PAN-OS Firewall Connector
This section details how to configure the Palo Alto PAN-OS Firewall Connector, for standalone firewalls not managed by Panorama.
Prerequisites
On the firewall side, you need to create an administrator account for Horizon, with an admin role allowing XML API access to import certificates and edit the configuration.
After performing these steps, you will get the following information, required later:
-
the administrator login/username
-
the administrator password
How to configure PAN-OS Firewall Connector
1. Log in to Horizon Administration Interface.
2. Access PAN-OS Firewall Connectors from the drawer or card: .
3. Click on .
4. Fill the mandatory fields.
General
-
Name* (string input):
Enter a meaningful connector name. It must be unique for each connector. Horizon uses the name to identify the connector. -
Hostname* (string input):
Enter the firewall hostname or URL. -
Credentials* (select):
SelectLogincredentials containing the username and password created for Horizon in the firewall. -
Proxy (select):
The HTTP/HTTPS proxy to use. -
Timeout* (finite duration):
Maximum time Horizon waits for a response from the firewall. -
TLS Insecure (boolean):
If enabled, TLS validation will ignore expired, invalid or untrusted certificates.
| This is not recommended for production usage |
Assets identification
-
VSYS (string input):
Name of the virtual system to target, for multi-VSYS firewalls. -
Prefix* (string input):
Prefix of the certificate names on the firewall, used to identify the certificates managed by Horizon.
Actors and renewal management
These configuration elements mainly define the number of authorized interactions with the remote service on a defined period. For example, one needs to ensure that the remote service will not be contacted more than 5 times per 3 seconds. Throttle parallelism defines the number of times and Throttle duration the period of time. Therefore, on the above example, throttle parallelism would be set to 5 and throttle duration would be set to 3 seconds.
-
Throttle duration* (finite duration):
Must be a valid finite duration. -
Throttle parallelism* (int):
Number of deployments processed in parallel.
Deployment jobs retry
Deployments to this third party are run as asynchronous jobs. When a job fails, Horizon retries it using an exponential backoff strategy.
-
Attempts* (int):
Maximum number of retry attempts before the job is considered failed. -
Minimum backoff* (finite duration):
Delay to wait before the first retry. -
Maximum backoff* (finite duration):
Maximum delay between two retries, capping the exponential backoff. -
Random factor* (decimal):
Random jitter added to each delay to avoid simultaneous retries (e.g.0.1adds up to 10%).
5. Click on the save button.
You can update or delete
the PAN-OS Firewall Connector.
|
You will not be able to delete a PAN-OS Firewall Connector if it is referenced in any other configuration element. |