<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BPA on multiple devices and Panorama in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/245312#M973</link>
    <description>&lt;P&gt;&lt;FONT face="helvetica"&gt;This is a good question.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;When checking the BPA, the checks are done on the&amp;nbsp; base-config selected for the project. Probably you have the Panorama config defined as a base-config.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;In your case, I understand you would like to check the BPA for the merged configuration, which it is neither the Panorama nor the FWs configs. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;In that case, that is a tricky one, because what you could do is to retrieve the merged config from the FW, set it as a base-config, and apply the BPA to&amp;nbsp;&lt;STRONG&gt;see&amp;nbsp;what&lt;/STRONG&gt; you should modify in the Panorama config (obviously, you do not want to apply changes into the merged, as it is read-only&amp;nbsp;config that results of merging the Panorama and FW configs).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;We will internally check with the Customer Success team, who is the one that developed the BPA module that we use in Expedition, in order to see if they have any other approach for this challenge.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2019 11:36:35 GMT</pubDate>
    <dc:creator>dgildelaig</dc:creator>
    <dc:date>2019-01-09T11:36:35Z</dc:date>
    <item>
      <title>BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/245286#M966</link>
      <description>&lt;P&gt;I'm having some trouble with Best Practices analysis and hoping someone here can confirm the functionality.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have many devices managed by Panorama.&amp;nbsp; Their configuration is built through a combination of some local device configuration and&amp;nbsp;policies, plus settings from templates and device groups in Panorama.&amp;nbsp; I've imported all devices including Panorama into a project, but when I run the Best Practices analysis it seems to only consider the Panorama config.&amp;nbsp; I don't see the settings or policies from the local device&amp;nbsp;configs in the analysis results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe this worked for me in the past, perhaps there is some trick I'm just forgetting.&amp;nbsp; I've tried toggling through devices in the bottom toolbar but it seems to have no effect when on the Best Practices tab.&amp;nbsp; Can anyone else confirm if BPA is working for them with a combination of Panorama and local device configurations?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition 1.1.2 / BP 3.6.3&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 23:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/245286#M966</guid>
      <dc:creator>cchaffee</dc:creator>
      <dc:date>2019-01-08T23:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/245312#M973</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica"&gt;This is a good question.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;When checking the BPA, the checks are done on the&amp;nbsp; base-config selected for the project. Probably you have the Panorama config defined as a base-config.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;In your case, I understand you would like to check the BPA for the merged configuration, which it is neither the Panorama nor the FWs configs. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;In that case, that is a tricky one, because what you could do is to retrieve the merged config from the FW, set it as a base-config, and apply the BPA to&amp;nbsp;&lt;STRONG&gt;see&amp;nbsp;what&lt;/STRONG&gt; you should modify in the Panorama config (obviously, you do not want to apply changes into the merged, as it is read-only&amp;nbsp;config that results of merging the Panorama and FW configs).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica"&gt;We will internally check with the Customer Success team, who is the one that developed the BPA module that we use in Expedition, in order to see if they have any other approach for this challenge.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 11:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/245312#M973</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-01-09T11:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246827#M1029</link>
      <description>&lt;P&gt;Unfortunately it seems even the merged configuration retrieved from the FW is not the full picture.&amp;nbsp; It seems to be missing the security rules that come down from Panorama; only security rules that are defined locally show up in the merged config.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be great if we could have&amp;nbsp;a tool&amp;nbsp;capable of running a comprehensive BPA on devices where the config is partly local and partly from Panorama.&amp;nbsp; For now, I'm thinking it might be possible to run separate BPA's for&amp;nbsp;the merged device config and the Panorama config, and then&amp;nbsp;take&amp;nbsp;the results from both to get a more complete picture.&amp;nbsp; If there's a better approach, I'm definitely interested in hearing about it.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 19:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246827#M1029</guid>
      <dc:creator>cchaffee</dc:creator>
      <dc:date>2019-01-21T19:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246967#M1036</link>
      <description>&lt;P&gt;Are you sure?&lt;/P&gt;
&lt;P&gt;The merge config should show the result of merging both Panorama rules and Device rules, obviously, if the device is within the DeviceGroup defined in the Panorama.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 15:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246967#M1036</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-01-22T15:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246993#M1039</link>
      <description>&lt;P&gt;Yes, I'm pretty sure. I used the API to&amp;nbsp;pull the merged config directly from the firewall, and it definitely does not include the security rules from Panorama.&amp;nbsp; I get the same results from the cli command 'show config merged'.&amp;nbsp; However, when I log into the device's web console, I can see all the rules that came from Panorama so I'm certain they're getting pushed to the device.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Btw, I can run 'show config pushed-shared-policy' on the firewall and all of the policy objects from Panorama are displayed.&amp;nbsp; They just do not appear in the merged output.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/246993#M1039</guid>
      <dc:creator>cchaffee</dc:creator>
      <dc:date>2019-01-22T17:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/247021#M1040</link>
      <description>Weird. Which version of PANOS are you running?&lt;BR /&gt;We would like to check as well on our device in our lab.&lt;BR /&gt;&lt;BR /&gt;My apologies for the typos, I am writing from my phone.</description>
      <pubDate>Tue, 22 Jan 2019 19:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/247021#M1040</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-01-22T19:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/247022#M1041</link>
      <description>&lt;P&gt;I’ve seen this behavior on devices running 8.0.13, 8.1.3 and 8.1.4.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 21:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/247022#M1041</guid>
      <dc:creator>cchaffee</dc:creator>
      <dc:date>2019-01-22T21:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: BPA on multiple devices and Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/255349#M1321</link>
      <description>&lt;P&gt;I am currently running into the same problem on PanOS 9.0.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has this issue been resolved? If so, is there a KB that can be referenced?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 02:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/bpa-on-multiple-devices-and-panorama/m-p/255349#M1321</guid>
      <dc:creator>scottatta</dc:creator>
      <dc:date>2019-03-29T02:28:25Z</dc:date>
    </item>
  </channel>
</rss>

