.

Drop a query if you have any questions regarding Palo Alto Networks’ and we will get back to you quickly.

Empowering organizations to become ‘data driven’ enterprises with our Cloud experts.

  • Reduced infrastructure costs
  • Timely data-driven decisions
Get Started

About CloudThat

CloudThat is an award-winning company and the first in India to offer cloud training and consulting services worldwide. As a Microsoft Solutions Partner, AWS Advanced Tier Training Partner, and Google Cloud Platform Partner, CloudThat has empowered over 850,000 professionals through 600+ cloud certifications winning global recognition for its training excellence including 20 MCT Trainers in Microsoft’s Global Top 100 and an impressive 12 awards in the last 8 years. CloudThat specializes in Cloud Migration, Data Platforms, DevOps, IoT, and cutting-edge technologies like Gen AI & AI/ML. It has delivered over 500 consulting projects for 250+ organizations in 30+ countries as it continues to empower professionals and enterprises to thrive in the digital-first world.

FAQs

1. Do I need to reboot after every software update?

ANS: – Only if prompted. Panorama and firewalls may or may not require a reboot depending on the update version.

2. Can I rollback a firewall upgrade?

ANS: – Yes, if a config snapshot and the previous version are available. Always take a backup before upgrading.

3. Can I commit rules on Panorama without pushing them immediately?

ANS: – Yes, use Commit to Panorama and push later using Push to Devices.

WRITTEN BY Noopur Shrivastava

Noopur Shrivastava works as a Research Associate at CloudThat, where she is deeply passionate about cloud computing technologies such as AWS and Azure. She continuously strives to expand her knowledge and gain practical industry experience. As an effective communicator and strong team player, she is always eager to embrace new challenges and grow in her role. Her enthusiasm for learning and exploring emerging technologies, combined with her technical skills, enables her to contribute meaningfully to any team within the cloud domain.

Share

Comments

    Click to Comment

Get The Most Out Of Us

Our support doesn't end here. We have monthly newsletters, study guides, practice questions, and more to assist you in upgrading your cloud career. Subscribe to get them all!