PAN-OS Firewall Connector

This section details how to configure the Palo Alto PAN-OS Firewall Connector, for standalone firewalls not managed by Panorama.

Prerequisites

On the firewall side, you need to create an administrator account for Horizon, with an admin role allowing XML API access to import certificates and edit the configuration.

After performing these steps, you will get the following information, required later:

  • the administrator login/username

  • the administrator password

How to configure PAN-OS Firewall Connector

1. Log in to Horizon Administration Interface.

2. Access PAN-OS Firewall Connectors from the drawer or card: Third Parties  PAN-OS Firewall  Connectors.

3. Click on Add Connector.

4. Fill the mandatory fields.

General

  • Name* (string input):
    Enter a meaningful connector name. It must be unique for each connector. Horizon uses the name to identify the connector.

  • Hostname* (string input):
    Enter the firewall hostname or URL.

  • Credentials* (select):
    Select Login credentials containing the username and password created for Horizon in the firewall.

  • Proxy (select):
    The HTTP/HTTPS proxy to use.

  • Timeout* (finite duration):
    Maximum time Horizon waits for a response from the firewall.

  • TLS Insecure (boolean):
    If enabled, TLS validation will ignore expired, invalid or untrusted certificates.

This is not recommended for production usage

Assets identification

  • VSYS (string input):
    Name of the virtual system to target, for multi-VSYS firewalls.

  • Prefix* (string input):
    Prefix of the certificate names on the firewall, used to identify the certificates managed by Horizon.

Actors and renewal management

These configuration elements mainly define the number of authorized interactions with the remote service on a defined period. For example, one needs to ensure that the remote service will not be contacted more than 5 times per 3 seconds. Throttle parallelism defines the number of times and Throttle duration the period of time. Therefore, on the above example, throttle parallelism would be set to 5 and throttle duration would be set to 3 seconds.

  • Throttle duration* (finite duration):
    Must be a valid finite duration.

  • Throttle parallelism* (int):
    Number of deployments processed in parallel.

Deployment jobs retry

Deployments to this third party are run as asynchronous jobs. When a job fails, Horizon retries it using an exponential backoff strategy.

  • Attempts* (int):
    Maximum number of retry attempts before the job is considered failed.

  • Minimum backoff* (finite duration):
    Delay to wait before the first retry.

  • Maximum backoff* (finite duration):
    Maximum delay between two retries, capping the exponential backoff.

  • Random factor* (decimal):
    Random jitter added to each delay to avoid simultaneous retries (e.g. 0.1 adds up to 10%).

5. Click on the save button.

You can update Edit Connector or delete Delete Connector the PAN-OS Firewall Connector.

You will not be able to delete a PAN-OS Firewall Connector if it is referenced in any other configuration element.