Skip to main content
Version: 2026.09

Firewall preparation

VPN Reporter connects to the firewall with a dedicated admin account that can only use two XML API permissions. Web UI, command line and REST API access are not needed, so they are all turned off.

PermissionWhy it is needed
XML API → LogRead traffic logs and interpret VPN sessions
XML API → Operational RequestsTrack active GlobalProtect sessions

1. Create a limited admin role profile​

  1. Go to Device → Admin Roles and click Add at the bottom of the list.
  2. Enter a Name, for example NascellaApiProfile.

Web UI tab​

Set every item to Disable (red cross), as in the screenshot. Click an item's icon to change its state.

Web UI tab: all items disabled

XML API tab​

Enable only Log and Operational Requests. Leave all other items disabled.

XML API tab: Log and Operational Requests enabled

Command Line tab​

Select None.

Command Line tab: None

REST API tab​

Leave every item disabled.

REST API tab: all items disabled

Click OK to save the profile.

2. Create the admin account​

  1. Go to Device → Administrators and click Add.
  2. Enter the account Name, for example nascella-api-user.
  3. Enter a strong password in Password and Confirm Password.
  4. In Administrator Type, select Role Based, select the profile you created in the previous step (NascellaApiProfile) in Profile, and click OK.
  5. Commit the changes.

Administrator: Role Based with NascellaApiProfile selected

User names are case-sensitive

PAN-OS treats upper- and lower-case letters as different characters. Enter the account name in VPN Reporter exactly as you typed it in the Name field — NascellaApi and nascellaapi are different accounts.

Panorama and HA

When logs are collected through Panorama, create the same role and account on Panorama. In high-availability (HA) pairs, enter both the primary and the secondary device in VPN Reporter.