<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 850 ETH1/1 disabled in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229471#M5910</link>
    <description>&lt;P&gt;after I disable ZTP mode, can I reboot the PA?&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 03:44:31 GMT</pubDate>
    <dc:creator>weezy</dc:creator>
    <dc:date>2025-05-20T03:44:31Z</dc:date>
    <item>
      <title>PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229033#M5890</link>
      <description>&lt;P&gt;Need your help we setup a new PA850 to replace our PRIMARY FW in EUR. Now the config has been push to the device however, i'm seeing the eth1/1 is disabled for some reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a command that I can forcefully enable it? even on GUI it shows RED status.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weezy_0-1747200270037.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67597i6B37BC93C3691013/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weezy_0-1747200270037.png" alt="weezy_0-1747200270037.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to disabled or re-enable it on CLI and I got this error&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set failed, may need to override template object ethernet1/1 first&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 05:38:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229033#M5890</guid>
      <dc:creator>weezy</dc:creator>
      <dc:date>2025-05-14T05:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229192#M5903</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259684"&gt;@weezy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for info, Looks like configuration has been pushed from panorama.&amp;nbsp; if you are enforcing the config from panorama then you can make the changes at panorama template or you can override the config locally at firewall and then make necessary changes as per your requirement.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;ukn/ukn/down(power-down) is when you set the Link-State to Disable&lt;/P&gt;
&lt;P&gt;disabled/down: You've disabled the interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;forced/ukn: You've forced the speed/duplex setting and the status of the interface is unknown. Usually caused by unsupported SFPs or if you statically set the link-state to up but the interface is unplugged.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;forced/down: You've forced the speed/duplex settings and the interface is down.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 02:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229192#M5903</guid>
      <dc:creator>mshekh</dc:creator>
      <dc:date>2025-05-16T02:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229412#M5904</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259684"&gt;@weezy&lt;/a&gt;&amp;nbsp;Did you remember to disable ZTP mode after the first boot?&lt;/P&gt;
&lt;P&gt;by default new devices boot up in ZTP mode which reserves interface 1/1 for ZTP. this will also block it from being used for anything else&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can disable that using the following command:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;set system ztp disable &lt;/LI-CODE&gt;
&lt;P&gt;after a reboot you should be good to go&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2025 07:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229412#M5904</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-05-19T07:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229470#M5909</link>
      <description>&lt;P&gt;Our SR. Engr check it and he said that the device on the other end which is cisco core switch interface is on error disabled state so he bounce it and he said that it was up now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is that also possible too?&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 03:43:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229470#M5909</guid>
      <dc:creator>weezy</dc:creator>
      <dc:date>2025-05-20T03:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229471#M5910</link>
      <description>&lt;P&gt;after I disable ZTP mode, can I reboot the PA?&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 03:44:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229471#M5910</guid>
      <dc:creator>weezy</dc:creator>
      <dc:date>2025-05-20T03:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA 850 ETH1/1 disabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229749#M5920</link>
      <description>&lt;P&gt;yes, reboot is required when you disable ZTP&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 07:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-850-eth1-1-disabled/m-p/1229749#M5920</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-05-22T07:34:48Z</dc:date>
    </item>
  </channel>
</rss>

