<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to push tempalte to new firewall in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584790#M2306</link>
    <description>&lt;P&gt;I have setup a couple of new firewalls and I am unable to push the template from panorama. Also device group has not yet been pushed.&lt;/P&gt;
&lt;P&gt;Should I deploy template or device group first?&lt;/P&gt;
&lt;P&gt;See the errors below..&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_0-1713964615519.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59258i0A47A6304AAC7852/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_0-1713964615519.png" alt="MAllen_0-1713964615519.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 13:17:17 GMT</pubDate>
    <dc:creator>M.Allen</dc:creator>
    <dc:date>2024-04-24T13:17:17Z</dc:date>
    <item>
      <title>Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584790#M2306</link>
      <description>&lt;P&gt;I have setup a couple of new firewalls and I am unable to push the template from panorama. Also device group has not yet been pushed.&lt;/P&gt;
&lt;P&gt;Should I deploy template or device group first?&lt;/P&gt;
&lt;P&gt;See the errors below..&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_0-1713964615519.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59258i0A47A6304AAC7852/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_0-1713964615519.png" alt="MAllen_0-1713964615519.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 13:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584790#M2306</guid>
      <dc:creator>M.Allen</dc:creator>
      <dc:date>2024-04-24T13:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584819#M2308</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is "Karelia_VPN_Gateway" a defined variable for this template/template stack? If so, is it type "IP Netmask"?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 17:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584819#M2308</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-04-24T17:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584826#M2309</link>
      <description>&lt;P&gt;Seemed to not be giving that error anymore..&amp;nbsp; but now seeing the below. Do I need to remove or disable something in the new firewall?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAllen_0-1713988337243.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59267i372E908F5FE05AA7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MAllen_0-1713988337243.png" alt="MAllen_0-1713988337243.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 19:52:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/584826#M2309</guid>
      <dc:creator>M.Allen</dc:creator>
      <dc:date>2024-04-24T19:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585162#M2311</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;Here is my notes about HA pair FW`s adding to Panorama.&lt;BR /&gt;Follow these steps it will be work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Adding HA Fw`s to Panorama.&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Connect firewalls to the Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama:&lt;BR /&gt;a. Panorama -&amp;gt; Managed Devices -&amp;gt; Summary -&amp;gt; Add&lt;BR /&gt;Enter device S/N. Enable Associate Devices checkbox. Generate Auth Key and copy it.&lt;BR /&gt;b. Commit to Panorama.&lt;BR /&gt;Firewall:&lt;BR /&gt;a. Device -&amp;gt; Setup -&amp;gt; Panorama Settings&lt;BR /&gt;Write the IP addresses of the Panorama SRVs. Paste created before Auth Key.&lt;BR /&gt;b. Commit.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;U&gt;Check connected device status in Panorama:&lt;/U&gt;&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary (the status should be connected)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;U&gt;Disable config sync in firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;U&gt;Import firewall config to Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Import device configuration to Panorama&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit to Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Template Stack for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Templates&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Remove HA config from each template:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; Template -&amp;gt; Remove all&lt;BR /&gt;(The same steps for both firwalls)&lt;BR /&gt;Commit to Panorama&lt;U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/U&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Export or push device config bundle:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Export or push device config bundle&lt;BR /&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit -&amp;gt; Push to device&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Device Group for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary&lt;BR /&gt;Commit and Push&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Enable config sync on firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Plan the transition to Panorama Mgmt&lt;/LI&gt;
&lt;LI&gt;Disable config sync&lt;/LI&gt;
&lt;LI&gt;Add HA Firewalls to Panorama&lt;/LI&gt;
&lt;LI&gt;Verify that the device state for each firewall is connected&lt;/LI&gt;
&lt;LI&gt;Import each Firewall config into Panorama&lt;/LI&gt;
&lt;LI&gt;Add the HA firewall pair into the same device group and template stack&lt;/LI&gt;
&lt;LI&gt;Push the device group and template stack configuration changes to your managed firewalls&lt;/LI&gt;
&lt;LI&gt;Enable config sync&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-----------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Migrate a Firewall HA Pair to Panorama Management and Reuse Existing Configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Disable configuration synchronization between the HA peers on each peer.&lt;/LI&gt;
&lt;LI&gt;Add HA firewalls to Panorama mgmt.:&lt;BR /&gt;a. Create a device registration auth key&lt;BR /&gt;Panorama -&amp;gt; Device Registration Auth Key and Add a new auth key&lt;BR /&gt;Copy Auth key and close.&lt;BR /&gt;b. Add firewalls to a Panorama mgmt. server.&lt;BR /&gt;Select Panorama -&amp;gt; Managed Devices -&amp;gt; Summary and Add a new firewall.&lt;BR /&gt;Enter the firewall SN&lt;BR /&gt;(No Need) Select Associate Devices to associate the fw with a device group.&lt;BR /&gt;Enter the device registration auth key created before.&lt;BR /&gt;Click ok.&lt;BR /&gt;c. (No Need) Associate firewall with a device group.&lt;BR /&gt;DISABLE Auto Push on 1&lt;SUP&gt;st&lt;/SUP&gt; connect&lt;BR /&gt;Click OK to add device.&lt;BR /&gt;d. Configura the fw to communicate with Panorama.&lt;BR /&gt;Login to the fw.&lt;BR /&gt;Configure the Panorama setings.&lt;BR /&gt;Device -&amp;gt; Setup -&amp;gt; Management and edi Panorama settings.&lt;BR /&gt;Enter primary and secondary Panorama addresses and Auth key.&lt;BR /&gt;Click OK and commit your changes.&lt;BR /&gt;e. Auth using custom cert???&lt;BR /&gt;f. Commit to Panorama and commit your changes.&lt;BR /&gt;g. Verify that the firewalls is connected to Panorama.&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary.&lt;BR /&gt;Device state should be shown as “Connected”.&lt;/LI&gt;
&lt;LI&gt;Import each firewall config into Panorama.&lt;BR /&gt;a. Panorama -&amp;gt; Setup -&amp;gt; Operations and click Import device configuration to Panorama and select the device.&lt;BR /&gt;b. Edit template name.&lt;BR /&gt;c. Commit to Panorama.&lt;BR /&gt;d. Panorama -&amp;gt; Setup -&amp;gt; Operations and Export or push device config bundle. Select the device, select ok and Push &amp;amp; Commit the configuration.&lt;BR /&gt;e. &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/use-the-web-interface/launch-the-web-interface.html" target="_blank"&gt;Launch the Web Interface&lt;/A&gt;&amp;nbsp;of the firewall HA peer and ensure that the configuration pushed in the previous step committed successfully. If not,&amp;nbsp;Commit the changes locally on the firewall.&lt;BR /&gt;f. Repeat Step&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_idf6f18528-8a0e-4ea6-9cc1-656fa4c5d4fc" target="_blank"&gt;1&lt;/A&gt;-&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_id81c78ac0-4946-4253-aef7-0ef982f248ad" target="_blank"&gt;6&lt;/A&gt;&amp;nbsp;above on the second firewall. The process creates a device group and template stack per each firewall.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 06:06:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585162#M2311</guid>
      <dc:creator>R.Seyidzada</dc:creator>
      <dc:date>2024-04-29T06:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585163#M2312</link>
      <description>&lt;P&gt;Hi! I hope these steps will help you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Notes from my configurations.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ADDING HA FW`s to Panorama&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Connect firewalls to the Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama:&lt;BR /&gt;a. Panorama -&amp;gt; Managed Devices -&amp;gt; Summary -&amp;gt; Add&lt;BR /&gt;Enter device S/N. Enable Associate Devices checkbox. Generate Auth Key and copy it.&lt;BR /&gt;b. Commit to Panorama.&lt;BR /&gt;Firewall:&lt;BR /&gt;a. Device -&amp;gt; Setup -&amp;gt; Panorama Settings&lt;BR /&gt;Write the IP addresses of the Panorama SRVs. Paste created before Auth Key.&lt;BR /&gt;b. Commit.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;U&gt;Check connected device status in Panorama:&lt;/U&gt;&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary (the status should be connected)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;U&gt;Disable config sync in firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;U&gt;Import firewall config to Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Import device configuration to Panorama&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit to Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Template Stack for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Templates&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Remove HA config from each template:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; Template -&amp;gt; Remove all&lt;BR /&gt;(The same steps for both firwalls)&lt;BR /&gt;Commit to Panorama&lt;U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/U&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Export or push device config bundle:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Export or push device config bundle&lt;BR /&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit -&amp;gt; Push to device&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Device Group for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary&lt;BR /&gt;Commit and Push&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Enable config sync on firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Plan the transition to Panorama Mgmt&lt;/LI&gt;
&lt;LI&gt;Disable config sync&lt;/LI&gt;
&lt;LI&gt;Add HA Firewalls to Panorama&lt;/LI&gt;
&lt;LI&gt;Verify that the device state for each firewall is connected&lt;/LI&gt;
&lt;LI&gt;Import each Firewall config into Panorama&lt;/LI&gt;
&lt;LI&gt;Add the HA firewall pair into the same device group and template stack&lt;/LI&gt;
&lt;LI&gt;Push the device group and template stack configuration changes to your managed firewalls&lt;/LI&gt;
&lt;LI&gt;Enable config sync&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Migrate a Firewall HA Pair to Panorama Management and Reuse Existing Configuration&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Disable configuration synchronization between the HA peers on each peer.&lt;/LI&gt;
&lt;LI&gt;Add HA firewalls to Panorama mgmt.:&lt;BR /&gt;a. Create a device registration auth key&lt;BR /&gt;Panorama -&amp;gt; Device Registration Auth Key and Add a new auth key&lt;BR /&gt;Copy Auth key and close.&lt;BR /&gt;b. Add firewalls to a Panorama mgmt. server.&lt;BR /&gt;Select Panorama -&amp;gt; Managed Devices -&amp;gt; Summary and Add a new firewall.&lt;BR /&gt;Enter the firewall SN&lt;BR /&gt;(No Need) Select Associate Devices to associate the fw with a device group.&lt;BR /&gt;Enter the device registration auth key created before.&lt;BR /&gt;Click ok.&lt;BR /&gt;c. (No Need) Associate firewall with a device group.&lt;BR /&gt;DISABLE Auto Push on 1&lt;SUP&gt;st&lt;/SUP&gt; connect&lt;BR /&gt;Click OK to add device.&lt;BR /&gt;d. Configura the fw to communicate with Panorama.&lt;BR /&gt;Login to the fw.&lt;BR /&gt;Configure the Panorama setings.&lt;BR /&gt;Device -&amp;gt; Setup -&amp;gt; Management and edi Panorama settings.&lt;BR /&gt;Enter primary and secondary Panorama addresses and Auth key.&lt;BR /&gt;Click OK and commit your changes.&lt;BR /&gt;e. Auth using custom cert???&lt;BR /&gt;f. Commit to Panorama and commit your changes.&lt;BR /&gt;g. Verify that the firewalls is connected to Panorama.&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary.&lt;BR /&gt;Device state should be shown as “Connected”.&lt;/LI&gt;
&lt;LI&gt;Import each firewall config into Panorama.&lt;BR /&gt;a. Panorama -&amp;gt; Setup -&amp;gt; Operations and click Import device configuration to Panorama and select the device.&lt;BR /&gt;b. Edit template name.&lt;BR /&gt;c. Commit to Panorama.&lt;BR /&gt;d. Panorama -&amp;gt; Setup -&amp;gt; Operations and Export or push device config bundle. Select the device, select ok and Push &amp;amp; Commit the configuration.&lt;BR /&gt;e. &lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/use-the-web-interface/launch-the-web-interface.html" target="_blank"&gt;Launch the Web Interface&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;of the firewall HA peer and ensure that the configuration pushed in the previous step committed successfully. If not,&amp;nbsp;Commit the changes locally on the firewall.&lt;BR /&gt;f. Repeat Step&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_idf6f18528-8a0e-4ea6-9cc1-656fa4c5d4fc" target="_blank"&gt;1&lt;/A&gt;&lt;/SPAN&gt;-&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_id81c78ac0-4946-4253-aef7-0ef982f248ad" target="_blank"&gt;6&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;above on the second firewall. The process creates a device group and template stack per each firewall.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 06:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585163#M2312</guid>
      <dc:creator>R.Seyidzada</dc:creator>
      <dc:date>2024-04-29T06:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585178#M2313</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;&lt;BR /&gt;Follow these steps. I hope will help you.&lt;BR /&gt;&lt;BR /&gt;ADDING HA FW`s to Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Connect firewalls to the Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama:&lt;BR /&gt;a. Panorama -&amp;gt; Managed Devices -&amp;gt; Summary -&amp;gt; Add&lt;BR /&gt;Enter device S/N. Enable Associate Devices checkbox. Generate Auth Key and copy it.&lt;BR /&gt;b. Commit to Panorama.&lt;BR /&gt;Firewall:&lt;BR /&gt;a. Device -&amp;gt; Setup -&amp;gt; Panorama Settings&lt;BR /&gt;Write the IP addresses of the Panorama SRVs. Paste created before Auth Key.&lt;BR /&gt;b. Commit.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;U&gt;Check connected device status in Panorama:&lt;/U&gt;&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary (the status should be connected)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;U&gt;Disable config sync in firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;U&gt;Import firewall config to Panorama:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Import device configuration to Panorama&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit to Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Template Stack for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Templates&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Remove HA config from each template:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; Template -&amp;gt; Remove all&lt;BR /&gt;(The same steps for both firwalls)&lt;BR /&gt;Commit to Panorama&lt;U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/U&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Export or push device config bundle:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Export or push device config bundle&lt;BR /&gt;(The same steps for both firewalls)&lt;BR /&gt;Commit -&amp;gt; Push to device&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Leave just 1 Device Group for HA devices:&lt;BR /&gt;&lt;/U&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary&lt;BR /&gt;Commit and Push&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Enable config sync on firewalls:&lt;BR /&gt;&lt;/U&gt;Device -&amp;gt; HA -&amp;gt; General -&amp;gt; Setup&lt;BR /&gt;Commit&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Plan the transition to Panorama Mgmt&lt;/LI&gt;
&lt;LI&gt;Disable config sync&lt;/LI&gt;
&lt;LI&gt;Add HA Firewalls to Panorama&lt;/LI&gt;
&lt;LI&gt;Verify that the device state for each firewall is connected&lt;/LI&gt;
&lt;LI&gt;Import each Firewall config into Panorama&lt;/LI&gt;
&lt;LI&gt;Add the HA firewall pair into the same device group and template stack&lt;/LI&gt;
&lt;LI&gt;Push the device group and template stack configuration changes to your managed firewalls&lt;/LI&gt;
&lt;LI&gt;Enable config sync&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Migrate a Firewall HA Pair to Panorama Management and Reuse Existing Configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Disable configuration synchronization between the HA peers on each peer.&lt;/LI&gt;
&lt;LI&gt;Add HA firewalls to Panorama mgmt.:&lt;BR /&gt;a. Create a device registration auth key&lt;BR /&gt;Panorama -&amp;gt; Device Registration Auth Key and Add a new auth key&lt;BR /&gt;Copy Auth key and close.&lt;BR /&gt;b. Add firewalls to a Panorama mgmt. server.&lt;BR /&gt;Select Panorama -&amp;gt; Managed Devices -&amp;gt; Summary and Add a new firewall.&lt;BR /&gt;Enter the firewall SN&lt;BR /&gt;(No Need) Select Associate Devices to associate the fw with a device group.&lt;BR /&gt;Enter the device registration auth key created before.&lt;BR /&gt;Click ok.&lt;BR /&gt;c. (No Need) Associate firewall with a device group.&lt;BR /&gt;DISABLE Auto Push on 1&lt;SUP&gt;st&lt;/SUP&gt; connect&lt;BR /&gt;Click OK to add device.&lt;BR /&gt;d. Configura the fw to communicate with Panorama.&lt;BR /&gt;Login to the fw.&lt;BR /&gt;Configure the Panorama setings.&lt;BR /&gt;Device -&amp;gt; Setup -&amp;gt; Management and edi Panorama settings.&lt;BR /&gt;Enter primary and secondary Panorama addresses and Auth key.&lt;BR /&gt;Click OK and commit your changes.&lt;BR /&gt;e. Auth using custom cert???&lt;BR /&gt;f. Commit to Panorama and commit your changes.&lt;BR /&gt;g. Verify that the firewalls is connected to Panorama.&lt;BR /&gt;Panorama -&amp;gt; Managed Devices -&amp;gt; Summary.&lt;BR /&gt;Device state should be shown as “Connected”.&lt;/LI&gt;
&lt;LI&gt;Import each firewall config into Panorama.&lt;BR /&gt;a. Panorama -&amp;gt; Setup -&amp;gt; Operations and click Import device configuration to Panorama and select the device.&lt;BR /&gt;b. Edit template name.&lt;BR /&gt;c. Commit to Panorama.&lt;BR /&gt;d. Panorama -&amp;gt; Setup -&amp;gt; Operations and Export or push device config bundle. Select the device, select ok and Push &amp;amp; Commit the configuration.&lt;BR /&gt;e. &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/use-the-web-interface/launch-the-web-interface.html" target="_blank"&gt;Launch the Web Interface&lt;/A&gt;&amp;nbsp;of the firewall HA peer and ensure that the configuration pushed in the previous step committed successfully. If not,&amp;nbsp;Commit the changes locally on the firewall.&lt;BR /&gt;f. Repeat Step&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_idf6f18528-8a0e-4ea6-9cc1-656fa4c5d4fc" target="_blank"&gt;1&lt;/A&gt;-&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management#id177DF10905Z_id81c78ac0-4946-4253-aef7-0ef982f248ad" target="_blank"&gt;6&lt;/A&gt;&amp;nbsp;above on the second firewall. The process creates a device group and template stack per each firewall.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 07:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585178#M2313</guid>
      <dc:creator>R.Seyidzada</dc:creator>
      <dc:date>2024-04-29T07:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585179#M2314</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attached file here. HA pair FW`s adding to Panorama and configuration steps. I Hope will help you.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 08:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/585179#M2314</guid>
      <dc:creator>R.Seyidzada</dc:creator>
      <dc:date>2024-04-29T08:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to push tempalte to new firewall</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/1228890#M2870</link>
      <description>&lt;P&gt;Allen,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any update on this? I got same error now.&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 03:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-push-tempalte-to-new-firewall/m-p/1228890#M2870</guid>
      <dc:creator>weezy</dc:creator>
      <dc:date>2025-05-13T03:06:10Z</dc:date>
    </item>
  </channel>
</rss>

