<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying already existing firewalls in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519607#M1178</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156979"&gt;@JaredBaglietto&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are having issues with conflicting objects, you may not have done step 5 in this doc -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;.&amp;nbsp; Exporting the Panorama config once to the NGFW &lt;STRONG&gt;right after you import the config&lt;/STRONG&gt; is necessary to delete the local &lt;EM&gt;polices and objects&lt;/EM&gt;.&amp;nbsp; After you do step 5 once, you then push all configs to the devices under the Commit menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to overwrite the local &lt;EM&gt;network and device&lt;/EM&gt; configurations with Panorama configs, you should check the box Force Template Values in step 6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Sat, 29 Oct 2022 16:38:38 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2022-10-29T16:38:38Z</dc:date>
    <item>
      <title>Deploying already existing firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519599#M1177</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been working with Panorama now for just over a month, learning most its concepts slowly but surely. I am now stuck however on the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before we acquired Panorama, we had several clients running PA-220s. After it was announced the 220s were reaching EoL, we replaced most with 410s and 440s. We then acquired Panorama to centralise all deployments. How I did it was to import each client's 220 configs into respective 410/440 replacements, then deploy them to client site. Then from office I would register them to our Panorama, import its config into client-respective device group and templates.&lt;/P&gt;
&lt;P&gt;From this point on, it has been really painful getting even one client FW to be in sync with either device group or template. I am having to rename/remove every single object/policy for example for the firewall to accept push, due to conflicting objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think lesson learnt here is that I should've pushed the configs into the firewall via Panorama instead of directly into firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question, is there any simpler way I can push templates and groups to already deployed firewalls more easily, without having to configure them from scratch and risk removing their running configs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jared&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 06:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519599#M1177</guid>
      <dc:creator>JaredBaglietto</dc:creator>
      <dc:date>2022-10-29T06:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying already existing firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519607#M1178</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156979"&gt;@JaredBaglietto&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are having issues with conflicting objects, you may not have done step 5 in this doc -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;.&amp;nbsp; Exporting the Panorama config once to the NGFW &lt;STRONG&gt;right after you import the config&lt;/STRONG&gt; is necessary to delete the local &lt;EM&gt;polices and objects&lt;/EM&gt;.&amp;nbsp; After you do step 5 once, you then push all configs to the devices under the Commit menu.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to overwrite the local &lt;EM&gt;network and device&lt;/EM&gt; configurations with Panorama configs, you should check the box Force Template Values in step 6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 16:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519607#M1178</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-10-29T16:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying already existing firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519687#M1180</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for that. I've tried the steps provided and I think it's what I'm looking for. Just hitting a few hurdles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have to be careful as I seem to be overwriting important network configs and policies that allow me remote access into the firewall. Accidentally kicked myself out of client firewall this past weekend and had to fix their config onsite.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When in step 6 making changes to config, I only end up getting an error such as 'ethernet1/1 is already in use'. Any idea why this may be occurring?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 15:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/deploying-already-existing-firewalls/m-p/519687#M1180</guid>
      <dc:creator>JaredBaglietto</dc:creator>
      <dc:date>2022-10-31T15:11:04Z</dc:date>
    </item>
  </channel>
</rss>

