Checking Firewall Health and Status from Panorama (Version 11.0)

PCNSE Objective Focus

This topic aligns with PCNSE objectives related to monitoring the status and operational health of devices managed by Panorama.

Overview: Centralized Monitoring Power

Panorama provides a centralized platform not only for configuration but also for monitoring the operational health and status of its managed firewalls and Log Collectors. Regularly checking device status from Panorama allows administrators to proactively identify potential issues, verify connectivity, ensure configuration consistency, and maintain overall network security posture.

Key aspects monitored via Panorama include:

Utilizing Panorama's monitoring tools is essential for efficient management of a Palo Alto Networks environment.

Managed Devices > Summary View

The primary dashboard for a quick overview of all managed devices (Firewalls and Log Collectors) is found at Panorama > Managed Devices > Summary .

This view provides critical status indicators in sortable columns:

This view is ideal for quickly identifying devices that are disconnected, out of sync, or running outdated software/content.

You can filter and sort this view based on different columns (e.g., sort by 'Connection' to bring disconnected devices to the top).

Managed Devices > Health View

For more detailed resource monitoring of individual firewalls, navigate to Panorama > Managed Devices > Health .

This section polls selected managed firewalls (you may need to enable monitoring for specific devices) and displays near real-time and historical performance metrics, including:

The Health view is particularly useful for:

Data collection for the Health view needs to be enabled and configured. It relies on Panorama periodically polling the firewalls, so it reflects near real-time data but isn't instantaneous.

Key Status Indicators and Their Meanings

Understanding the status messages in the 'Connection', 'Shared Policy Status', and 'Device Config Status' columns is crucial:

Status Indicator Column(s) Meaning Common Causes / Next Steps
Connected Connection The firewall has an active and healthy management connection to Panorama. Normal operating state.
Disconnected Connection Panorama cannot establish a management connection to the firewall. Network reachability issue (routing, firewall rules blocking mgmt traffic), device powered off, device certificate issue, Panorama service down on firewall. Investigate connectivity.
Connection status mismatch Connection The firewall is connected, but there might be an issue with the secure channel or component mismatch (less common). Check certificates, PAN-OS component status, potential need to restart management server on firewall. Check system logs.
In sync Shared Policy Status, Device Config Status The configuration pushed from Panorama (for that scope - DG or Template) matches the running configuration on the firewall. Normal operating state.
Out of sync Shared Policy Status, Device Config Status The configuration on the firewall does not match the configuration intended by Panorama for that scope. A recent commit/push may have failed, local changes might have been made on the firewall overriding Panorama, or a push is needed. Perform a Commit & Push from Panorama for the relevant DG/Template.
Pending Shared Policy Status, Device Config Status Panorama has changes staged for this device/scope that have been committed locally on Panorama but not yet pushed to the firewall. Perform a Commit & Push from Panorama, or use 'Push to Devices'.
Commit Required Shared Policy Status, Device Config Status Changes affecting this device/scope have been made in Panorama but not yet committed locally on Panorama. Perform a Commit (or Commit & Push) on Panorama.
N/A Shared Policy Status, Device Config Status Status is not applicable, often seen for disconnected devices or devices not assigned to a DG/Template. Check connection status and DG/Template assignment.

Panorama Dashboard Widgets

The main Panorama > Dashboard tab can be customized with various widgets that provide summarized health and status information.

Useful widgets include:

Configuring relevant widgets provides an immediate, high-level view of the overall health of your managed devices upon logging into Panorama.

Using Logs and Task Manager

For deeper analysis and troubleshooting specific status issues:

Logs provide the detailed history needed to understand *why* a device might be disconnected or out of sync.

Best Practices for Monitoring

Caveats / Gotchas / Considerations

PCNSE Exam Focus (Relevant to 11.0 Concepts)

References (Version 11.0)

These links point to the relevant sections within the official Palo Alto Networks documentation for Panorama version 11.0.