<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disabled rules on Panorama being pushed to firewall in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/576971#M2149</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a very strange behavior recently on panorama. Disabled rules don't go to firewalls when a push is performed from Panorama, but I had a disabled rule on panorama which got pushed to firewalls. Please find below events in the order they appeared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. I had disabled a Security Rule and 2 PBF rules on Panorama and pushed the config to firewalls. It was pushed successfully, and I couldn't see disabled rules on the local firewall, which is expected behavior.&lt;/P&gt;
&lt;P&gt;2. I had to configure a security rule on same Device Group to allow some traffic and it was pushed successfully onto the local firewall.&lt;/P&gt;
&lt;P&gt;3. When I checked the local firewall after the last push, I found that along with the new rule, the disabled rule and 2 PBFs were also pushed, but when I checked back on Panorama, they were still showing disabled and there were no pending changes to commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anybody has come across such behavior or know anything about it, your help will be much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Feb 2024 08:24:32 GMT</pubDate>
    <dc:creator>SCH-Gaurav</dc:creator>
    <dc:date>2024-02-12T08:24:32Z</dc:date>
    <item>
      <title>Disabled rules on Panorama being pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/576971#M2149</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a very strange behavior recently on panorama. Disabled rules don't go to firewalls when a push is performed from Panorama, but I had a disabled rule on panorama which got pushed to firewalls. Please find below events in the order they appeared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. I had disabled a Security Rule and 2 PBF rules on Panorama and pushed the config to firewalls. It was pushed successfully, and I couldn't see disabled rules on the local firewall, which is expected behavior.&lt;/P&gt;
&lt;P&gt;2. I had to configure a security rule on same Device Group to allow some traffic and it was pushed successfully onto the local firewall.&lt;/P&gt;
&lt;P&gt;3. When I checked the local firewall after the last push, I found that along with the new rule, the disabled rule and 2 PBFs were also pushed, but when I checked back on Panorama, they were still showing disabled and there were no pending changes to commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anybody has come across such behavior or know anything about it, your help will be much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 08:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/576971#M2149</guid>
      <dc:creator>SCH-Gaurav</dc:creator>
      <dc:date>2024-02-12T08:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled rules on Panorama being pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/577198#M2155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308488"&gt;@SCH-Gaurav&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I haven't encountered this in the past, but if you enable and disable the appropriate policies in Panorama and then push them out, do they still appear on the managed firewall?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 22:22:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/577198#M2155</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-02-13T22:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled rules on Panorama being pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/577208#M2156</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308488"&gt;@SCH-Gaurav&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you confirm what PAN-OS version you are running on Panorama? If you are running PAN-OS 10.2, you might be running into bugs addressed in PAN-OS 10.2.8:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-240197&lt;BR /&gt;Fixed an issue where configuration changes made in Panorama and pushed to the firewall weren’t reflected on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-208438&lt;BR /&gt;Fixed an issue on Panorama where Security policy rules incorrectly displayed as disabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 23:56:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/disabled-rules-on-panorama-being-pushed-to-firewall/m-p/577208#M2156</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-02-13T23:56:34Z</dc:date>
    </item>
  </channel>
</rss>

