<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall has the IPSec tunnel but Panorama don't. How to fix? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-has-the-ipsec-tunnel-but-panorama-don-t-how-to-fix/m-p/582728#M2267</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;We have one of the IPSec tunnel missing on Panorama but it is configured on individual Firewalls (HA pair). The tunnel is up and running. We don't want any downtime on VPN tunnel.&lt;/P&gt;
&lt;P&gt;Can I simply add missing IPSec tunnel to Panorama and do just " Commit to Panorama"?&lt;/P&gt;
&lt;P&gt;Or is there something else needs to be done?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2024 23:24:37 GMT</pubDate>
    <dc:creator>MINKU2</dc:creator>
    <dc:date>2024-04-04T23:24:37Z</dc:date>
    <item>
      <title>Firewall has the IPSec tunnel but Panorama don't. How to fix?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-has-the-ipsec-tunnel-but-panorama-don-t-how-to-fix/m-p/582728#M2267</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;We have one of the IPSec tunnel missing on Panorama but it is configured on individual Firewalls (HA pair). The tunnel is up and running. We don't want any downtime on VPN tunnel.&lt;/P&gt;
&lt;P&gt;Can I simply add missing IPSec tunnel to Panorama and do just " Commit to Panorama"?&lt;/P&gt;
&lt;P&gt;Or is there something else needs to be done?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 23:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-has-the-ipsec-tunnel-but-panorama-don-t-how-to-fix/m-p/582728#M2267</guid>
      <dc:creator>MINKU2</dc:creator>
      <dc:date>2024-04-04T23:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall has the IPSec tunnel but Panorama don't. How to fix?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-has-the-ipsec-tunnel-but-panorama-don-t-how-to-fix/m-p/582840#M2268</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313540"&gt;@MINKU2&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from your post it looks like you are considering to move IPsec local Firewall configuration to Panorama managed configuration. If this is the case, then there are a few things to consider.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will have to configure IPsec in Panorama's Template, then commit and push it to Firewall. If the IPsec configuration is identical, the local configuration will have precedence, then you will have to override it locally in Firewall to use Panorama's configuration. This will have to be committed to take an effect. During commit the configuration will be replaced that will likely cause IPsec tunnel reset. If you are concerned about down time, then migration from local to Panorama configuration on one to one bases should be performed during a maintenance window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There might be some work arounds to make this transition without down time. For example push from Panorama IPsec configuration with unique names to prevent overriding it locally, then if you are using any routing protocol to shift traffic to new tunnel. This will required more information about your setup and more planning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2024 04:27:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/firewall-has-the-ipsec-tunnel-but-panorama-don-t-how-to-fix/m-p/582840#M2268</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-04-06T04:27:33Z</dc:date>
    </item>
  </channel>
</rss>

