Device groups
Before we can start managing devices, they first need to be connected to Panorama. On the Panorama side, the device is added by its serial number, and on the firewall side, the Panorama IP address needs to be added. This means the firewall always makes a connection out to the Panorama server. Any connections originating from Panorama are backchanneled over the continuous connection that a firewall has with its management station.
There are two TCP ports that are used for communication:
TCP\3978
is a bidirectional connection initiated by the firewall and used for all communications between the firewall and Panorama or collectors. Panorama uses this connection to context switch to a firewall or push a configuration over while the firewall sends logs through the connection. Collectors also use it to connect to Panorama. (Log collectors communicate with collector group members viaTCP\28270
.)TCP\28443
is used by managed devices to retrieve content and...