Panorama Connector

This section details how to configure the Palo Alto Panorama Connector.

Required By

Prerequisites

On the Panorama side, you need to create an administrator account for Horizon, with an admin role allowing XML API access to import certificates, edit the configuration and, if devices are synchronized, commit and push the configuration.

After performing these steps, you will get the following information, required later:

  • the administrator login/username

  • the administrator password

How to configure Panorama Connector

1. Log in to Horizon Administration Interface.

2. Access Panorama Connectors from the drawer or card: Third Parties  Panorama  Connectors.

3. Click on Add Connector.

4. Fill the mandatory fields.

General

  • Name* (string input):
    Enter a meaningful connector name. It must be unique for each connector. Horizon uses the name to identify the connector.

  • Hostname* (string input):
    Enter the Panorama hostname or URL.

  • Credentials* (select):
    Select Login credentials containing the username and password created for Horizon in Panorama.

  • Proxy (select):
    The HTTP/HTTPS proxy to use.

  • Timeout* (finite duration):
    Maximum time Horizon waits for a response from Panorama.

  • TLS Insecure (boolean):
    If enabled, TLS validation will ignore expired, invalid or untrusted certificates.

This is not recommended for production usage

Assets identification

  • Template (string input):
    Name of the Panorama template to push certificates to.

  • Template stack (string input):
    Name of the Panorama template stack to push changes to.

  • VSYS (string input):
    Name of the virtual system to target within the template. Requires Template to be set.

  • Prefix* (string input):
    Prefix of the certificate names on Panorama, used to identify the certificates managed by Horizon.

  • Synchronize devices (boolean):
    If enabled, Horizon commits the configuration to the devices managed by Panorama after pushing the certificate. Otherwise, the certificate stays in the Panorama candidate configuration until an operator commits it.

Actors and renewal management

These configuration elements mainly define the number of authorized interactions with the remote service on a defined period. For example, one needs to ensure that the remote service will not be contacted more than 5 times per 3 seconds. Throttle parallelism defines the number of times and Throttle duration the period of time. Therefore, on the above example, throttle parallelism would be set to 5 and throttle duration would be set to 3 seconds.

  • Throttle duration* (finite duration):
    Must be a valid finite duration.

  • Throttle parallelism* (int):
    Number of deployments processed in parallel.

Deployment jobs retry

Deployments to this third party are run as asynchronous jobs. When a job fails, Horizon retries it using an exponential backoff strategy.

  • Attempts* (int):
    Maximum number of retry attempts before the job is considered failed.

  • Minimum backoff* (finite duration):
    Delay to wait before the first retry.

  • Maximum backoff* (finite duration):
    Maximum delay between two retries, capping the exponential backoff.

  • Random factor* (decimal):
    Random jitter added to each delay to avoid simultaneous retries (e.g. 0.1 adds up to 10%).

5. Click on the save button.

You can update Edit Connector or delete Delete Connector the Panorama Connector.

You will not be able to delete a Panorama Connector if it is referenced in any other configuration element.