Panorama is a well-known tool for managing Palo Alto Networks firewalls and providing central log storage. It has been available for as long as the NGFW firewalls themselves. I work with it frequently. Like any product, it is not perfect. I have encountered several specific drawbacks.
Panorama management logic is based on Device Groups for objects and policies. The second part of the configuration involves Templates. Templates are used for device settings like networking, routing, zones, external server profiles and many, many more. Templates aggregate into Template Stacks. Firewalls are assigned to these stacks. This allows the same configuration to apply to multiple firewalls. In theory, this logic is correct. However, a profile configured within one template cannot be used in another. This limitation makes the system inflexible.

Storage capacity is another significant issue. Panorama has strict limitations regarding disk count and capacity. Increasing log storage requires additional Panorama instances acting as Log Collectors. Some instances handle management while others are dedicated to logging. Logs remain visible from the management Panorama. Data performance becomes an issue when storage is full. Filtering logs is slow in such cases.
Strata Cloud Manager (SCM) introduces a completely different logic. There is no separation between objects, policies, and device settings. Everything is organized into folders. Configuration is possible at every folder level. Folder settings are inherited from higher levels.

SCM also introduces Snippets. Snippets allow the same configurations as folders. However, Snippets can be linked at any level. This provides more flexibility than the Panorama approach.


Another feature is Best Practice Assessment (BPA). I wrote article how to measure configuration quality, elaborated process is manual.. SCM performs this automatically for managed devices. NGFWs must send telemetry data for this to function. Telemetry is a requirement for SCM onboarding. Automated BPA eliminates the need for manual work to verify best practices.



SCM offers two license levels: Essential and Pro

Using the free Essential version allows for NGFW management and BPA. This provides significant value at no cost. The free version does not include log storage. Log storage is the primary reason to upgrade to the Pro version.
As of writing this article, no tool exists to migrate Panorama configurations to SCM. Palo Alto Networks is developing a solution. I remain concerned about how it will handle configuration translation for complex environments. Worth to mention, SCM manages firewalls only when the Advanced Routing Engine (ARE) is enabled. ARE was introduced in PAN-OS 10.2. Most existing firewalls utilize legacy Virtual Routers, the routing mode must be changed to ARE before onboarding to SCM.
Panorama adoption is broad and will remain with us for a long time. I do not expect it to be deprecated soon. However, the industry direction is moving toward the cloud. I expect Panorama will be maintained without the introduction of new features
If you have multiple firewalls without Panorama, you can now manage them centrally using Essential SCM for free.