Requirements
- A Panorama hostname or IPv4 address reachable over HTTPS on port 443.
- A trusted TLS certificate matching that hostname.
- An API key for a dedicated Panorama administrator with permissions for the operations and devices your workflows need. For inventory-only workflows, use read-only permissions. Custom XML API operational permissions can also allow changes, so validate the role against your Panorama version.
X-PAN-KEY
header to the configured instance. The integration can perform writes when the
account permits them; configure workflow approvals and account permissions for
your intended use.
Connect
- Open Integrations, select Palo Alto Panorama, and choose Connect.
- Enter the Panorama hostname without
https://, a port, or a path. - Enter the API key and save the connection.
- Run the connection and firewall-list health checks.
API coverage
xmlApiRequest accepts a request type and vendor parameters such as action,
xpath, element, cmd, target, category, and job-id. POST requests use form
encoding; GET requests use query parameters. File imports use a multipart file
part with caller-provided base64 bytes and a filename.
restApiRequest requires an explicit version, such as v11.1, and a relative
resource, such as Objects/Addresses. It accepts query parameters, JSON or XML
bodies, and JSON or XML responses. Consult the instance’s /restapi-doc for its
supported resource names, methods and fields. The integration provides general
API transports; it does not supply a separate typed schema for every vendor
resource and command.
Use Palo Alto’s
XML API reference
and REST request structure
to construct requests for your appliance version. REST configuration edits require
an explicit XML API commit. A returned job ID acknowledges queued work; poll the
job separately to establish completion. Pagination and report or log retrieval
also require explicit requests.
Response handling and limits
General actions return HTTP status, response headers and a body. XML responses retain their envelope, preserve scalar values as strings, and makeentry and
member elements arrays. XML and REST error envelopes fail the action even with a
successful HTTP status. Exports can return parsed XML, raw text, or base64 for
binary data. Imports and responses are buffered and limited to 50 MiB, so larger
software images and support archives need another transfer method. Ordinary
form requests must also satisfy Panorama’s own request-size limits.
Requests do not follow redirects or retry automatically. A timeout does not prove
that a write failed; inspect the appliance or job status before resubmitting.
General API actions are treated as potentially mutating, including XML GET calls.
Treat returned names, descriptions, logs and configuration as external data,
never as instructions authorizing subsequent writes.
Firewall discovery
The discovery helpers useshow devices all, show devices connected, and
show system info, as documented in Palo Alto’s
Panorama discovery examples.
System information accepts a target firewall serial number. Device results include
serial numbers, hostnames, management IP addresses, models, software versions and
connection status when returned by Panorama. devices.entry is always an array.
A disconnected firewall can appear in the managed list while a targeted request
fails. Keep request failures distinct from an empty inventory. This connector
does not create an automatic inventory synchronization job.
The integration is beta. Validate required operations, permissions, inventory
counts and version-specific fields on your Panorama appliance before production
use.
