This topic aligns with PCNSE objectives related to monitoring the status and operational health of devices managed by Panorama.
Panorama provides a centralized platform not only for configuration but also for monitoring the operational health and status of its managed firewalls and Log Collectors. Regularly checking device status from Panorama allows administrators to proactively identify potential issues, verify connectivity, ensure configuration consistency, and maintain overall network security posture.
Key aspects monitored via Panorama include:
Utilizing Panorama's monitoring tools is essential for efficient management of a Palo Alto Networks environment.
The primary dashboard for a quick overview of all managed devices (Firewalls and Log Collectors) is found at
Panorama > Managed Devices > Summary
.
This view provides critical status indicators in sortable columns:
This view is ideal for quickly identifying devices that are disconnected, out of sync, or running outdated software/content.
You can filter and sort this view based on different columns (e.g., sort by 'Connection' to bring disconnected devices to the top).
For more detailed resource monitoring of individual firewalls, navigate to
Panorama > Managed Devices > Health
.
This section polls selected managed firewalls (you may need to enable monitoring for specific devices) and displays near real-time and historical performance metrics, including:
The Health view is particularly useful for:
Data collection for the Health view needs to be enabled and configured. It relies on Panorama periodically polling the firewalls, so it reflects near real-time data but isn't instantaneous.
Understanding the status messages in the 'Connection', 'Shared Policy Status', and 'Device Config Status' columns is crucial:
Status Indicator | Column(s) | Meaning | Common Causes / Next Steps |
---|---|---|---|
Connected | Connection | The firewall has an active and healthy management connection to Panorama. | Normal operating state. |
Disconnected | Connection | Panorama cannot establish a management connection to the firewall. | Network reachability issue (routing, firewall rules blocking mgmt traffic), device powered off, device certificate issue, Panorama service down on firewall. Investigate connectivity. |
Connection status mismatch | Connection | The firewall is connected, but there might be an issue with the secure channel or component mismatch (less common). | Check certificates, PAN-OS component status, potential need to restart management server on firewall. Check system logs. |
In sync | Shared Policy Status, Device Config Status | The configuration pushed from Panorama (for that scope - DG or Template) matches the running configuration on the firewall. | Normal operating state. |
Out of sync | Shared Policy Status, Device Config Status | The configuration on the firewall does not match the configuration intended by Panorama for that scope. | A recent commit/push may have failed, local changes might have been made on the firewall overriding Panorama, or a push is needed. Perform a Commit & Push from Panorama for the relevant DG/Template. |
Pending | Shared Policy Status, Device Config Status | Panorama has changes staged for this device/scope that have been committed locally on Panorama but not yet pushed to the firewall. | Perform a Commit & Push from Panorama, or use 'Push to Devices'. |
Commit Required | Shared Policy Status, Device Config Status | Changes affecting this device/scope have been made in Panorama but not yet committed locally on Panorama. | Perform a Commit (or Commit & Push) on Panorama. |
N/A | Shared Policy Status, Device Config Status | Status is not applicable, often seen for disconnected devices or devices not assigned to a DG/Template. | Check connection status and DG/Template assignment. |
The main
Panorama > Dashboard
tab can be customized with various widgets that provide summarized health and status information.
Useful widgets include:
Configuring relevant widgets provides an immediate, high-level view of the overall health of your managed devices upon logging into Panorama.
For deeper analysis and troubleshooting specific status issues:
Panorama > Task Manager
) Shows the status (Success, Fail, Pending) of recent jobs initiated from Panorama, such as Commits, Pushes to Devices, Software/Content installs. Error messages here are crucial for diagnosing failed operations that lead to 'Out of sync' states.
Monitor > Logs > System
) for events related to device connectivity, commit operations initiated from Panorama, and Panorama's own health.
Monitor > Logs > System
, filter by device). Look for events related to HA failovers, management server restarts, commit operations performed locally, or specific errors reported by the firewall.
Logs provide the detailed history needed to understand *why* a device might be disconnected or out of sync.
Panorama > Managed Devices > Summary
.
Panorama > Managed Devices > Health
.
Panorama > Task Manager
) for diagnosing failed operations.
These links point to the relevant sections within the official Palo Alto Networks documentation for Panorama version 11.0.