SD-WAN Palo Alto Prisma Deployment / Configuration Guide
This document describes the steps to deploy and configure the Palo Alto Prisma SD-WAN Plugin.
Please do not run sevone-cli command from a subdirectory under /opt/SevOne/upgrade and /var/log/pods. It can be run from any directory except for from subdirectories under /opt/SevOne/upgrade and /var/log/pods.
Please use support user for SevOne NMS version 7.0.0 and above.
However, for SevOne NMS versions prior to version 7.0.0, please use root user instead of support user.
Prerequisites
- To connect to Palo Alto Prisma SD-WAN plugin, a non administrator-level user must have a PAN (Palo Alto Networks) Service account with a Client ID and Client Secret, with View Only Administrator role assigned along with Strata Cloud Manager Tenant Service Group ID (TSGID).
- SNMP v2 or SNMP v3 details for the ION devices, based on device compatibility.
Device Onboarding
When onboarding Palo Alto Prisma devices in SevOne NMS, you only need to add a single SD-WAN integration device (the Palo Alto Prisma Orchestrator) with the appropriate orchestrator credentials. Once the integration device is added and saved, SevOne NMS automatically discovers all ION devices managed by that integration. There is no need to manually add each ION device.
If the ION devices already exist in SevOne NMS with SNMP-only monitoring and valid IP addresses, adding the SD-WAN integration device with both SNMP and SD-WAN plugins will automatically associate the integration with the existing devices. The SD-WAN metadata will then populate alongside the existing SNMP data, without creating duplicates.
To onboard Palo Alto Prisma ION devices in SevOne NMS, execute the following steps.
- Using a web browser, navigate to the SevOne NMS appliance URL, log in with your credentials, then go to the Devices menu via the navigation bar, select Device Manager, and click Add Device to create a new device.
- On the New Device page, add the following details.

- In the Name field, enter the device name.
- In the Alternate Name field, enter an alternate device name. You can search for a device by its alternate name.
- In the Description field, enter the device description. You can use this to provide additional information about the function, location, or any other pertinent information about the device.
- (optional) In the IP Address field, enter the device IP address.
- In the Read Community String field , enter sevone as shown in the image above.
- Enter the Username and Password for the Palo Alto Prisma ION device.
Note: Ensure that the same SNMP credentials are configured on all Palo Alto Prisma ION devices.
- Click Save to create a new device with the current changes. The device is then queued for discovery.
- Again, click the Devices menu and select Discovery Manager.
- After the discovery process is completed, the Palo Alto Prisma ION Device will be visible on the Device Manager screen.

- To retrieve or edit the metadata for Palo Alto Prisma SD-WAN device, execute the steps as shown.
- In the Device Manager , select the Device from the list to view its metadata.
- Click
in the Actions column to open the Edit Metadata pop-up. - In the Edit Metadata pop-up, locate the attribute Device to view the device-related metadata fields.
- In the Edit Metadata pop-up, locate the attribute Location to view the location-related metadata fields.
Example: Device- related metadata fields.

The TopN Report Views are automatically imported and are listed as shown below. Manual importing is not required for these reports.
- Prisma SD-WAN - Top TCP Established Connections
- Prisma SD-WAN - Top TCP Segments Sent/Received
- Prisma SD-WAN - Top UDP Datagrams
- Prisma SD-WAN Active Tunnels
- Prisma SD-WAN Disk Utilization
- Prisma SD-WAN Top CPU Utilization
- Prisma SD-WAN Top Memory Utilization
- Prisma SD-WAN Tunnel Utilization- In & Out
- Prisma SD-WAN Usable Tunnels
SD-WAN Palo Alto Prisma Flows in SevOne NMS
To check the flows received on SevOne NMS, from the navigation bar, click Administration menu, select Flow Configuration, and then select Flow Interface Manager.
Support Long Flows on SevOne NMS
Sometimes, the flows are dropped when Palo Alto Prisma ION devices send flows with a longer duration than what is configured. To allow long flows, from the navigation bar, click the Administration menu and select Cluster Manager and then select Cluster Settings. Click on the FlowFalcon subtab and uncheck the Drop Long Flows option.

Solution Verification & Customization
- Enter the URL for the SevOne NMS appliance into your web browser to display the Login page.
- Enter the credentials and click Login. For example, Username: admin and Password: SevOne
- To check device groups imported, click the Devices menu and select Grouping, then Device Groups. Please refer to Device Groups for details.

- Prisma SD-WAN device group is available along with its subgroups Branch and Data Center.
- To check object types, click the Administration menu and select Monitoring Configuration, then Object Types. Please refer to Object Types for details.
Example

SD-WAN Palo Alto Prisma OOTB Reports in SevOne Data Insight
- Log in to your SevOne Data Insight by navigating to the appropriate URL in your web browser. Enter your credentials on the login page and click Login.
- Select Reports, and under the SevOne Folders, click on the SD-WAN drop-down list, and select Prisma folder and then choose Palo Alto Prisma SD-WAN Report. Alternatively, to view the same reports, select Palo Alto Prisma SD-WAN Report and click on the Run button as shown below.

-
Click on Devices to view the Device Manager page, then select the relevant datasource from the Datasource drop-down list to view the corresponding devices and their details.
Example
