84
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Add
a
Firewall
as
a
Managed
Device
Manage
Firewalls
Add
a
Firewall
as
a
Managed
Device
To
use
Panorama
for
central
management
of
firewalls,
the
first
step
is
to
add
them
as
managed
devices.
Before
starting,
collect
the
firewall
serial
numbers
and
prepare
each
firewall
as
follows:
Perform
initial
configuration
on
the
firewall
so
that
it
is
accessible
and
can
communicate
with
Panorama
over
the
network.
For
details,
refer
to
the
Add
the
Panorama
IP
address(es)
(one
server
or
two,
if
Panorama
is
configured
in
a
high
availability
pair)
in
the
Panorama
Settings
section
of
the
Device > Setup> Management
tab
and
commit
the
changes.
Set
up
the
data
interfaces.
For
each
interface
you
plan
to
use,
select
the
interface
type
and
attach
it
to
a
security
zone
so
that
you
can
push
configuration
and
policy
from
Panorama.
For
details,
refer
to
the
.
You
can
then
add
the
firewalls
as
managed
devices
on
Panorama:
When
you
add
a
firewall
as
a
managed
device,
it
uses
an
SSL
connection
with
AES
‐
256
encryption
to
register
with
Panorama.
Panorama
and
the
firewall
authenticate
each
other
using
2,048
‐
bit
certificates
and
use
the
SSL
connection
for
configuration
management
and
log
collection.
Add
a
Firewall
as
a
Managed
Device
Step
1
Add
device(s)
to
Panorama.
1.
Select
Panorama > Managed Devices.
2.
Click
Add
and
enter
the
serial
number
for
each
device
that
you
want
to
manage
centrally
using
Panorama.
Add
only
one
entry
per
line.
3.
Click
OK
.
The
Managed
Devices
pane
displays
the
new
device.
4.
(Optional)
Add
a
Tag
.
Tags
make
it
easier
for
you
to
find
a
device
from
a
large
list;
they
help
you
to
dynamically
filter
and
refine
the
list
of
firewalls
that
display.
For
example,
if
you
add
a
tag
called
branch
office,
you
can
filter
for
all
branch
office
devices
across
your
network.
a.
Select
the
check
box
beside
the
managed
device
and
click
Tag
.
b.
Click
Add
,
enter
a
string
of
up
to
31
characters
(no
empty
spaces),
and
click
OK
.
5.
Click
Commit
,
for
the
Commit Type
select
Panorama
,
then
click
OK
.
Step
2
Verify
that
the
device
is
connected
to
Panorama.
If
the
firewall
is
accessible
on
the
network
and
the
Panorama
IP
address
is
configured
on
the
device,
Panorama
must
be
able
to
connect
to
the
device.