26
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Panorama
Recommended
Deployments
Panorama
Overview
Panorama
in
a
Distributed
Log
Collection
Deployment
The
hardware
‐
based
Panorama—the
M
‐
100
appliance—can
be
deployed
either
as
a
Panorama
management
server
that
performs
management
and
log
collection
functions
or
as
a
dedicated
Log
Collector
that
provides
a
comprehensive
log
collection
solution
for
the
firewalls
on
your
network.
Using
the
M
‐
100
appliance
as
a
Log
Collector
allows
for
a
more
robust
environment
where
the
log
collection
process
is
offloaded
to
a
dedicated
appliance.
Using
a
dedicated
appliance
in
a
Distributed
Log
Collection
(DLC)
deployment
provides
redundancy,
improved
scalability,
and
capacity
for
longer
term
log
storage.
In
a
DLC
deployment,
the
Panorama
management
server
(Panorama
virtual
appliance
or
an
M
‐
100
appliance
in
Panorama
mode)
manages
the
firewalls
and
the
Log
Collectors.
Using
Panorama,
the
firewalls
are
configured
to
send
logs
to
one
or
more
Log
Collectors;
Panorama
can
then
be
used
to
query
the
Log
Collectors
and
provide
an
aggregated
view
of
network
traffic.
In
a
DLC
configuration,
the
logs
stored
on
the
Log
Collectors
are
accessible
from
both
the
primary
and
secondary
Panorama
peers
in
a
high
availability
(HA)
pair.
In
the
following
topology,
the
Panorama
peers
in
an
HA
configuration
manage
the
deployment
and
configuration
of
firewalls
running
PAN
‐
OS
4.x
and
5.x
or
6.x.
This
solution
provides
the
following
benefits:
Allows
for
improved
performance
in
the
management
functions
on
Panorama
Provides
high
‐
volume
log
storage
on
a
dedicated
hardware
appliance
Provides
horizontal
scalability
and
redundancy
with
RAID
1
storage