<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Export via API not allowing Security Profile Groups to be deleted in Pano in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350479#M2979</link>
    <description>&lt;P&gt;I am using Expedition 1.1.80 to make bulk changes to Security Profile Groups that are used on rules. Once the changes are made I am using the API Output Manager to push the changes back to Panorama. Once this is done and I am sure the old security profile groups are no longer used I delete them. This works just fine most of the time but there are times where when I choose to delete the groups Pano comes back and tells me the groups are still used in rules. When I check the rules they are indeed using the NEW groups, not the old groups. The way to fix this is to just open the rules and save them again and the problem goes away. The problem with this approach is sometimes we are talking about 50 rules this needs to be done on and that defeats the whole point of automation using Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts on what might be causing this and how to fix it?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 19:08:57 GMT</pubDate>
    <dc:creator>aporue</dc:creator>
    <dc:date>2020-09-18T19:08:57Z</dc:date>
    <item>
      <title>Export via API not allowing Security Profile Groups to be deleted in Pano</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350479#M2979</link>
      <description>&lt;P&gt;I am using Expedition 1.1.80 to make bulk changes to Security Profile Groups that are used on rules. Once the changes are made I am using the API Output Manager to push the changes back to Panorama. Once this is done and I am sure the old security profile groups are no longer used I delete them. This works just fine most of the time but there are times where when I choose to delete the groups Pano comes back and tells me the groups are still used in rules. When I check the rules they are indeed using the NEW groups, not the old groups. The way to fix this is to just open the rules and save them again and the problem goes away. The problem with this approach is sometimes we are talking about 50 rules this needs to be done on and that defeats the whole point of automation using Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts on what might be causing this and how to fix it?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 19:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350479#M2979</guid>
      <dc:creator>aporue</dc:creator>
      <dc:date>2020-09-18T19:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350518#M2980</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108153"&gt;@aporue&lt;/a&gt;&amp;nbsp;This might be related to PAN-OS API, the workaround is you can save the candidate config from Panorama and load the candidate file back again, then you should be able to commit to panorama without errors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 20:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350518#M2980</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-09-18T20:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350736#M2982</link>
      <description>&lt;P&gt;Thanks for the quick reply. I do want to make sure that you fully understand the issue. I am not having any problem committing to Panorama or when pushing to the firewalls after exporting the API output back to Panorama. The problem is that I am trying to delete security profile groups that are no longer used in the rules but Panorama is claiming they are still being used. Currently, the only way to fix that is to open each rule that is erroring on and save it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you saying that saving the candidate config and reloading it will solve this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 20:39:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350736#M2982</guid>
      <dc:creator>aporue</dc:creator>
      <dc:date>2020-09-20T20:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350790#M2983</link>
      <description>&lt;P&gt;yes, with exporting the candiate-config and a reimport of the same, the Panorama DB which hold the configuration is refreshed.&lt;BR /&gt;&lt;BR /&gt;Please be informed that this issue you are running into, is not an Expedition issue.&lt;BR /&gt;So we from Expedition team can only give you advise how you can use the work around,&lt;BR /&gt;so that you can continue your work.&lt;BR /&gt;&lt;BR /&gt;For more problem solving part please open a Palo Alto Networks Tac case related to PAN-OS API.&lt;BR /&gt;&lt;BR /&gt;regards&lt;/P&gt;
&lt;P&gt;Sven&lt;BR /&gt;--------------------&lt;BR /&gt;Solutions Engineer - Expedition&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 06:50:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/350790#M2983</guid>
      <dc:creator>swaschkut</dc:creator>
      <dc:date>2020-09-21T06:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351581#M2992</link>
      <description>&lt;P&gt;Just an FYI that I was able to simply delete the security profile groups via the CLI and got no complaints from Panos so that fixed the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 20:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351581#M2992</guid>
      <dc:creator>aporue</dc:creator>
      <dc:date>2020-09-23T20:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351716#M2994</link>
      <description>&lt;P&gt;I would like to collect a bit of information about this issue. Could you share thePANOS version that got affected in this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 09:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351716#M2994</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-09-24T09:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Export via API not allowing Security Profile Groups to be deleted in Pa</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351932#M2995</link>
      <description>&lt;P&gt;It is PANOS 9.07&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 19:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/export-via-api-not-allowing-security-profile-groups-to-be/m-p/351932#M2995</guid>
      <dc:creator>aporue</dc:creator>
      <dc:date>2020-09-24T19:02:43Z</dc:date>
    </item>
  </channel>
</rss>

