We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

Palo Alto Firewall Device with Virtual System (VSYS) discovery

Kavitha Raydurg
Tera Contributor

Hi,

Do I need a plugin to discover and map Virtual Systems (vsys) on Palo Alto Firewall devices? Or is there another built-in method to discover them?

 

Thanks
Kavitha Raydurga

2 REPLIES 2

Dr Atul G- LNG
Tera Patron

Hi @Kavitha Raydurg 

 

https://www.servicenow.com/docs/r/it-operations-management/discovery-and-service-mapping-patterns/pa...

 

 

Data collected by Discovery during horizontal discovery

Discovery populates the data in the CMDB when running the Next-Generation Palo Alto Firewall Pattern.

Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]
Field Description
IP Address [ip_address] IP address of the Palo Alto device.
Serial number [serial_number] Serial number of the Palo Alto device.
Fully qualified domain name [fqdn] Fully qualified domain name (FQDN) of the Palo Alto device.
Manufacturer [manufacturer] Palo Alto device manufacturer.
Model ID [model_id] Model ID of the Palo Alto device.
Operational status [operational_status] Indicates whether the Palo Alto device is in active state.
Hardware OS [hardware_os] OS running on the hardware.
Hardware OS Version [hardware_os_version] OS version running on the hardware.
Description [short_description] Short description of the Palo Alto device.
Firmware version [firmware_version] Palo Alto device firmware version.
*************************************************************************************************************
Regards
Dr. Atul G. - Learn N Grow Together
ServiceNow Techno - Functional Trainer
LinkedIn: https://www.linkedin.com/in/dratulgrover
YouTube: https://www.youtube.com/@LearnNGrowTogetherwithAtulG

****************************************************************************************************************

Tanushree Maiti
Tera Patron

Hi @Kavitha Raydurg 

 

Refer ServiceNow Documentation on it: Palo Alto Networks firewall discovery 

 

Prerequisites

  • Ensure that your network firewall device has SNMP access.
  • On the ServiceNow instance, configure SNMP credentials. For more information, see SNMP credentials.
  • Add the SNMP system OID record for the Palo Alto Networks device to the ServiceNow instance. Update the following:
    • Classifier: Palo Alto Firewall
    • Class: Palo Alto Firewall Device
  • Deploy the pattern as follows:
    1. Download and install Firewall extension classes from the ServiceNow Store. The app adds the new CMDB classes required for network firewall discovery.
    2. Download and install the discovery pattern from the ServiceNow Store.
    3. Sync the pattern with the appropriate MID Server.

Data collected by Discovery during horizontal discovery

Discovery populates the data in the CMDB when running the Next-Generation Palo Alto Firewall Pattern.

Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]Field Description
IP Address [ip_address]IP address of the Palo Alto device.
Serial number [serial_number]Serial number of the Palo Alto device.
Fully qualified domain name [fqdn]Fully qualified domain name (FQDN) of the Palo Alto device.
Manufacturer [manufacturer]Palo Alto device manufacturer.
Model ID [model_id]Model ID of the Palo Alto device.
Operational status [operational_status]Indicates whether the Palo Alto device is in active state.
Hardware OS [hardware_os]OS running on the hardware.
Hardware OS Version [hardware_os_version]OS version running on the hardware.
Description [short_description]Short description of the Palo Alto device.
Firmware version [firmware_version]Palo Alto device firmware version.
Network Adapter [cmdb_ci_network_adapter]Field Description
IP Address [ip_address]IP address of the network adapter.
Alias [alias]The user-assigned name for the network adapter.
Netmask [netmask]Netmask of the network adapter.
MAC address [mac_address]MAC address of the network adapter.
Name [name]Name of the network adapter.
Configuration Item [cmdb_ci]References the Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto] table.
IP Address [cmdb_ci_ip_address]Field Description
IP Address [ip_address]IP address of the Palo Alto firewall.
Netmask [netmask]Netmask of the Palo Alto firewall.
Nic [nic]References the Network Adapter [cmdb_ci_network_adapter] table.
DNS Name [cmdb_ci_dns_name]Field Description
Name [name]Domain Name System (DNS) name of the Palo Alto firewall device.
IP Address [ip_address]Host IP address.

CI relationships

The Next-Generation Palo Alto Firewall pattern creates the following relationships and references to support Palo Alto Networks firewall discovery. References link to records in other tables and don't appear in the CI Relationship [cmdb_rel_ci] table.

CI relationshipsCI Relationship CI
Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]Owns::Owned byNetwork Adapter [cmdb_ci_network_adapter]
Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]Owns::Owned byIP Address [cmdb_ci_ip_address]
Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]Uses::Used byRouter Interface [dscy_router_interface]
Network Adapter [cmdb_ci_network_adapter]Owns::Owned byIP Address [cmdb_ci_ip_address]
CI referencesCI Field Referenced CI
Serial Number [cmdb_serial_number]Configuration item [configuration_item]Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]
Network Adapter [cmdb_ci_network_adapter]Configuration Item [cmdb_ci]Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]
Router Interface [dscy_router_interface]Configuration Item [cmdb_ci]Palo Alto Firewall Device [cmdb_ci_firewall_device_palo_alto]
IP Address [cmdb_ci_ip_address]Nic [nic]Network Adapter [cmdb_ci_network_adapter]

 

 

 

Also check : Discovery of Palo Alto firewall on SSH 

 

 

 

Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti