SD-WAN Palo Alto Prisma Deployment / Configuration Guide

This document describes the steps to deploy and configure the Palo Alto Prisma SD-WAN Plugin.

Important:

Please do not run sevone-cli command from a subdirectory under /opt/SevOne/upgrade and /var/log/pods. It can be run from any directory except for from subdirectories under /opt/SevOne/upgrade and /var/log/pods.

Important:

Please use support user for SevOne NMS version 7.0.0 and above.

However, for SevOne NMS versions prior to version 7.0.0, please use root user instead of support user.

Prerequisites

  • To connect to Palo Alto Prisma SD-WAN plugin, a non administrator-level user must have a PAN (Palo Alto Networks) Service account with a Client ID and Client Secret, with View Only Administrator role assigned along with Strata Cloud Manager Tenant Service Group ID (TSGID).
  • SNMP v2 or SNMP v3 details for the ION devices, based on device compatibility.

Device Onboarding

Note:

When onboarding Palo Alto Prisma devices in SevOne NMS, you only need to add a single SD-WAN integration device (the Palo Alto Prisma Orchestrator) with the appropriate orchestrator credentials. Once the integration device is added and saved, SevOne NMS automatically discovers all ION devices managed by that integration. There is no need to manually add each ION device.

If the ION devices already exist in SevOne NMS with SNMP-only monitoring and valid IP addresses, adding the SD-WAN integration device with both SNMP and SD-WAN plugins will automatically associate the integration with the existing devices. The SD-WAN metadata will then populate alongside the existing SNMP data, without creating duplicates.

To onboard Palo Alto Prisma ION devices in SevOne NMS, execute the following steps.

  1. Using a web browser, navigate to the SevOne NMS appliance URL, log in with your credentials, then go to the Devices menu via the navigation bar, select Device Manager, and click Add Device to create a new device.
  2. On the New Device page, add the following details.

    Palo Alto New Device

    1. In the Name field, enter the device name.
    2. In the Alternate Name field, enter an alternate device name. You can search for a device by its alternate name.
    3. In the Description field, enter the device description. You can use this to provide additional information about the function, location, or any other pertinent information about the device.
    4. (optional) In the IP Address field, enter the device IP address.
    5. In the Read Community String field , enter sevone as shown in the image above.
    6. Enter the Username and Password for the Palo Alto Prisma ION device.
      Note: Ensure that the same SNMP credentials are configured on all Palo Alto Prisma ION devices.
    7. Click Save to create a new device with the current changes. The device is then queued for discovery.
    8. Again, click the Devices menu and select Discovery Manager.
    9. After the discovery process is completed, the Palo Alto Prisma ION Device will be visible on the Device Manager screen.

      Palo Alto SD-WAN Device

    1. To retrieve or edit the metadata for Palo Alto Prisma SD-WAN device, execute the steps as shown.
      1. In the Device Manager , select the Device from the list to view its metadata.
      2. Click Edit metadata in the Actions column to open the Edit Metadata pop-up.
      3. In the Edit Metadata pop-up, locate the attribute Device to view the device-related metadata fields.
      4. In the Edit Metadata pop-up, locate the attribute Location to view the location-related metadata fields.

        Example: Device- related metadata fields. Palo Alto Device Related Metadata

Note:
Note:

The TopN Report Views are automatically imported and are listed as shown below. Manual importing is not required for these reports.

  • Prisma SD-WAN - Top TCP Established Connections
  • Prisma SD-WAN - Top TCP Segments Sent/Received
  • Prisma SD-WAN - Top UDP Datagrams
  • Prisma SD-WAN Active Tunnels
  • Prisma SD-WAN Disk Utilization
  • Prisma SD-WAN Top CPU Utilization
  • Prisma SD-WAN Top Memory Utilization
  • Prisma SD-WAN Tunnel Utilization- In & Out
  • Prisma SD-WAN Usable Tunnels

SD-WAN Palo Alto Prisma Flows in SevOne NMS

To check the flows received on SevOne NMS, from the navigation bar, click Administration menu, select Flow Configuration, and then select Flow Interface Manager.Palo Alto Flow Interface

Support Long Flows on SevOne NMS

Sometimes, the flows are dropped when Palo Alto Prisma ION devices send flows with a longer duration than what is configured. To allow long flows, from the navigation bar, click the Administration menu and select Cluster Manager and then select Cluster Settings. Click on the FlowFalcon subtab and uncheck the Drop Long Flows option.

Palo Alto Drop Long Flows

Solution Verification & Customization

Perform the following steps by logging in to SevOne NMS appliance.
Note: For more details, please refer to Login page.
  1. Enter the URL for the SevOne NMS appliance into your web browser to display the Login page.
  2. Enter the credentials and click Login. For example, Username: admin and Password: SevOne
  3. To check device groups imported, click the Devices menu and select Grouping, then Device Groups. Please refer to Device Groups for details.

    Palo Alto Device Groups

  4. Prisma SD-WAN device group is available along with its subgroups Branch and Data Center.
  5. To check object types, click the Administration menu and select Monitoring Configuration, then Object Types. Please refer to Object Types for details.

    ExamplePalo Alto Object Types

SD-WAN Palo Alto Prisma OOTB Reports in SevOne Data Insight

Note: Please refer to Data Insight 8.0 Guides for details.
  1. Log in to your SevOne Data Insight by navigating to the appropriate URL in your web browser. Enter your credentials on the login page and click Login.
  2. Select Reports, and under the SevOne Folders, click on the SD-WAN drop-down list, and select Prisma folder and then choose Palo Alto Prisma SD-WAN Report. Alternatively, to view the same reports, select Palo Alto Prisma SD-WAN Report and click on the Run button as shown below.

    Palo Alto Prisma Report

  3. Click on Devices to view the Device Manager page, then select the relevant datasource from the Datasource drop-down list to view the corresponding devices and their details.

    Example

    Palo Alto Prisma Device Manager