<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama On Boarding in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559167#M1871</link>
    <description>&lt;P&gt;Thanks for the link, I appreciate you. It is helpful for me.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2023 13:53:10 GMT</pubDate>
    <dc:creator>JeriShubert</dc:creator>
    <dc:date>2023-09-22T13:53:10Z</dc:date>
    <item>
      <title>Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/558634#M1859</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;For the last 10 years, i am in charge of 3 PA devices.&lt;/P&gt;
&lt;P&gt;Device #1 (HA Pair of 1410) in the main site.&lt;/P&gt;
&lt;P&gt;Device #2 (460) in the DR site.&lt;/P&gt;
&lt;P&gt;Device #3 (440) in 2nd DR site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have recently purchased Panorama to make it easier to deploy some shared policies and objects (right now I am doing this manually on each).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have already registered the devices, which are log forwarding to the Panorama.&lt;/P&gt;
&lt;P&gt;I have been trying for 5 weeks without success to start the main mission which is the policy deployments.&lt;/P&gt;
&lt;P&gt;i did the import from devices, but I have a total mess and the push is not working (a lot of errors regarding profile groups).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also heard the I will need to clear all devices in order to let Panorama to push them the policy (which will lead to downtime),&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideas? Help plz...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 20:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/558634#M1859</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-19T20:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/558668#M1861</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great question!&amp;nbsp; Adding a locally managed NGFW to Panorama is tricky.&amp;nbsp; You have to do it a few times to get used to it.&amp;nbsp; Here are the steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in the long run, it will be worth it because you can change something once and push it to your NGFWs.&amp;nbsp; Here are some pointers:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The HA pair document has extra steps.&amp;nbsp; Be sure to go through those.&amp;nbsp; My step #s below refer to the top URL.&lt;/LI&gt;
&lt;LI&gt;When you import the device configuration, it will create a new device group and template.
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Uncheck "Import devices's shared objects into Panorama's shared context (device group specific objects will be created if unique)" if you have LOTS of objects.&amp;nbsp; Otherwise you can get conflicts and commit errors.&amp;nbsp; You can move your objects to the Shared device group and resolve duplicates after the NGFWs are imported.&lt;/LI&gt;
&lt;LI&gt;I usually import my rules into the Post Rulebase.&lt;/LI&gt;
&lt;LI&gt;Do not make any changes to the device group or template until after you are finished with these steps.&lt;/LI&gt;
&lt;LI&gt;You can always rename the device group and/or template any time.&amp;nbsp; Don't worry about it for now.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Step 5 is very important!&amp;nbsp; (Step 4 on the HA doc.). Do not do the 1st push from the Commit menu.&amp;nbsp; Push &amp;amp; Commit from the &lt;SPAN&gt;Panorama &amp;gt; Setup &amp;gt; Operations &amp;gt; Export or push device config bundle&lt;/SPAN&gt; menu.&amp;nbsp; This step deletes the local policies and objects so that you will not have duplicate object commit errors.&amp;nbsp; After this step, push normally.&lt;/LI&gt;
&lt;LI&gt;Finally, the top URL document above is not complete!&amp;nbsp; (The HA one has this step.). If you want to managed the Network and Device configuration from Panorama, select Force Template Values in step 6.
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;This will override IP addresses, etc. So, make sure you have &lt;SPAN&gt;automated commit recovery&lt;/SPAN&gt; enabled so that if the NGFW cannot communicate with Panorama it revert the configuration.&amp;nbsp; This is critical if the NGFW is at a remote location.&lt;/LI&gt;
&lt;LI&gt;Like step 5, this only needs to be done once.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Try it out!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 23:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/558668#M1861</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-19T23:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559167#M1871</link>
      <description>&lt;P&gt;Thanks for the link, I appreciate you. It is helpful for me.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 13:53:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559167#M1871</guid>
      <dc:creator>JeriShubert</dc:creator>
      <dc:date>2023-09-22T13:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559724#M1881</link>
      <description>&lt;P&gt;Ok thanks.&lt;/P&gt;
&lt;P&gt;Done.&lt;/P&gt;
&lt;P&gt;Now i have the managed policy in yellow\orange.&lt;/P&gt;
&lt;P&gt;What if the Panorama is not available (since it's on central location), and i need to make urgent policy change or rule disable in the running managed firewall? i saw i can add local rules to policy, but i have no options beside read only on the yellow\orange rules&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 16:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559724#M1881</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-27T16:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559742#M1882</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct.&amp;nbsp;&amp;nbsp; You cannot edit or override device group configurations (Policies or Objects) on the local NGFW.&amp;nbsp; It is important to know the hierarchy of the rules on the NGFW.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies\" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies\&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, any rules that may block critical traffic should be place in the Panorama post-rules section.&amp;nbsp; Then, any locally created rules will take precedence.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If my original answer solved your problem, please mark it as the solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 18:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559742#M1882</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-27T18:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559754#M1883</link>
      <description>&lt;P&gt;Thanks for the answer.&lt;/P&gt;
&lt;P&gt;Still, something doesn't make sense for me.&lt;/P&gt;
&lt;P&gt;Our risk management must have a solution in case of Panorama lost.&lt;/P&gt;
&lt;P&gt;What if we have a deny rule from the shared DG rules. And we need to bypass it somehow, locally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To add post rule (local) will not help here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 18:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559754#M1883</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-27T18:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559761#M1884</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not say &lt;EM&gt;local&lt;/EM&gt; post-rule.&amp;nbsp; Any deny rules that may need to be bypassed should be in the &lt;EM&gt;Panorama&lt;/EM&gt; post-rules section.&amp;nbsp; If you look at the URL I posted you will see that local rules come before Panorama post-rules.&amp;nbsp; You will be able to add a local rule that is matched before the deny rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559761#M1884</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-27T19:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559762#M1885</link>
      <description>&lt;P&gt;This mean i have to re-design all my policy, because i have deny rules per zones. For example deny outbound ldap before allow any.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sound like very hard mission, this Panorama deployment&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:15:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559762#M1885</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-27T19:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559764#M1886</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not need to redesign all of your policy.&amp;nbsp; Are your security policy rules in the Panorama pre-rules or post-rules section?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559764#M1886</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-27T19:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559765#M1887</link>
      <description>&lt;P&gt;Just import them to as your first answer recommendation . I have import all to pre-rules.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559765#M1887</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-27T19:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559766#M1888</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Simply use the Move button on the bottom of the page to move your rules to post-rules one rule at a time. You can start at the bottom and then move each rule to the top of the post-rules section.&amp;nbsp; Once you are done, the order on the NGFW will be the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my first answer I recommended moving all the rules to post-rules, but i understand that pre-rules is the default.&amp;nbsp; I usually use pre-rules only for Shared rules which I push out to all NGFWs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559766#M1888</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-27T19:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559767#M1889</link>
      <description>&lt;P&gt;Ok cool.&lt;/P&gt;
&lt;P&gt;So once all of them will be in post-rules, i will actually have the option to add local rules that will take place before them?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559767#M1889</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-09-27T19:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559768#M1890</link>
      <description>&lt;P&gt;Exactly!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/559768#M1890</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-27T19:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563378#M1970</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After playing arround, i feel ready to onboard HA pair.&lt;/P&gt;
&lt;P&gt;I am working with this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But something is bothering me:&lt;/P&gt;
&lt;P&gt;Step 5 (of HA) tells me to consolidate both peers to the same device group (which makes sense) and alto to same template stack.&lt;/P&gt;
&lt;P&gt;SubStep F tells me to add the 2nd peer to the 1st peer stack, but what about 2nd peer template?&lt;/P&gt;
&lt;P&gt;Not using the 2nd template will override all device configs including the management interface, and HA as well.&lt;/P&gt;
&lt;P&gt;On the other hand,&amp;nbsp;&amp;nbsp;SubStep G&amp;nbsp; tells me to remote the HA template. Since the config import created only one template for each peer,&amp;nbsp;removing the HA config from the 1st (merged) template will override and destroy the HA in both peers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sounds scary a little bit&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 14:05:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563378#M1970</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-10-27T14:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563389#M1971</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good questions.&amp;nbsp; Yes, add both NGFWs to the same template stack.&amp;nbsp; The NGFW is smart enough NOT to used the Panorama-pushed configuration for the management interface, even when you Force Template Values.&amp;nbsp; I have done it many times, and never lost connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to HA, you have 2 options:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Delete the HA config in Panorama, which means the HA will remain&amp;nbsp;locally configured.&amp;nbsp; Panorama does not &lt;EM&gt;remove&lt;/EM&gt; Network or Device configuration if it doesn't have it.&amp;nbsp; It stays on the NGFW.&lt;/LI&gt;
&lt;LI&gt;Use template variables for the HA IP addresses.&amp;nbsp; This is a little more complicated, but you get to manage the configuration from Panorama.&amp;nbsp; If you get it wrong, HA won't work.&amp;nbsp; Generally you do not lose connectivity to Panorama.&amp;nbsp; If the HA pair is in production at a remote site from Panorama, you may want to be on site.&amp;nbsp; If HA fails, both NGFWs may become active, and you may have connectivity issues.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=MxAy_7X5g3E" target="_blank"&gt;https://www.youtube.com/watch?v=MxAy_7X5g3E&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 14:53:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563389#M1971</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-27T14:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563393#M1972</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;thanks a lot!&lt;/P&gt;
&lt;P&gt;But if the local HA config will stay, why do i need to struggle with variables....?&lt;/P&gt;
&lt;P&gt;My goal is to be as simple as possible. Manage the HA config LOCALY on the firewalls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you suggest?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:12:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563393#M1972</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-10-27T15:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama On Boarding</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563395#M1973</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That sounds good!&amp;nbsp; Use option 1 and manage HA locally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-on-boarding/m-p/563395#M1973</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-27T15:16:20Z</dc:date>
    </item>
  </channel>
</rss>

