<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you import objects from a firewall into a new Panorama config to then push to all firewalls? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526416#M1306</link>
    <description>&lt;P&gt;We are working on configuring Panorama and currently already have 3 firewall HA pairs. We have 4000+ address objects in one of our firewall pairs. Is there a way to import these into Panorama to then push to the other 2 firewall pairs post integration? It would be great to not have to add 4000 address objects to the other two firewalls.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 22:34:49 GMT</pubDate>
    <dc:creator>MDroyKT</dc:creator>
    <dc:date>2023-01-09T22:34:49Z</dc:date>
    <item>
      <title>Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526416#M1306</link>
      <description>&lt;P&gt;We are working on configuring Panorama and currently already have 3 firewall HA pairs. We have 4000+ address objects in one of our firewall pairs. Is there a way to import these into Panorama to then push to the other 2 firewall pairs post integration? It would be great to not have to add 4000 address objects to the other two firewalls.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 22:34:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526416#M1306</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-01-09T22:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526417#M1307</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230979"&gt;@MDroyKT&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The scenario you described is possible. Below are 2 KB articles that include information to import configuration and then push it back to the Firewall as Panorama managed configuration. Both KBs are a bit dated, however the concept remains the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding pushing Device Group objects from imported configuration, I would advised to perform following steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) During import of configuration into Panorama, create a Device Group that is position in the Device Group hierarchy that is not device specific, but is logically position to be meant as shared for multiple Firewalls for example based on function of Firewalls or location.&lt;/P&gt;
&lt;P&gt;2.) After you complete the import and push the configuration back in step no.1, you can add 2 remaining Firewalls to the same Device Group. If you manage to add them to the same Device Group, the configuration can be shared to them by pushing configuration from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 23:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526417#M1307</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-01-09T23:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526534#M1308</link>
      <description>&lt;P&gt;Thank you very much!!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 15:07:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526534#M1308</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-01-10T15:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526541#M1309</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230979"&gt;@MDroyKT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the steps to add an HA pair to Panorama -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It includes some of the pointers that &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; made.&amp;nbsp; You put the HA pair in the same DG and templates.&amp;nbsp; Notice that config sync is okay to be enabled afterwards for local changes, just not during the import process.&amp;nbsp; Config sync does not apply to configs pushed from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are a couple of important steps to understand:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You must "Export or push device config bundle" (step 6, 5) for the 1st push to the NGFW.&amp;nbsp; This step actually removes the local Policies and Objects configuration.&lt;/LI&gt;
&lt;LI&gt;If you want the Network and Device configuration managed by Panorama, you must select "Force Template Values" (step 8, 2) in order to override the local configuration.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 15:36:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526541#M1309</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-10T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526798#M1312</link>
      <description>&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 16:17:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/526798#M1312</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-01-12T16:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533175#M1382</link>
      <description>&lt;P&gt;After getting through an authentication configuration issue, I've finally gotten around to formally planning for this firewall migration. Now that I've taken a closer look, it seems like if I do as you mentioned,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;, I would have to push both the current Objects AND Policies from my main firewall pair to my other two firewall pairs. The problem is, I only want the Objects to be pushed to the other pairs.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to do this?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 18:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533175#M1382</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-03-03T18:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533178#M1383</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230979"&gt;@MDroyKT&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, there is a way to do this.&amp;nbsp; If you checked the box "Import devices's shared objects into Panorama's shared context" during the config import, then your objects will already be in the Shared device group and will be pushed out to all NGFWs.&amp;nbsp; Another item to note is that the Panorama &amp;gt; Setup &amp;gt; Management &amp;gt; Panorama Settings &amp;gt; "Share Unused Address and Service Objects with Devices" should be checked to share unused objects.&amp;nbsp; If not, the objects will be pushed once they are used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you did not do that, you can shift-click the object line (not check box) and bulk move the objects to Shared.&amp;nbsp; Your policies for the other NGFWs will be in a lower device group and not pushed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 19:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533178#M1383</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-03T19:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can you import objects from a firewall into a new Panorama config to then push to all firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533510#M1395</link>
      <description>&lt;P&gt;THANK YOU so much!!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 19:55:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-you-import-objects-from-a-firewall-into-a-new-panorama/m-p/533510#M1395</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-03-07T19:55:59Z</dc:date>
    </item>
  </channel>
</rss>

