<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add Vm 100 palo alto machin (dr site) to a Panorama to the same device group and template (main Site) in Integration Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/integration-discussions/add-vm-100-palo-alto-machin-dr-site-to-a-panorama-to-the-same/m-p/432122#M92</link>
    <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/120680"&gt;@DinBarzilay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you have written you are facing an issue with interfaces, I will focus on Panorama Templates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One way I can think of to go around this issue is to create 2 hierarchy of Templates. For example templates based on model of the Firewall:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_pa3220&lt;/P&gt;&lt;P&gt;template_vm100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then in each template you configure only interfaces that are exactly matching model of the Firewall. You can also add any other configuration that falls under Network/Device and is specific to particular model of Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then define one Template that has all other settings. For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_global-configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this template you can configure everything but interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then group Templates in Template Stack by placing template with interface specific configuration on the top. For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_pa3220&lt;BR /&gt;template_global-configuration&lt;BR /&gt;&lt;STRONG&gt;template-stack_pa3220&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_vm100&lt;BR /&gt;template_global-configuration&lt;BR /&gt;&lt;STRONG&gt;template-stack-vm100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and associate each of the firewall to particular Template Stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since interface configuration is likely one time task and you can re-use interface specific Template for new Firewalls, you will not have to re-visit this Template anymore. All the configurations that are meant to be pushed to all Firewalls will be done in this Template:&amp;nbsp;template_global-configuration. By placing template that configures interfaces on the top in template stack, will have highest preference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are a few screens for reference:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1630965780944.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36173iA2E296D83A11EEF9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1630965780944.png" alt="PavelK_0-1630965780944.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_1-1630965893065.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36174iCE42B78EB4E90045/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_1-1630965893065.png" alt="PavelK_1-1630965893065.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_2-1630966004721.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36175i3C80296486614E54/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_2-1630966004721.png" alt="PavelK_2-1630966004721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you design Templates in this modular way, you will not lock yourself into an issue when you add yet another model of Firewall. There are possibly other ways around it. Please let me know whether this would work for you or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it comes to Device Group, I am not aware of any configuration that falls under Device Group (Policies and Objects) and has dependencies on Firewall model. Also, all configuration under&amp;nbsp;Device Group (Policies and Objects) except of a few setting has dependency on Templates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Sep 2021 22:13:22 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-09-06T22:13:22Z</dc:date>
    <item>
      <title>Add Vm 100 palo alto machin (dr site) to a Panorama to the same device group and template (main Site)</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/add-vm-100-palo-alto-machin-dr-site-to-a-panorama-to-the-same/m-p/428078#M88</link>
      <description>&lt;P&gt;hey&lt;/P&gt;&lt;P&gt;so i have main site and dr site and they are connected in L2&lt;/P&gt;&lt;P&gt;i have in the main site 2 physical pa3220 that there are in cluster (active, passive) and they connected to Panorama and they work perfect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now i need to add the Palo Vm 100 machine that is in the dr site but i want that in the end every change that i will do in the main site&lt;/P&gt;&lt;P&gt;like add policy , add object, add Nat, add route and etc. will replicate to the dr site cause it "cold dr site"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i do it?&lt;/P&gt;&lt;P&gt;my problem here cause is 2 different model of machine and the interface are different&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 11:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/add-vm-100-palo-alto-machin-dr-site-to-a-panorama-to-the-same/m-p/428078#M88</guid>
      <dc:creator>DinBarzilay</dc:creator>
      <dc:date>2021-08-20T11:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Add Vm 100 palo alto machin (dr site) to a Panorama to the same device group and template (main Site)</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/add-vm-100-palo-alto-machin-dr-site-to-a-panorama-to-the-same/m-p/432122#M92</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/120680"&gt;@DinBarzilay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you have written you are facing an issue with interfaces, I will focus on Panorama Templates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One way I can think of to go around this issue is to create 2 hierarchy of Templates. For example templates based on model of the Firewall:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_pa3220&lt;/P&gt;&lt;P&gt;template_vm100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then in each template you configure only interfaces that are exactly matching model of the Firewall. You can also add any other configuration that falls under Network/Device and is specific to particular model of Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then define one Template that has all other settings. For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_global-configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this template you can configure everything but interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then group Templates in Template Stack by placing template with interface specific configuration on the top. For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_pa3220&lt;BR /&gt;template_global-configuration&lt;BR /&gt;&lt;STRONG&gt;template-stack_pa3220&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template_vm100&lt;BR /&gt;template_global-configuration&lt;BR /&gt;&lt;STRONG&gt;template-stack-vm100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and associate each of the firewall to particular Template Stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since interface configuration is likely one time task and you can re-use interface specific Template for new Firewalls, you will not have to re-visit this Template anymore. All the configurations that are meant to be pushed to all Firewalls will be done in this Template:&amp;nbsp;template_global-configuration. By placing template that configures interfaces on the top in template stack, will have highest preference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are a few screens for reference:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1630965780944.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36173iA2E296D83A11EEF9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1630965780944.png" alt="PavelK_0-1630965780944.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_1-1630965893065.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36174iCE42B78EB4E90045/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_1-1630965893065.png" alt="PavelK_1-1630965893065.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_2-1630966004721.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36175i3C80296486614E54/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PavelK_2-1630966004721.png" alt="PavelK_2-1630966004721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you design Templates in this modular way, you will not lock yourself into an issue when you add yet another model of Firewall. There are possibly other ways around it. Please let me know whether this would work for you or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it comes to Device Group, I am not aware of any configuration that falls under Device Group (Policies and Objects) and has dependencies on Firewall model. Also, all configuration under&amp;nbsp;Device Group (Policies and Objects) except of a few setting has dependency on Templates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 22:13:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/add-vm-100-palo-alto-machin-dr-site-to-a-panorama-to-the-same/m-p/432122#M92</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-06T22:13:22Z</dc:date>
    </item>
  </channel>
</rss>

