Panorama: Key Security Features Management
Panorama: Key Security Features Management
Panorama: Key Security Features Management
Security deployments are complex and can overload IT teams with complex
security rules and mountains of data from multiple sources. Panorama™ network
security management empowers you with easy-to-implement, consolidated policy
creation and centralized management features. Set up and control firewalls centrally
with industry-leading functionality and an efficient rule base, and gain insight into
network-wide traffic and threats.
Deployment Flexibility
You can deploy Panorama either as a
hardware or virtual appliance. PN
Hardware Appliances
Panorama can be deployed as the
M-100, M-200, M-500 or M-600
management appliance.
Virtual Appliances
Panorama can be deployed as a virtual
Log collector Log collector Log collector Logging Service
appliance on VMware® ESXi™ or in (hardware) (private cloud) (public cloud)
public cloud environments, including
Amazon® Web Services, or AWS®, and Figure 5: Panorama log management
Microsoft® Azure®.
Deployment Modes
You can separate management and logging functions of Panorama using deployment modes. The three supported
deployment modes are:
1. Panorama: Panorama controls both policy and log management functions for all managed devices.
2. Management Only: Panorama manages configurations for the managed devices but does not collect or manage logs.
3. Log Collector; Panorama collects and manages logs from managed devices. This assumes another deployment of
Panorama is operating in Management Only mode.
The separation of management and log collection enables the Panorama deployment to meet scalability, organizational and
geographic requirements. The choice of form factor and deployment mode gives you the maximum flexibility for managing
Palo Alto Networks next-generation firewalls in a distributed network.
Deployment Scale
The Panorama Interconnect plugin
connects multiple Panorama instances
to scale firewall management to tens of PN
thousands of firewalls. By leveraging the
Controller
plugin, the Panorama Controller allows
you to synchronize the configuration,
quickly onboard firewalls, and schedule
content updates from a central location
(see Figure 6). This lets you simplify man-
agement by centrally defining security
policies and distributing them across all PN PN PN PN
your firewalls regardless of their location 1 2 3 4
– on-premises or in the cloud.
Note: Panorama Interconnect is supported
only on Panorama M-600 appliances or
similarly resourced VMs.
Figure 6: Synchronized configuration across all firewalls
3000 Tannery Way © 2018 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 trademark of Palo Alto Networks. A list of our trademarks can be found at
Main: +1.408.753.4000 https://www.paloaltonetworks.com/company/trademarks.html. All other
Sales: +1.866.320.4788 marks mentioned herein may be trademarks of their respective companies.
Support: +1.866.898.9087 panorama-ds-082918
www.paloaltonetworks.com