<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How are duplicate shared objects identified in Panorama? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539627#M1487</link>
    <description>&lt;P&gt;I know that when you migrate a firewall into Panorama and you keep the&amp;nbsp;&lt;STRONG&gt;Import device's shared objects into Panorama's shared context&amp;nbsp;&lt;/STRONG&gt;box checked, this imports the firewall's objects as shared objects, unless there are duplicates. I'm wondering--how does Panorama identify any duplicates? Is it by the name of the object or other characteristics (such as the IP address itself)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example: If I have an Address Object on one firewall called "Server-DNS" with IP 8.8.8.8 and an Address Object on a different firewall called "DNS-Server" with the same IP 8.8.8.8, will it identify that as a duplicate? I'm assuming not, since you are able to have multiple Address Objects with the same IP, but would like to verify.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 21:12:35 GMT</pubDate>
    <dc:creator>MDroyKT</dc:creator>
    <dc:date>2023-04-20T21:12:35Z</dc:date>
    <item>
      <title>How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539627#M1487</link>
      <description>&lt;P&gt;I know that when you migrate a firewall into Panorama and you keep the&amp;nbsp;&lt;STRONG&gt;Import device's shared objects into Panorama's shared context&amp;nbsp;&lt;/STRONG&gt;box checked, this imports the firewall's objects as shared objects, unless there are duplicates. I'm wondering--how does Panorama identify any duplicates? Is it by the name of the object or other characteristics (such as the IP address itself)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example: If I have an Address Object on one firewall called "Server-DNS" with IP 8.8.8.8 and an Address Object on a different firewall called "DNS-Server" with the same IP 8.8.8.8, will it identify that as a duplicate? I'm assuming not, since you are able to have multiple Address Objects with the same IP, but would like to verify.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 21:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539627#M1487</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-04-20T21:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539746#M1490</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230979"&gt;@MDroyKT&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have imported multiple NGFW configs into Panorama, and the duplicates are always removed.&amp;nbsp; I never thought about the specifics until now.&amp;nbsp; Here is a doc that explains the process -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/plan-the-transition-to-panorama-management#id068490d9-66d8-4de4-8c7a-f6bd06b3153e_idedeb9d50-b4e0-475d-869d-5deccc7f8661" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/plan-the-transition-to-panorama-management#id068490d9-66d8-4de4-8c7a-f6bd06b3153e_idedeb9d50-b4e0-475d-869d-5deccc7f8661&lt;/A&gt;.&amp;nbsp; Look under the section "Plan how to manage shared settings."&amp;nbsp; The rules are as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If the name and value are the same, it is not imported.&lt;/LI&gt;
&lt;LI&gt;If the name or value differs (assuming one name or value is the same?), the object is imported into the device group and not Shared.&lt;/LI&gt;
&lt;LI&gt;If the object references a shared object or template on the NGFW, it is imported into Shared even if you didn't check the box.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I would love to hear what you find if you import objects with duplicate names and/or values.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 21:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539746#M1490</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-21T21:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539976#M1497</link>
      <description>&lt;P&gt;Thank you, Tom! It will likely be a few months at least before I get all our firewalls migrated (still in the planning phase for the first firewall migration) but I will make a note to comment back here on it once I do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Michelle&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 19:17:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/539976#M1497</guid>
      <dc:creator>MDroyKT</dc:creator>
      <dc:date>2023-04-24T19:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/548885#M1631</link>
      <description>&lt;P&gt;for the mentioned example:&lt;BR /&gt;&lt;BR /&gt;1) different object name but same value:&amp;nbsp;&lt;SPAN&gt;"Server-DNS" with IP 8.8.8.8 and "DNS-Server" also with IP 8.8.8.8&lt;BR /&gt;&lt;BR /&gt;there is nothing available directly on PAN-OS Firewall or Panorama; until now also not on the Strata Cloud Manager.&lt;BR /&gt;&lt;BR /&gt;For all the mentioned Palo Alto Networks products you can use PAN-OS-PHP framework with predefined utilities to find and merge e.g. duplicate address objects by value.&lt;BR /&gt;&lt;BR /&gt;The tool is also checking and correcting all places where the planned merged object is used and is replacing it with the object which will be kept.&lt;BR /&gt;&lt;A href="https://github.com/PaloAltoNetworks/pan-os-php" target="_blank"&gt;https://github.com/PaloAltoNetworks/pan-os-php&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;also available as Docker Container:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;docker run  --name panosphp --rm -v ${PWD}:/share -it swaschkut/pan-os-php:latest&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;more information about the specific address-merger utility:&lt;BR /&gt;&lt;A href="https://github.com/PaloAltoNetworks/pan-os-php/wiki/type=address-merger" target="_blank"&gt;https://github.com/PaloAltoNetworks/pan-os-php/wiki/type=address-merger&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;more predefined merger scripts available for:&lt;BR /&gt;- rule&lt;BR /&gt;- address-group&lt;BR /&gt;- service&lt;BR /&gt;- service-group&lt;BR /&gt;- tag&lt;BR /&gt;- custom-url-category&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 08:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/548885#M1631</guid>
      <dc:creator>swaschkut</dc:creator>
      <dc:date>2023-07-11T08:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/548919#M1632</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38031"&gt;@swaschkut&lt;/a&gt; for the cool tool!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition is also able to clean up the config via the API.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 12:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/548919#M1632</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-07-11T12:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: How are duplicate shared objects identified in Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/555825#M1801</link>
      <description>&lt;P&gt;Panorama configurations with big config file size are hard to optimise.&lt;BR /&gt;Based on the feedback of Palo Alto Networks Professional Services engineers, you need to focus on which tool can be used,&lt;BR /&gt;to be successfully in a timely manner.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;PAN-OS-PHP has an additional feature by optimise your configuration and based on the changes it is possible to provide "set commands",&amp;nbsp;&lt;BR /&gt;which can be directly pasted into the Panorama / Firewall CLI.&lt;BR /&gt;&lt;BR /&gt;This feature is needed for customers where a ChangeRequest must be up-front documented well with detailed change commands,&lt;BR /&gt;and of course where NO direct PAN-OS XML API access is possible.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 09:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-are-duplicate-shared-objects-identified-in-panorama/m-p/555825#M1801</guid>
      <dc:creator>swaschkut</dc:creator>
      <dc:date>2023-08-30T09:15:59Z</dc:date>
    </item>
  </channel>
</rss>

