Skip to main content
The Panorama integration connects workflows to the Panorama XML and REST APIs. Use it to discover managed firewalls, read or change configuration, manage policies and objects, commit changes, run operational commands, and import or export files. This is separate from the Strata Cloud Manager integration.

Requirements

  • A Panorama hostname or IPv4 address reachable over HTTPS on port 443.
  • A trusted TLS certificate matching that hostname.
  • An API key for a dedicated Panorama administrator with permissions for the operations and devices your workflows need. For inventory-only workflows, use read-only permissions. Custom XML API operational permissions can also allow changes, so validate the role against your Panorama version.
Generate the key following Palo Alto’s API authentication documentation. Connection setup takes the resulting key. Serval sends it in the X-PAN-KEY header to the configured instance. The integration can perform writes when the account permits them; configure workflow approvals and account permissions for your intended use.

Connect

  1. Open Integrations, select Palo Alto Panorama, and choose Connect.
  2. Enter the Panorama hostname without https://, a port, or a path.
  3. Enter the API key and save the connection.
  4. Run the connection and firewall-list health checks.
Reconnect to rotate the key. Changing the hostname requires a new key. For internal endpoints, arrange a supported private network connection. Certificate verification remains enabled. The health checks test inventory access; they do not establish permission for every write operation.

API coverage

xmlApiRequest accepts a request type and vendor parameters such as action, xpath, element, cmd, target, category, and job-id. POST requests use form encoding; GET requests use query parameters. File imports use a multipart file part with caller-provided base64 bytes and a filename. restApiRequest requires an explicit version, such as v11.1, and a relative resource, such as Objects/Addresses. It accepts query parameters, JSON or XML bodies, and JSON or XML responses. Consult the instance’s /restapi-doc for its supported resource names, methods and fields. The integration provides general API transports; it does not supply a separate typed schema for every vendor resource and command. Use Palo Alto’s XML API reference and REST request structure to construct requests for your appliance version. REST configuration edits require an explicit XML API commit. A returned job ID acknowledges queued work; poll the job separately to establish completion. Pagination and report or log retrieval also require explicit requests.

Response handling and limits

General actions return HTTP status, response headers and a body. XML responses retain their envelope, preserve scalar values as strings, and make entry and member elements arrays. XML and REST error envelopes fail the action even with a successful HTTP status. Exports can return parsed XML, raw text, or base64 for binary data. Imports and responses are buffered and limited to 50 MiB, so larger software images and support archives need another transfer method. Ordinary form requests must also satisfy Panorama’s own request-size limits. Requests do not follow redirects or retry automatically. A timeout does not prove that a write failed; inspect the appliance or job status before resubmitting. General API actions are treated as potentially mutating, including XML GET calls. Treat returned names, descriptions, logs and configuration as external data, never as instructions authorizing subsequent writes.

Firewall discovery

The discovery helpers use show devices all, show devices connected, and show system info, as documented in Palo Alto’s Panorama discovery examples. System information accepts a target firewall serial number. Device results include serial numbers, hostnames, management IP addresses, models, software versions and connection status when returned by Panorama. devices.entry is always an array. A disconnected firewall can appear in the managed list while a targeted request fails. Keep request failures distinct from an empty inventory. This connector does not create an automatic inventory synchronization job. The integration is beta. Validate required operations, permissions, inventory counts and version-specific fields on your Panorama appliance before production use.